Skip Navigation

[Resolved] Toolset Maps and Google Maps API restrictions

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

This topic contains 3 replies, has 2 voices.

Last updated by Minesh 1 year, 8 months ago.

Assisted by: Minesh.

Author
Posts
#2566289

Google has started sending notifications to API key owners when credentials are publicly exposed on sites and not sufficiently restricted. Toolset has always had this problem and it has, at times, cost me and my clients a fair amount of money in API usage fees when credentials get stolen and abused.

Is Toolset ever going to enhance Maps so that we can use http referrer restrictions on the front-end Google Maps API Key credentials?

#2566809

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

Dont you able to restrict the google map site key from your google map API settings page?

More info:
- hidden link

#2566927

Hi Minesh, I know how to restrict Maps API keys. Toolset's documentation says that we cannot use http referrer restrictions. My question is whether that will ever change?

I have the browser keys restricted to javascript api and places api but I'd also like to restrict them to requests referred from the web server as I'm still seeing some abuse of the APIs with the restrictions that work with Toolset Maps and my clients are now getting emails from Google saying their API keys aren't well enough protected.

#2567603

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Here is the related ticket where one of the user solved the issue about http referer:
- https://toolset.com/forums/topic/google-maps-api-validation-restriction-error/#post-1809879

Can you please try to follow that and check if that helps?

Update:
Another source that might help:
- https://stackoverflow.com/questions/35288250/google-maps-javascript-api-referernotallowedmaperror