4 ms·
> "... he'll stop sending us stupid emails asking how to call our server-side API using jQuery or, not making this up as it's happened several times from severa
by duncans 13y ago
> "... he'll stop sending us stupid emails asking how to call our server-side API using jQuery or, not making this up as it's happened several times from several customers, a form on an HTML page."
Have you considered that maybe an API should be callable using `jQuery.ajax(...)` or a simple `application/x-www-form-urlencoded` POST?
(...or was this satire?)
- cruise02 13y agoI think he's saying that their API is callable from jQuery, they just don't want any more questions emailed to them about it.
- lostcolony 13y agoI think it more was the junior devs who tried calling it with jQuery.ajax, but did stupid stuff like send the wrong content type for their data and then "Why isn't it working?! Can you send me an example?!"
- jasonkester 13y agoI'll assume you missed the "server-side" in the above, or that I wasn't clear in what that meant. I'm referring to API calls that you really really only want to ever do from your server. Things like starting and stopping EC2 instances, where you need to send along your API keys that are essentially the keys to your bank account and your business's future survival. Now imagine, as the owner of that service, that your customer is sending those keys in plain text to the client, and wondering why he's having a hard time starting EC2 instances using javascript from his user's browser.
- nl 13y agoI wrote a thing to start & stop OpenStack servers via JavaScript. HTTPS is a thing. I have trouble thinking of any API that shouldn't be callable from a client.
- kodablah 13y agoAny API that uses some form of authentication token that is not obtained via some user-based interaction like OAuth may need to be at least proxied via a server side piece to prevent exposing credentials/keys.
- nl 13y agoErr.. why? Clearly the keys need to be obtained somehow, but that was out of band for my application. Once they are obtained I don't see any reason why passing them from a 3rd party app over HTTPS (using CORS) is any less secure than using session based authentication with a 1st party app. In both cases you are vulnerable to MTM and XSS attacks. Sessions expire which is nice, but that's the only real difference.