4 ms·
It's an NPM package that people download - how would you store it outside the repo such that people that download the package can reference the token? Can't rea
by jaebradley 10y ago
It's an NPM package that people download - how would you store it outside the repo such that people that download the package can reference the token? Can't really use an environment variable at that point, right? There probably has to be some HTTP request to some service that ends up forwarding the request to Uber with the token. Maybe I'm over-thinking this...
- lexpar 10y agoI think the idea is that you implement some interface for interested users to supply their own API keys.
- Chloro 10y agoYep!
- jaebradley 10y agoGotcha - ok, that certainly makes sense. Though makes for a slightly less friendly (but certainly more secure) service.
- mr_turtle 10y agoA friend of mine accidentally pushed his Heroku or New Relic API key to a toy repo which was public and that information was immediately scraped and used. He was billed a non trivial about which he disputed but cost some time and headache. Enforce best practices and don't do that even if it's for something trivial and won't have real world consequences.
- elgenie 10y ago$ uber time '123 anywhere st' No API key found. Please create one using the instructions at <site> and call 'uber set-key <key>' $ uber set-key <key> # writes <key> to a file in home dir or a .gitignore location in the repo Well done! $ uber time '123 anywhere st' # reads <key> from file, works as you have it ...
- dzhiurgis 10y agoHow does Google Maps get this information? They probably have their middleware, right?
- kfrzcode 10y agoSo if I clone this repo I can now access your API account? Might want to pull this repository from Github......
- divbit 10y agoI guess it might be better to disable the api key...
- jaebradley 10y agoYou would have access to my server token, certainly. But I checked the documentation and in order to request rides, I think you would need other pieces of information that I did not expose. Additionally, there are various scopes that Uber grants regarding the API exposure that any application has. I think / hope that the worst damage that can be done is hitting Uber's rate limit. Definitely not defending my decision to include the server token, but I don't think it's the end of the world (just terrible practice).
- amenghra 10y agountil they launch a new API endpoint and forget to enforce something...
- throwanem 10y ago> Can't really use an environment variable at that point, right? Why not?