الفرق بين المراجعتين لصفحة «تصميم:دواسوا/cryptographic-token»
اذهب إلى التنقل
اذهب إلى البحث
(إنشاء) |
ط (underscore for nodejs hates dashes) |
||
| (مراجعة متوسطة واحدة بواسطة نفس المستخدم غير معروضة) | |||
| سطر 8: | سطر 8: | ||
The cryptographic token is constructed as follows: | The cryptographic token is constructed as follows: | ||
| − | <code>base62(sha512(<var>[[../data#Listings|id]]</var> . <var>verb</var> . <var>[[../configuration variables# | + | <code>base62(sha512(<var>[[../data#Listings|id]]</var> . <var>verb</var> . <var>[[../configuration variables#cryptographic_token_salt|cryptographic_token_salt]]</var>))</code> |
| − | Where <var>verb</var> is the literal name of the action being performed; i.e. one of <kbd> | + | Where <var>verb</var> is the literal name of the action being performed; i.e. one of <kbd>instate_entry</kbd> or <kbd>remove_entry</kbd> |
</div> | </div> | ||
المراجعة الحالية بتاريخ 13:35، 2 يناير 2017
The system has no user accounts nor sessions, and the API is all public. All actions are confirmed via email messages
API actions that commit changes to the listings database are performed over two steps:
- a request is received containing the object information to be affected, where all information is public
- a confirmation action follows by providing using a cryptographic token received over email, which uniquely identifies the object.
The cryptographic token is constructed as follows:
base62(sha512(id . verb . cryptographic_token_salt))
Where verb is the literal name of the action being performed; i.e. one of instate_entry or remove_entry