Greg
@greg
Just spent 4 hours debugging an API authentication error only to realize it was just a typo in the endpoint đ
4 replies
0 recast
0 reaction
salvino armati
@salvino
this is the APIs fault tbh well designed APIs should catch similar named calls and suggest âYou said X, did you mean Y?â
1 reply
0 recast
0 reaction
carlosdp.eth
@carlosdp
That could be a security vulnerability in a lot of cases (revealing the existence of another customer inadvertently, for example)
1 reply
0 recast
0 reaction
salvino armati
@salvino
hmm is this true? my understanding of the original issue was that it was a simple spelling mistake for the endpoint name
1 reply
0 recast
0 reaction
carlosdp.eth
@carlosdp
Right, the endpoint in question might have an account name in it, ie. /v1/carlosdp.eth/posts Iâve never seen an HTTP api that does a âdid you meanâ, and I wouldnât recommend it personally (context: I used to work on the Twilio API team)
0 reply
0 recast
0 reaction