Skip to content
TORNLIFE More

AdmiralSnackbar: forum

AdmiralSnackbar [2112923] Level 60

Forum posts (Torn's count)
17 observed
Archived posts
13
Threads started (archived)
3

Boards

From the 13 newest archived posts.

Threads started

Most-liked posts

Likes as archived at fetch time, adjusted for how long each post had been up. Scored posts only; the full score pass runs after the import.

Looking for Work? Post your Stats here · · 1 like

Hi there, I'm looking to join a new company
  • Manual labor 41,097
  • Intelligence 54,608
  • Endurance 55,250
  • Total 150,950

Pass API_KEY via Authorization headers not URL · · 7 likes

I'm just starting to get into the TORN api and the first thing that I noticed that is REALLY BAD is why do we pass the API_KEY via URL parameters???

This is so bad, wrong, dangerous etc. in so many ways...

Think about what a URL is. URLs are public. People copy and paste them. They share them, they put them on advertisements. Nothing prevents someone (knowingly or not) from mailing that URL around for other people to use. If your API key is in that URL, everybody has it.


1. There is a web standard for a reason. See here
2. Sharing URL means users sensitive API_KEYS get shared too.
3. Even with HTTPS your API_KEY isn't safe from being stolen.
4. Man in the middle attacks listening on the public api for URLs with users API_KEYS

So, my question is why not follow the web standard and pass any tokens, keys etc via the authorization bearer token at the very least?

Hashed operationIds in OpenAPI · · 2 likes

So yeah… tried generating a TypeScript SDK from your openapi.json (https://www.torn.com/swagger/openapi.json) and it’s… insane. All the function names are hashes. I mean literally:

 

```typescript

import { createClient } from "../generated/torn/client/index.js";
import { c82d282102d0d4f54768a6a465639673, 94dfc0c0663c9dc53241abbc59e39597 } from "../generated/torn/sdk.gen.js";

const client = createClient({ auth: process.env.TORN_API_KEY });

const myFaction = await c82d282102d0d4f54768a6a465639673({ client });
const otherFaction = await 94dfc0c0663c9dc53241abbc59e39597({ client, query: { id: 12345 } });

```

I can’t remember these names. I can’t explain them to anyone. They work… technically… but this is unusable in any real code.

If the operationIds were descriptive, like:


```typescript
import { getMyFaction, getUserFaction } from "../generated/torn/sdk.gen.js";

const myFaction = await getMyFaction({ client });
const otherFaction = await getUserFaction({ client, query: { id: 12345 } });

```


…then it would be readable, obvious, and maintainable.

 

Steps to reproduce:

- Use https://www.torn.com/swagger/openapi.json.

- Generate a TypeScript SDK with @hey-api/openapi-ts and operations.strategy = "flat".

- Notice all function names are long hashes.

- Switching to byTags or single doesn’t really help.

Suggested fix:

- Replace hashed operationIds with descriptive ones:


```json
"/user/faction": { "get": { "operationId": "getMyFaction", ... } },
"/user/{id}/faction": { "get": { "operationId": "getUserFaction", ... } }

```

That’s it. No hacks, no wrappers needed, just readable function names.

Feature Requests · · 0 likes

Is torn an open source app?

Can users make feature requests?

I'd really like to contribute to torn's code base and look into refactoring the api to follow web standards.

p.s. working professionally as software engineer for a couple years with go, kubernetes, react mostly

Recent archived posts

Hashed operationIds in OpenAPI · · 1 like

Thank you so much! 

Can confirm as seeing proper names instead of hash codes.

Hashed operationIds in OpenAPI · · 2 likes

So yeah… tried generating a TypeScript SDK from your openapi.json (https://www.torn.com/swagger/openapi.json) and it’s… insane. All the function names are hashes. I mean literally:

 

```typescript

import { createClient } from "../generated/torn/client/index.js";
import { c82d282102d0d4f54768a6a465639673, 94dfc0c0663c9dc53241abbc59e39597 } from "../generated/torn/sdk.gen.js";

const client = createClient({ auth: process.env.TORN_API_KEY });

const myFaction = await c82d282102d0d4f54768a6a465639673({ client });
const otherFaction = await 94dfc0c0663c9dc53241abbc59e39597({ client, query: { id: 12345 } });

```

I can’t remember these names. I can’t explain them to anyone. They work… technically… but this is unusable in any real code.

