Skip to content
TORNLIFE More

API Suggestions

Started by LuigiMangione [1870934] on in API Development.

6 replies · 65 views · thread synced · 5 days ago · View on torn.com
About this thread

Posts archived: 7 / 7 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
7
Discussion span
→
People posting
5
Likes on archived posts
1
Posts by staff, officers and moderators
1
Authority score
70 / 100
Historical score
16 / 100
Story score
25 / 100
Engagement score
43 / 100

Most-liked replies

LuigiMangione [1870934]

Hey everyone! I had 2 suggestions to make the API system more secure.
1) You should be able to generate multiple API keys for different applications. If an application misuses your data, you can revoke just one key instead of having to reset them on all applications.
2) API keys should have permission settings. For example, a chaining app doesn't need access to cash information. A cash-management app doesn't need access to stat info.
---------------
Are these good suggestions?
Mods: I'm not sure if this should go in the suggestion forum or the API forum, please move if needed.
McNeo [864688]

I think it's more up to the player to use a reputable person.

The apps I'm developing have an explicit notice saying that nothing is saved or transmitted and the data is only used within the app, and that's true, simple as that.

Now, could a malicious person make the same notice and lie about it? Sure they could. But, if something were to happen and as patterns form, I'm sure Torn is ready to ban the offending apps from making API requests. Also, if you think something is fishy, you can change your API key. (i.e. you start using a "cash management" tool and the next day you start getting mugged non-stop).

One thing to look for may be apps that are open source, so yourself or others can check to see what the code is doing. Alternatively, like I said, just use a trustworthy source. (don't install an app advertised by someone 2 days old, etc)
IceBlueFire [776] Officer Officer

We discussed both of these things for awhile, but ultimately chalked it up to a "Perhaps something we can add in the future", hoping to maintain an ease of use factor by not complicating it with multiple keys.

We'll see what the future holds!
Meme_Raven [1891116]

Or we could just go the open way and show our code so the end-user knows what's going on, no matter how horrible and poor the code is. You learn over time and end-user feedback is the best.
Mauk [1494436]

The solution will never be "require programming knowledge from every potential user," and any other "source code's available" situation would be built on implicit trust. That's an orthogonal discussion-- trust could still be broken.
Meme_Raven [1891116]

So you're telling me there's more trust in a 30 day old sample snippet than there is in a open Git system updated well, whenever the code is updated?

Things in Torn are highly confidential and using the API opens everything and all could be logged / cached.