For services like S3 or cloudinary, if you don’t have a backend, that means you need to give an access token to the frontend (which can be accessed by the user).
What services would you use instead to stay secure?
Restricting the scope of the access...