If the operationIds were descriptive, like:


```typescript
import { getMyFaction, getUserFaction } from "../generated/torn/sdk.gen.js";

const myFaction = await getMyFaction({ client });
const otherFaction = await getUserFaction({ client, query: { id: 12345 } });

```


…then it would be readable, obvious, and maintainable.

 

Steps to reproduce:

- Use https://www.torn.com/swagger/openapi.json.

- Generate a TypeScript SDK with @hey-api/openapi-ts and operations.strategy = "flat".

- Notice all function names are long hashes.

- Switching to byTags or single doesn’t really help.

Suggested fix:

- Replace hashed operationIds with descriptive ones:


```json
"/user/faction": { "get": { "operationId": "getMyFaction", ... } },
"/user/{id}/faction": { "get": { "operationId": "getUserFaction", ... } }

```

That’s it. No hacks, no wrappers needed, just readable function names.

Looking for Work? Post your Stats here · · 1 like

Hi there, I'm looking to join a new company
  • Manual labor 41,097
  • Intelligence 54,608
  • Endurance 55,250
  • Total 150,950

Feature Requests ·

For clarity, I mean as a hobby or in my own time.

Feature Requests ·

Is torn an open source app?

Can users make feature requests?

I'd really like to contribute to torn's code base and look into refactoring the api to follow web standards.

p.s. working professionally as software engineer for a couple years with go, kubernetes, react mostly

Pass API_KEY via Authorization headers not URL ·

Thank you. I guess we are stuck with the snowflake API the torn devs provide us with.

Pass API_KEY via Authorization headers not URL ·

programmers are surely able to use the URL with the requirement of auth headers, are they not?
Hmm...no. If I understand correctly. If one tries to make a request to the torn API by setting the "X-Api-Key" in the header. Something like this:

const response = await fetch(`https://api.torn.com/user/?selections=profile`, {
headers: {
"Content-Type": "application/json",
"X-Api-Key": process.env.API_KEY,
}
});

const userProfile = await response.json();

It doesn't work at all. However setting it in the URL params does work but refer back to why its less than ideal in original post.

Pass API_KEY via Authorization headers not URL ·

In that case providing two mechanisms would be great.

1. via the URL parameter for newbies getting into programming
2. via headers for others who want to build custom user interfaces / apis

I couldn't find information on point 2.

For extra context I'm basing it around this.

Pass API_KEY via Authorization headers not URL · · 7 likes

I'm just starting to get into the TORN api and the first thing that I noticed that is REALLY BAD is why do we pass the API_KEY via URL parameters???

This is so bad, wrong, dangerous etc. in so many ways...

Think about what a URL is. URLs are public. People copy and paste them. They share them, they put them on advertisements. Nothing prevents someone (knowingly or not) from mailing that URL around for other people to use. If your API key is in that URL, everybody has it.


1. There is a web standard for a reason. See here
2. Sharing URL means users sensitive API_KEYS get shared too.
3. Even with HTTPS your API_KEY isn't safe from being stolen.
4. Man in the middle attacks listening on the public api for URLs with users API_KEYS

So, my question is why not follow the web standard and pass any tokens, keys etc via the authorization bearer token at the very least?

Looking for Work? Post your Stats here ·

Subscriber status
Active daily
Looking for good pay
  • Manual labor: 23,646
  • Intelligence: 22,828
  • Endurance: 29,639

Looking for Work? Post your Stats here ·

Manual labor 23,646
Intelligence 20,389
Endurance 25,481

Looking for a *8+ Television Network.
Subscriber active daily.

Looking for Work? Post your Stats here ·


New player looking to join a company

Active daily, willing to start on low salary of $10,000.

Stats:



Manual Labour: 323

Endurance: 399

Intelligence: 466


Looking for Work? Post your Stats here ·


New player looking to join any company.

Active daily, starting salary of $10,000.

Stats:

Manual Labour: 323

Intelligence: 466

Endurance:399