diff --git a/README.md b/README.md index 7e6adbf..a726d28 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,13 @@ This API wrapper contains function for interacting easily with ZeroBounce API. More information about ZeroBounce you can find in the [official documentation](https://www.zerobounce.net/docs/). + +## Security + +- Keep API keys on a trusted server. Do not embed them in mobile apps or browser JavaScript that untrusted users can inspect. +- Custom API base URLs (when supported) must use `https://`. Do not pass end-user-controlled hosts into those settings. +- Request URLs include `api_key` as a query parameter (ZeroBounce API contract). Do not log full request URLs or enable payload debug logging in production. + ## INSTALLATION Before installing the wrapper, you have to make sure that `CMake` is installed on your system. It can be downloaded from [here](https://cmake.org/download/). diff --git a/src/ZeroBounce.c b/src/ZeroBounce.c index f45cd43..9fb940e 100644 --- a/src/ZeroBounce.c +++ b/src/ZeroBounce.c @@ -59,6 +59,8 @@ static size_t write_callback(void *data, size_t size, size_t nmemb, void *client void set_write_callback(CURL* curl, memory* response_data) { curl_easy_setopt(curl, CURLOPT_WRITEFUNCTION, write_callback); curl_easy_setopt(curl, CURLOPT_WRITEDATA, (void*)response_data); + curl_easy_setopt(curl, CURLOPT_TIMEOUT, 120L); + curl_easy_setopt(curl, CURLOPT_CONNECTTIMEOUT, 30L); } long get_http_code(CURL* curl) {