An endpoint may be authenticated and still be costly to run. Recovery links, search, exports, and third-party sends each have a different abuse surface. This track applies budgets to actions and work, prevents identity disclosure through response differences, offers accessible alternatives to challenges, and records denial outcomes without turning every user into a permanent fingerprint. The goal is a service that can reject harmful volume while giving legitimate users a path to finish.
Topics in this track
- Account Recovery Enumeration and Throttle Policy — Bound recovery requests without exposing which identities exist or locking out legitimate owners.
- Expensive Request Work Budgets and Load Shedding — Bound CPU, bytes, fan-out, provider spend, and concurrency before costly work begins.
- Human Challenges, Accessible Alternatives, and Signal Retention — Escalate suspicious actions without making visual puzzles the only route or retaining excessive signals.
- Abuse Decision Telemetry and False-Positive Rollback — Measure defense outcomes and recover legitimate users when a rule blocks the wrong traffic.
Prerequisite paths
Rate Limits and Request Budgets; Identity and Application Security.
Neighbor track
Background Workflow Reliability.
Practice path
Build Project: public permit endpoint abuse controls and check decisions in Web Development: jobs and abuse decisions quiz.
