13 replies · 129 views · thread synced · 5 days ago
· View on torn.com
About this thread
Posts archived:14 / 14 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Counted by TornLife from the archived posts.
Archived posts
14
Discussion span
→
People posting
4
Likes on archived posts
3
Posts by staff, officers and moderators
2
Authority score
72 / 100
Historical score
20 / 100
Story score
30 / 100
Engagement score
53 / 100
Most-liked replies
IceBlueFire[776]Officer
· 2 likes · As far as i know, that was never meant to happen for fear of outside automation. City Watch is one thing, because they can control it, but allowing it to users...may be a bit sketchy.
IceBlueFire[776]Officer
· 1 likes · I believe he was having them log in, with his app already. I'm not entirely sure how it worked as i never trusted anything third party that required my torn details haha. But i believe that's how he was doing …
As far as i know, that was never meant to happen for fear of outside automation. City Watch is one thing, because they can control it, but allowing it to users...may be a bit sketchy.
I believe he was having them log in, with his app already. I'm not entirely sure how it worked as i never trusted anything third party that required my torn details haha. But i believe that's how he was doing it, and using the old City Watch API for his notifications
I'm against this idea because of the security implications. The API would need to be heavily reworked to support this use-case.
The official City Watch API does indeed use the player credentials for the login. It's a separate method of logging in, but it's essentially the same as the site, security-wise.
It's really nice to just be able to click and be all logged in and ready to go. But most users probably save their credentials in their web browser or password manager anyway, so it's just one extra step.
I'm not sure how you'd do it in any language? Remember, I'm coding a desktop program, not a web-based page/app/script.
CW, much like my new app and other, merely have buttons/links to open a respective Torn webpage. CW uses it's method to auto-login users when you do that - this is the functionality I'm looking to add, whatever magical code is it adds, like:
Just open an html page that POSTs the login form automatically. It can be a local html file, so it doesn't matter what technology your desktop application is using.
You could also authenticate directly with Torn and edit the browsers' cookies, but that'd be very hacky.
CityWatch's "magical code" is actually MD5(lowercase(username) + time + HMAC-SHA512(password, citywatch-secret)). It's homemade crypto.