I am having trouble with people misuse my API Endpoint which has been developed using PHP Flat, so to prevent others to access the API I have created a method on my own thoughts to prevent people to submit any request or to handle it by our serverside if it was not originated from our domain.
the code is written in PHP.
every time that I make an AJAX request from the page a token will be generated using this code
$token = sha1(date("Y-m-d H:i:s").session_id()."ITcanBEanyRANDOMstring");
$_SESSION['token'] = $token;
$_SESSION['is_used'] = FALSE;
then on the API End port website, it will check for the token using the code below
if(($_POST['token'] === $_SESSION['token']) && !$_SESSION['is_used']){
$_SESSION['is_used'] = true;
}
any other suggestion ? is this method secure !!