Skip to content
TORNLIFE More

Permissions-restricted API Keys

Started by sullengenie [1946152] on in API Development.

10 replies · 167 views · thread synced · 5 days ago · View on torn.com
About this thread

Posts archived: 11 / 11 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
11
Discussion span
→
People posting
6
Likes on archived posts
15
Authority score
52 / 100
Historical score
31 / 100
Story score
37 / 100
Engagement score
56 / 100
sullengenie [1946152]

I suspect the people who frequent this forum have some appreciation for how much power you give someone when you hand them (or their service) your API key. They instantly have access to your inventory, your battle stats, who you're sending messages with, when you're on/off drug cooldown, etc. This is a silly amount of personal information to give out to a script/service that may have limited functionality, like notifying you when you receive a new message.

I would love to see a system where players can have multiple API keys (a max of 10, perhaps?) and control which endpoints each key has access to. I would be much more likely to sign up for services if I could restrict their access to just the information they need. Maybe this control could be toggled as "advanced controls" so as not to confuse players that do not care.

I'm posting this in the API forums to solicit feedback. Do you think this would be a worthwhile investment of developer time? Do you have suggestions for how it could be best implemented?
saeed [1826888]

+1

basically exactly as you said, or maybe have "app-registry" where you have to authorize access from an app and set per-app perms?

kinda like discord, you register your app in one place and then per-server can change perms.



not sure how to implement an authorization system though.
Mauk [1494436]

I mean, I could care less, but it's pretty down there on my personal wishlist. :/

(btw, not a diss at proposing it. it'd be pretty neat. I just have tons of api needs that I'd consider more important)
Mauk [1494436]

In no particular order (and some could be implemented in terms of others): forums access, typed events (instead of plain strings), typed hospital/jail timings, warbase access or batched user calls, users by nick, search (users, factions, etc), oc... Non-exhaustive list from the top of my head. If I were to search through my users' feature requests, I could probably double this. :P

Some of these are certainly not as important or prominent as this thread's topic, but I don't see the lack of API keys flexibility a real blocker so far. There are too few developers working on api stuff-- it's easy enough taking care of that with good ol' trust.
sullengenie [1946152]

I also would particularly enjoy seeing batched user calls and cleanup of null attributes, which are sometimes 0, sometimes "", and sometimes null.
Mauk [1494436]

The nulls thing'd be awesome. d:

I was thinking a bit more about the multiple keys thing and came to the conclusion I don't think it's a net gain. Most people barely know what an api key is, and having the security on their hands doesn't seem that much better (could be wrong). If they were to implement better security, I say go full on authenticated services/oauth, so that if a creator goes rogue they can revoke every api key given to the service.