> Just be sure to allow URLs from *.push.apple.com if you are in control of your server push endpoints.
Wait, why would anyone be doing any sort of whitelisting? That seems a disastrously bad idea that utterly ruins interoperability. I could understand checking that the IP address the URL resolves to isn’t private, but what they’ve written suggests something much broader.
Am I missing something, or have they gone off the deep end, or are they reacting to implementers that have gone off the deep end?
Wait, why would anyone be doing any sort of whitelisting? That seems a disastrously bad idea that utterly ruins interoperability. I could understand checking that the IP address the URL resolves to isn’t private, but what they’ve written suggests something much broader.
Am I missing something, or have they gone off the deep end, or are they reacting to implementers that have gone off the deep end?