ciudadanointeligente / write-it

App to create and send messages to public persons. It's a component of POPLUS project.
poplus.org
GNU General Public License v3.0
38 stars 23 forks source link

You can push as many messages as you want through the API #623

Open lfalvarez opened 9 years ago

lfalvarez commented 9 years ago

And a bot can create several messages.

lfalvarez commented 9 years ago

Approaches which we could use to fix this problem:

martinszy commented 9 years ago

API keys for individual messages? You have to obtain the key before displaying the form. This will double api requests and will get us into a semi-authenticated scheme I'm not very fond of. El mar 24, 2015 5:53 PM, "Luis Felipe Álvarez Burgos" < notifications@github.com> escribió:

Approaches which we could use to fix this problem:

— Reply to this email directly or view it on GitHub https://github.com/ciudadanointeligente/write-it/issues/623#issuecomment-85620055 .

lfalvarez commented 9 years ago

do you have somewhere where to read? I wouldn't know how to do it

martinszy commented 9 years ago

I just searched for ror api keys and these articules turned up: http://railscasts.com/episodes/352-securing-an-api?view=asciicast http://blog.joshsoftware.com/2014/05/08/implementing-rails-apis-like-a-professional/

They are on topic, but I haven't read in detail so I can't assure every recommendation is worth implementing. We can discuss further or maybe just implement the other approaches you were proposing.

Martín.

2015-03-24 18:44 GMT+00:00 Luis Felipe Álvarez Burgos < notifications@github.com>:

do you have somewhere where to read? I wouldn't know how to do it

— Reply to this email directly or view it on GitHub https://github.com/ciudadanointeligente/write-it/issues/623#issuecomment-85638203 .

Martín Szyszlican Desarrollo web usable y accesible martinszyszlican.com