- Manual labor 41,097
- Intelligence 54,608
- Endurance 55,250
- Total 150,950
AdmiralSnackbar: forum
AdmiralSnackbar [2112923] Level 60
- Forum posts (Torn's count)
- 17 observed
- Archived posts
- 13
- Threads started (archived)
- 3
Boards
From the 13 newest archived posts.
- API Development
- Company Recruitment
- Bugs & Issues
Threads started
Most-liked posts
Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.
This is so bad, wrong, dangerous etc. in so many ways...
Think about what a URL is. URLs are public. People copy and paste them. They share them, they put them on advertisements. Nothing prevents someone (knowingly or not) from mailing that URL around for other people to use. If your API key is in that URL, everybody has it.
1. There is a web standard for a reason. See here
2. Sharing URL means users sensitive API_KEYS get shared too.
3. Even with HTTPS your API_KEY isn't safe from being stolen.
4. Man in the middle attacks listening on the public api for URLs with users API_KEYS
So, my question is why not follow the web standard and pass any tokens, keys etc via the authorization bearer token at the very least?
So yeah… tried generating a TypeScript SDK from your openapi.json (https://www.torn.com/swagger/openapi.json) and it’s… insane. All the function names are hashes. I mean literally:
```typescript
import { createClient } from "../generated/torn/client/index.js";
import { c82d282102d0d4f54768a6a465639673, 94dfc0c0663c9dc53241abbc59e39597 } from "../generated/torn/sdk.gen.js";
const client = createClient({ auth: process.env.TORN_API_KEY });
const myFaction = await c82d282102d0d4f54768a6a465639673({ client });
const otherFaction = await 94dfc0c0663c9dc53241abbc59e39597({ client, query: { id: 12345 } });
```
I can’t remember these names. I can’t explain them to anyone. They work… technically… but this is unusable in any real code.
If the operationIds were descriptive, like:
```typescript
import { getMyFaction, getUserFaction } from "../generated/torn/sdk.gen.js";
const myFaction = await getMyFaction({ client });
const otherFaction = await getUserFaction({ client, query: { id: 12345 } });
```
…then it would be readable, obvious, and maintainable.
Steps to reproduce:
- Use https://www.torn.com/swagger/openapi.json.
- Generate a TypeScript SDK with @hey-api/openapi-ts and operations.strategy = "flat".
- Notice all function names are long hashes.
- Switching to byTags or single doesn’t really help.
Suggested fix:
- Replace hashed operationIds with descriptive ones:
```json
"/user/faction": { "get": { "operationId": "getMyFaction", ... } },
"/user/{id}/faction": { "get": { "operationId": "getUserFaction", ... } }
```
That’s it. No hacks, no wrappers needed, just readable function names.
Can users make feature requests?
I'd really like to contribute to torn's code base and look into refactoring the api to follow web standards.
p.s. working professionally as software engineer for a couple years with go, kubernetes, react mostly
Recent archived posts
Thank you so much!
Can confirm as seeing proper names instead of hash codes.
So yeah… tried generating a TypeScript SDK from your openapi.json (https://www.torn.com/swagger/openapi.json) and it’s… insane. All the function names are hashes. I mean literally:
```typescript
import { createClient } from "../generated/torn/client/index.js";
import { c82d282102d0d4f54768a6a465639673, 94dfc0c0663c9dc53241abbc59e39597 } from "../generated/torn/sdk.gen.js";
const client = createClient({ auth: process.env.TORN_API_KEY });
const myFaction = await c82d282102d0d4f54768a6a465639673({ client });
const otherFaction = await 94dfc0c0663c9dc53241abbc59e39597({ client, query: { id: 12345 } });
```
I can’t remember these names. I can’t explain them to anyone. They work… technically… but this is unusable in any real code.
If the operationIds were descriptive, like:
```typescript
import { getMyFaction, getUserFaction } from "../generated/torn/sdk.gen.js";
const myFaction = await getMyFaction({ client });
const otherFaction = await getUserFaction({ client, query: { id: 12345 } });
```
…then it would be readable, obvious, and maintainable.
Steps to reproduce:
- Use https://www.torn.com/swagger/openapi.json.
- Generate a TypeScript SDK with @hey-api/openapi-ts and operations.strategy = "flat".
- Notice all function names are long hashes.
- Switching to byTags or single doesn’t really help.
Suggested fix:
- Replace hashed operationIds with descriptive ones:
```json
"/user/faction": { "get": { "operationId": "getMyFaction", ... } },
"/user/{id}/faction": { "get": { "operationId": "getUserFaction", ... } }
```
That’s it. No hacks, no wrappers needed, just readable function names.
- Manual labor 41,097
- Intelligence 54,608
- Endurance 55,250
- Total 150,950
Can users make feature requests?
I'd really like to contribute to torn's code base and look into refactoring the api to follow web standards.
p.s. working professionally as software engineer for a couple years with go, kubernetes, react mostly
programmers are surely able to use the URL with the requirement of auth headers, are they not?Hmm...no. If I understand correctly. If one tries to make a request to the torn API by setting the "X-Api-Key" in the header. Something like this:
const response = await fetch(`https://api.torn.com/user/?selections=profile`, {
headers: {
"Content-Type": "application/json",
"X-Api-Key": process.env.API_KEY,
}
});
const userProfile = await response.json();
It doesn't work at all. However setting it in the URL params does work but refer back to why its less than ideal in original post.
1. via the URL parameter for newbies getting into programming
2. via headers for others who want to build custom user interfaces / apis
I couldn't find information on point 2.
For extra context I'm basing it around this.
This is so bad, wrong, dangerous etc. in so many ways...
Think about what a URL is. URLs are public. People copy and paste them. They share them, they put them on advertisements. Nothing prevents someone (knowingly or not) from mailing that URL around for other people to use. If your API key is in that URL, everybody has it.
1. There is a web standard for a reason. See here
2. Sharing URL means users sensitive API_KEYS get shared too.
3. Even with HTTPS your API_KEY isn't safe from being stolen.
4. Man in the middle attacks listening on the public api for URLs with users API_KEYS
So, my question is why not follow the web standard and pass any tokens, keys etc via the authorization bearer token at the very least?
Active daily
Looking for good pay
- Manual labor: 23,646
- Intelligence: 22,828
- Endurance: 29,639
Intelligence 20,389
Endurance 25,481
Looking for a *8+ Television Network.
Subscriber active daily.
New player looking to join a company
Active daily, willing to start on low salary of $10,000.
Stats:
Manual Labour: 323
Endurance: 399
Intelligence: 466
New player looking to join any company.
Active daily, starting salary of $10,000.
Stats:
Manual Labour: 323
Intelligence: 466
Endurance:399