Skip to content
TORNLIFE More

Cloudflare affecting command line API requests?

Started by Murky [1839173] on in API Development.

22 replies · 407 views · thread synced · 6 days ago · View on torn.com
About this thread

Posts archived: 23 / 23 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
23
Discussion span
→
Authority score
68 / 100
Historical score
27 / 100
Story score
39 / 100
Engagement score
66 / 100

People posting, likes and official posts are not counted for this thread yet: on threads longer than one page they come from a periodic pass over the archive, which has not covered it.

Murky [1839173]

I request API calls from the command line.  I limit the calls per minute so avoid hitting the (now 60) limit.  It seems the recent outtage and now Cloudflare browser checks are affecting the ability to fetch URLs from anything other than a browser.

Is the above behavior related to Cloudflare, and is this temporary?

Edit: fixed typo for Cloudflare, 
Pi77Bull [2082618]

I am experiencing the same. Kind of annoying but they are likely already working on a fix.

Edit: Websites like Tornstats and userscripts that use the API don't work either. Doctorn is somehow not affected by this.
nepherius [2009878]

Had same issue with my scripts, it was caused by CORS policy, you should be able to see an error if you press F12 whenever you're using whatever script is not working.

Just need for owner to whitelist the API
Murky [1839173]

Pressing F12 won't do anything, i'm not using a web browser per-se, thus javascript not supported thus no make Cloudflare happy.  This is pure fetching of API data via the URL.  It works fine except when Cloudflare is likely set into anti-DDoS mode.  I just want to know if this is temporary.  I don't know why the subdomain api.torn.com is subject to this cloudflare stuff when the API has a built in way to reject too many API requests per minute -- and if more DDoS type requests are made to api.torn.com why aren't those just IP blocked.  
UwU [2081212]

Yes this is widespread.

 

DocTorn isn't affected because it makes the api call through the same browser you completed the JS challenge on. 

 

But for direct http requests via python console or anything like that will fail because it cannot pass the JS challenge.

 

Can't do much about this because I think any workaround to bypass the cloudfare protection would result in us breaching the TOS.

 

Very annoying, because I had just finished adjusting everything to accommodate the new 60 call limit which worked for a day and now nothing works. 
Murky [1839173]

Yes, last weekend was a different shutdown, sucks.   - i don't think rigging browser output breaches TOS if you stick to api.torn.com subdomain calls but it's pushing the spirit of what the TOS was written against.  Need torn to just get us back to normal.  Wanna know if this is temporary but in the back of my mind i know it'll happen again.  Be nice if there were a better solution for the community that doesn't write browser based scripts and wanna keep everything legit.
Max_Cohen [512123]

Maybe this is why I'm getting a 503 Server Unavailable. Or who knows. The API is down so much there seems to be little point trying to do any development against it. May as well just use tampermonkey and scrape the page.
chadmck [2163132]

Yeah my app is also affected. Until they cut turn open CORS back on , or whitelist our servers, there isnt much we can do. I hope it's temporary , or that they are willing to add header configs for us. 
nepherius [2009878]

Works fine for my apps and scripts with slight changes. Only one still having issues with is my server - torn.market- but didn't have much time to work on it and find a fix
UwU [2081212]

That's because you're making API calls via the browser you already solved the JS challenge on.

 

It still won't work on standalone services that consume the API. For many of those services, running it in a user browser via Tampermonkey or custom extension is not a viable solution.
tonyuh [2093883]

Its not really a solution if you need to get infomation from the browser before you can make any calls, not all servers have GUI so using browser is out of the question, unless you have some clever way of doing JS challenge without using a browser.