3 ms·
I curious as to why people would have a public API to begin with if they wanted to protect it from people using it. Then again, why would anyone have a public u
by devjab 2y ago
I curious as to why people would have a public API to begin with if they wanted to protect it from people using it. Then again, why would anyone have a public undocumented API in 2024 when a LLM can give you a cli tool to auto-generate 90% of the OpenAPI spec in a couple of hours? The last question isn't serious, I've worked in enterprise for decades and almost none of the tools organisations end up buying have good documentation for their API's. Not that those are publicly available, but still.
- lesuorac 2y agoI think you have a misunderstanding here. The API needs to be "public" because the app uses the internet to communicate back to the home server. The API is not "public" in the sense that the app developers want anybody to use it; they just want their app to use this API. So they don't write publicly accessible documentation about it because they don't want to encourage its use. A tool like MitmProxy2Swagger lets you run the app and record all of its API calls so that you can use this unadvertised API.
- devjab 2y agoWhy wouldn’t you add authentication to an API you don’t want others to use?
- ssdspoimdsjvv 2y agoThe web app probably authenticates using an API as well, in which case it's trivial to add that to your shadow client as long as you have the credentials.
- lesuorac 2y agoLaziness / skill issue. How many apps have you seen only do client-side protection?