why is it still 2023 and we're letting some random guy on the internet use our public api endpoints?