Skip to content
TORNLIFE More

Log in user

Started by McNeo [864688] on in API Development.

13 replies · 129 views · thread synced · 5 days ago · View on torn.com
About this thread

Posts archived: 14 / 14 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
14
Discussion span
→
People posting
4
Likes on archived posts
3
Posts by staff, officers and moderators
2
Authority score
72 / 100
Historical score
20 / 100
Story score
30 / 100
Engagement score
53 / 100

Most-liked replies

McNeo [864688]

So, thus may belong in suggestions, but I'll start here.

I know the api is read only, and I know the functionality I'm looking for isn't publicly available, but...

Any chance of making a way for third party devs to allow users to auto login? Like city watch?
IceBlueFire [776] Officer Officer

As far as i know, that was never meant to happen for fear of outside automation. City Watch is one thing, because they can control it, but allowing it to users...may be a bit sketchy.
McNeo [864688]

The original third-party Android City Watch could do this, and was made by an outsider... How does one apply for such privileges?
IceBlueFire [776] Officer Officer

I believe he was having them log in, with his app already. I'm not entirely sure how it worked as i never trusted anything third party that required my torn details haha. But i believe that's how he was doing it, and using the old City Watch API for his notifications
McNeo [864688]

Hmmm, well it's a she I'm thinking of. And yes, log in credentials were provided to the app, then passes along to Torn the same way CityWatch does it.

I know this isn't exactly an API thing but, thought this might be a good place to start.
Mauk [1494436]

I'm against this idea because of the security implications. The API would need to be heavily reworked to support this use-case.

The official City Watch API does indeed use the player credentials for the login. It's a separate method of logging in, but it's essentially the same as the site, security-wise.
McNeo [864688]

It's really nice to just be able to click and be all logged in and ready to go. But most users probably save their credentials in their web browser or password manager anyway, so it's just one extra step.
McNeo [864688]

I'm not sure how you'd do it in any language? Remember, I'm coding a desktop program, not a web-based page/app/script.

CW, much like my new app and other, merely have buttons/links to open a respective Torn webpage. CW uses it's method to auto-login users when you do that - this is the functionality I'm looking to add, whatever magical code is it adds, like:

https://www.torn.com/citywatch-auth.php?version=2.0.6&username=[username]&time=1461791542&hashutp=[magicalcode]

Otherwise I'm just opening pages, like torn.com/items.php, and if the user isn't logged in, then it just redirects to the login page.
Mauk [1494436]

Just open an html page that POSTs the login form automatically. It can be a local html file, so it doesn't matter what technology your desktop application is using.

You could also authenticate directly with Torn and edit the browsers' cookies, but that'd be very hacky.

CityWatch's "magical code" is actually MD5(lowercase(username) + time + HMAC-SHA512(password, citywatch-secret)). It's homemade crypto.
McNeo [864688]

Yeah I have no idea how so send POST data lol. I've played around with trying to import cookies and sessions in the past and got nowhere.