3 ms·
I was stressful whenever my teammates, talented developers, share the curl, which including the secret credentials like - Authorization Token, for detecting and
by _thinx 4y ago
I was stressful whenever my teammates, talented developers, share the curl, which including the secret credentials like - Authorization Token, for detecting and resolving the issues. So, I am curious that how you guys do that ? There have any better way to send an API bug report ?
Updated:
--
I think that way is not secure enough. For example, I can use Secret Token, which is exposed in curl, to do something like ~ buying my own stuff .
So, there have anyway to secure the curl ? But we are still easy to detect the API issue.
- metadat 4y agoWhat? Why is it a real problem? If you don't like curl, think maybe you're more of a postman person?
- _thinx 4y agoI think that way is not secure enough. For example, I can use Secret Token, which is exposed in curl, to do something like ~ buying my own stuff . So, there have anyway to secure the curl ? But we are still easy to detect the API issue.
- metadat 4y agoMaybe when they share it, replace the secret with a shell variable? Solved!
- _thinx 4y agoI thought about that way. But, we can't re-produce or see the API's response. So, it so hard to detect the API's issue, right :?
- metadat 4y agoWhat real problem does the sharing cause?
- _thinx 4y agoSorry, maybe I don't say clearly enough :(. Let show some code, hope it easy to understand. I found that, the order listing API doesn't work as expected. I send the curl to my teammate. Please take a look at `-H 'X-Access-Token: SECRET_TOKEN' \` ``` curl 'https://mocha.lozi.vn/v6/users/me/orders https://mocha.lozi.vn/v6/users/me/orders' \ -X GET \ -H 'X-Access-Token: SECRET_TOKEN' \ -H 'Host: mocha.lozi.vn' \ -H 'User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:101.0) Gecko/20100101 Firefox/101.0' \ -H 'Accept: /' \ -H 'Accept-Language: vi_VN' \ -H 'Accept-Encoding: gzip, deflate, br' \ -H 'X-Lozi-Client: 1' \ -H 'X-City-ID: 50' \ -H 'Origin: https://loship.vn https://loship.vn' \ -H 'Connection: keep-alive' \ -H 'Referer: https://loship.vn/ https://loship.vn/' \ -H 'Sec-Fetch-Dest: empty' \ -H 'Sec-Fetch-Mode: cors' \ -H 'Sec-Fetch-Site: cross-site' ``` The problem is: 1/ If I don't replace the real token by SECRET_TOKEN, others can use it to buying their own stuffs, by my token. :( 2/ If I replace the real token by SECRET_TOKEN, it's so hard to detect what the problem is, cause my teammate can't see the response, and can't request to re-produce the issue too.
- _thinx 4y agoActually, I'm a terminal guy, and I like to use curl than postman