3 ms·
Iron Money’s API[1] is RESTful and protected with OAuth 1.0a; since it uses the plaintext signature method, no nonce is used for each request. I’m not quite su
by rendezvouscp 15y ago
Iron Money’s API[1] is RESTful and protected with OAuth 1.0a; since it uses the plaintext signature method, no nonce is used for each request.
I’m not quite sure what your security question is. Since the API and web app use different authentication schemes and have different endpoints, there is no risk of CSRF.
[1] https://ironmoney.com/api/ https://ironmoney.com/api/
- NanoWar 15y agoI don't see HATEOAS ("API browsing") there at all. Only in the documentation[1] I see the resource layout one time... [1] https://ironmoney.com/api/resources/ https://ironmoney.com/api/resources/
- rendezvouscp 15y agoYes, hence “RESTful.” The API is definitely not a prime example of a REST API since it doesn’t return the URIs of resources. It does, however, generally follow the other constraints.