I'v been running a test with my faction api access, im the only member with faction access to the API
the setting is in the faction control permissions under AA
if i share my API key with someone, they can access the faction data without having faction permissions
this dont sound right
has someone missed this
I don't know how else they'd control this. If you give someone your API key, they have access to everything your user has access to. If your faction gives you API access, then you have access to it, and so does anyone with your API key.
People may develop tools that use the factions information, so this would be the only way to get it. If I developed such a tool, for example, it wouldn't seem write for your faction to give me access.
I understand what you're saying and I see the potential risk here, but how else could they do it?
> how else could they do it?
How about a Faction Key that Leader and Co can set and share with users they trust (and get rid of the AA permission altogether)?
It completely slipped my mind that Torn Stats does just that
It not safe at all, a slip of information without thinking could spark off wars.
a solution would be an External Permissions list in the Factions Control Panel with User Info or Web Address
how this will work out, i don't know!
:/
Better Idea than mine
thumbs up :)
Currently, if "player" wants to use an app that needs faction API access, then the faction leader grants this access. Now, *ANY* API app the player uses has faction API access. So yes, I see the risk.
If the faction had an API key that were handed out, what happens if a player leaves the faction? The faction API would need to be reset, and the other 99 members would lose access until they update it where need be. The AA permission in the faction is meant to automate this process, so only faction members have access.
Just like you as a player need to be responsible of who you give your API key to, factions need to be responsible to who they give AA access to.
Well, IMHO a "faction app" should be installed somewhere and accessible by all members (with simple login eventually).
Only the app developer(s) and the leaders should know the faction key and resetting it would require a change in a single place.
Of course if you want to give each single user the ability to run their own copy of the app, that wouldn't work.
We tossed around that idea, and eventually decided against it, leaving it in the faction leaders' hands to hand out permission to the members. It's the members responsibility to be smart about where they're putting their key.
That said, it's only read only. So the most harm that comes of it is they see how much money is in a faction...that will never get destroyed...or potentially they could get the attack news and see who is making the hits.
We knew factions were a sensitive subject, which is why they were given their own permission level while nothing else in the game got that. Leaders be smart about it and there won't be an issue.