English 中文(简体)
Why should we use webapi keys
原标题:
  • 时间:2010-05-21 13:41:22
  •  标签:
  • http
  • api-key

Why should we generate api keys for domains to use web api when we have the referrer to check the source of the request?

问题回答

The value of HTTP_REFERER can easily be faked. If you want to verify that somebody (or some website) is really entitled to access a service, you have to involve some sort of authentication, which generally means an API key (or for people, a username/password).

Some browsers don t send REFERER headers.





相关问题
How to set response filename without forcing "save as" dialog

I am returning a stream in some response setting the appropriate content-type header. The behavior I m looking for is this: If the browser is able to render content of the given content type then it ...

Which Http redirects status code to use?

friendfeed.com uses 302. bit.ly uses 301. I had decided to use 303. Do they behave differently in terms of support by browsers ?

Does HttpWebRequest send 200 OK automatically?

Background: I am implementing Paypal IPN handler. This great article on Paypal states that I am required to send a 200 OK back to Paypal after I read the response. The processing of IPN request is ...

Java HTTPAUTH

我试图把桌面应用程序连接起来,我是同D.icio.us api @ Delicious Alan书写的,简单地向他们提供我的用户名和密码,并请他把书记上写给我......。

Finding out where curl was redirected

I m using curl to make php send an http request to some website somewhere and have set CURLOPT_FOLLOWLOCATION to 1 so that it follows redirects. How then, can I find out where it was eventually ...

热门标签