Skip to content
TORNLIFE More

how-to

Started by Stomps [1958934] on in API Development.

8 replies · 194 views · thread synced · 5 days ago · View on torn.com
About this thread

Posts archived: 9 / 9 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
9
Discussion span
→
People posting
5
Likes on archived posts
3
Posts by staff, officers and moderators
1
Authority score
72 / 100
Historical score
19 / 100
Story score
29 / 100
Engagement score
53 / 100

Most-liked replies

Stomps [1958934]

Ok, Im taking my first step here. I know the url etc (the absolute basic, lol) but how do I create an input so I can search an view profiles?
Dr-Greenthumb [87775]

This is how you would grab strength, for example, but you will need both the user's ID and key to access the information.

<?php

$user_id = ''; //User ID
$api_key = ''; //Personal API Key

$api_link = "http://api.torn.com/user/$user_id?selections=battlestats&key=$api_key"; //Link to JSON data

$json = file_get_contents($api_link); //Request JSON data from API
$data = json_decode($json, true); //Decode JSON as array

echo $data['strength'];

?>

Meme_Raven [1891116]

HTML that POSTs to a PHP page, but it's insecure and leaves the API key visible and easy to sniff. HTTPS + DB + Scrambled API is my best bet. No idea if it works, I've yet to get to that stage
Dr-Greenthumb [87775]

This is true. But none of this site runs of HTTPS anyhow - including the API. If you're going to go as far as keeping it secure, another way is to store the key outside of the public folder and/or encrypt it.
Meme_Raven [1891116]

The main site runs https, API doesn't though. Perhaps encryption via client JS will be OK but that's a lot of work and more hours making a decoder. Believe me, I tried with a Windows - Windows client.
Dr-Greenthumb [87775]

Oh yeah, haha, I didn't even look at the address bar :P I think if people are really concerned about losing their API key then maybe it would be best for them not to create anything at all at this moment in time - unless they really want to put the effort in. Or treat it how you would database information - aforementioned - possibly storing it outside of the public_html.
IceBlueFire [776] Officer Officer

If you want bare bones, try something like this:


<html> <head> <title>Simple Form and API Tutorial</title> </head> <body> <form method="POST" action="<?php echo 'http://'.$_SERVER['HTTP_HOST'].$_SERVER['PHP_SELF']; ?>"> <p>ID: <input type="text" id="user_id" name="user_id"></p> <p><input type="submit" name="Submit" value="Submit"></p> </form> <?php if(isset($_POST['user_id'])) { $apikey = ''; // Your API key $user_id = $_POST['user_id']; $url = "http://api.torn.com/user/$user_id?selections=profile&key=$apikey"; // URL to get the user's profile contents $json = file_get_contents($url); // Read the JSON response from the server $data = json_decode($json, true); // Convert JSON into a PHP array } ?> <pre> <?php print_r($data); ?> </pre> Name: <?php echo $data['name']; ?> </body></html>