الفرق بين المراجعتين لصفحة «تصميم:دواسوا/cryptographic-token»
اذهب إلى التنقل
اذهب إلى البحث
(إنشاء) |
(verb literals) |
||
| سطر 10: | سطر 10: | ||
<code>base62(sha512(<var>[[../data#Listings|id]]</var> . <var>verb</var> . <var>[[../configuration variables#cryptographic-token-salt|cryptographic-token-salt]]</var>))</code> | <code>base62(sha512(<var>[[../data#Listings|id]]</var> . <var>verb</var> . <var>[[../configuration variables#cryptographic-token-salt|cryptographic-token-salt]]</var>))</code> | ||
| − | Where <var>verb</var> is the literal name of the action being performed; i.e. one of <kbd> | + | Where <var>verb</var> is the literal name of the action being performed; i.e. one of <kbd>instate_entry</kbd> or <kbd>remove_entry</kbd> |
</div> | </div> | ||
مراجعة 13:04، 2 يناير 2017
The system has no user accounts nor sessions, and the API is all public. All actions are confirmed via email messages
API actions that commit changes to the listings database are performed over two steps:
- a request is received containing the object information to be affected, where all information is public
- a confirmation action follows by providing using a cryptographic token received over email, which uniquely identifies the object.
The cryptographic token is constructed as follows:
base62(sha512(id . verb . cryptographic-token-salt))
Where verb is the literal name of the action being performed; i.e. one of instate_entry or remove_entry