4 ms·
Yeah here they’re talking about a JSON API and then just “serving HTML” (which is its own API). I really think it’s so valuable to take what you use internally
by rtpg 3y ago
Yeah here they’re talking about a JSON API and then just “serving HTML” (which is its own API).
I really think it’s so valuable to take what you use internally seriously, exposing and documenting it to end users is a great way to avoid hackiness, and just leads to more regular designs IMO. More work of course but … not that much in the vast majority of cases
- BlueTemplar 3y agoAnother issue might be security ? Completely different assumptions about it between internal and external sounds like you would want avoid sharing them anyway ?
- erhaetherth 3y ago1st party APIs that are exposed to the client need to be secure anyway or users will discover and start using it. I found a library on GitHub that does exactly this to our app. They reverse-engineered nearly everything. I'm sure we could break the lib if we encrypt a few tokens but no one seems to care. I don't mind either, since we clearly aren't giving users a proper API.