3 ms·
I think an electronic keypad works better as a example. You get to a door, and there is a postit note on the door saying "Keycode is 2424". You know your job
by Prickle 3y ago
I think an electronic keypad works better as a example.
You get to a door, and there is a postit note on the door saying "Keycode is 2424".
You know your job is in the building. Your keycard let you into the room with the door. Therefore, if this door lead to a "high-security" area, surely they wouldn't put a postit note there? Maybe, as the bug exterminator, or maintenance person, it is expected that I should be able to enter that room?
- lamontcg 3y agoExcept that this is an API which is not yours that you've found by reverse engineering. You're constructing an analogy where the authorization surface is much less distinct where you're already allowed into the building because that makes the surface much less distinct. That analogy isn't at all obvious to me and I don't think you've offered any rationale for why that is more appropriate. Once you start playing around with someone's remote API then I'd strongly advise you to consider it more like a door around the outside of a building. If you want to argue about that with me, then you may wind up arguing about that with a judge.