Skip to content
TORNLIFE More

Add new API keys per user

Started by L4suicide [15699] on in API Development.

6 replies · 102 views · thread synced · 7 days ago · View on torn.com
About this thread

Posts archived: 7 / 7 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
7
Discussion span
→
People posting
5
Likes on archived posts
9
Authority score
66 / 100
Historical score
19 / 100
Story score
30 / 100
Engagement score
50 / 100
L4suicide [15699]

So I was talking with Ucan and he suggested Ched adds a 2nd api key per user with less access

Well..

I expand on this. Just like with other web services perhaps we could create api profiles for ourselves.

Users can go and create a new profile, with a new key, and set WHAT access that key gets. Then users can share different keys with different services (or even people they trade with or something)

The original key which gives full access stays as is, as we know most users wouldn't understand. But for those of us who build tools for our own factions then it gives us ways of accessing things like nerve bar, without giving stats away or money on hand, which is the main reason I hear when people don't want to sign up to tornstats etc.

 

I doubt this would mean many changes to the api itself, so the work involved would be building something to manage these profiles and ensuring that wherever they are stored can cope with multiple keys per user.. 

I assume there is already some kind of check in place for public vs private info, so prolly some small tweaks there to incorporate some groupings of api permissions..

thoughts, feelings and notes?
aurigus [37524]

API keys should have specific access right associated to them. They should also be created and able to be deleted with those certain access rights. Right now it's an 'all or nothing' approach. 

I'd like to see a write api as well, but I know we are trying to prevent automated playing so that might not make much sense. 
Kivou [2000607]

Very good idea.

I see that useful for faction management like getting energy/drug CD of members for chain watch. Or drug addiction for directors...
Helcostr [1934501] Wiki Editor

A write api that could make sense are stuff like chatbox (for discord chatroom sync, mainly i look for read access), forum access (questionable), mail (customized mail per user using some code to replace variables): they are all informational, and don't directly affect gameplay too much. This api would still fall under spam prevention, and probably would share the same (or even longer) cooldown: you wouldn't beable to use the write api to send a mail message, if you already sent a mail message.

Other stuff can be chat management (request multiple chat windows to be closed), adding friends (not enemies though, since the enemy list does have an in game impact.. still can be discussed).

So a write API does make alot of sense, as long as it is kept away from the main body of the game.
Helcostr [1934501] Wiki Editor

its why i highlight read, more than write. think of this in terms of faction chat and communication, not the messy public chat rooms