mirror of
https://git.ianrenton.com/ian/spothole.git
synced 2026-09-28 18:22:05 +00:00
Create the concept of API keys to allow third party clients to skip the CAPTCHA check on spot submission
This commit is contained in:
@@ -130,7 +130,7 @@
|
||||
const ALLOW_UPSTREAM_SPOTTING = {% raw safe_json_dumps(web_ui_options["allow_upstream_spotting"]) %};
|
||||
</script>
|
||||
|
||||
<script src="/static/js/add-spot.js?v=1790517301"></script>
|
||||
<script src="/static/js/add-spot.js?v=1790521969"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-add-spot").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
@@ -87,7 +87,7 @@
|
||||
|
||||
</div>
|
||||
|
||||
<script src="/static/js/alerts.js?v=1790517301"></script>
|
||||
<script src="/static/js/alerts.js?v=1790521969"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-alerts").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
@@ -82,8 +82,8 @@
|
||||
const BANDS = {% raw safe_json_dumps(options["bands"]) %};
|
||||
</script>
|
||||
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790517301"></script>
|
||||
<script src="/static/js/bands.js?v=1790517301"></script>
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790521969"></script>
|
||||
<script src="/static/js/bands.js?v=1790521969"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-bands").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
+5
-5
@@ -1,6 +1,6 @@
|
||||
{% extends "skeleton.html" %}
|
||||
{% block head_extra %}
|
||||
<link rel="stylesheet" href="/static/css/style.css?v=1790517300" type="text/css">
|
||||
<link rel="stylesheet" href="/static/css/style.css?v=1790521969" type="text/css">
|
||||
<link href="/static/vendor/css/bootstrap-5.3.8.min.css" rel="stylesheet">
|
||||
<link href="/static/vendor/css/fontawesome-6.7.2.min.css" rel="stylesheet">
|
||||
<link href="/static/vendor/css/solid-6.7.2.min.css" rel="stylesheet">
|
||||
@@ -16,10 +16,10 @@
|
||||
window.fetchEventSource = fetchEventSource;
|
||||
</script>
|
||||
|
||||
<script src="/static/js/utils.js?v=1790517300"></script>
|
||||
<script src="/static/js/ui-ham.js?v=1790517300"></script>
|
||||
<script src="/static/js/geo.js?v=1790517300"></script>
|
||||
<script src="/static/js/common.js?v=1790517300"></script>
|
||||
<script src="/static/js/utils.js?v=1790521969"></script>
|
||||
<script src="/static/js/ui-ham.js?v=1790521969"></script>
|
||||
<script src="/static/js/geo.js?v=1790521969"></script>
|
||||
<script src="/static/js/common.js?v=1790521969"></script>
|
||||
{% end %}
|
||||
{% block body %}
|
||||
<div class="container">
|
||||
|
||||
@@ -284,7 +284,7 @@
|
||||
</div>
|
||||
|
||||
<script src="/static/vendor/js/chart-4.4.9.umd.min.js"></script>
|
||||
<script src="/static/js/conditions.js?v=1790517300"></script>
|
||||
<script src="/static/js/conditions.js?v=1790521969"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-conditions").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
@@ -47,6 +47,25 @@
|
||||
all means base your own project on data from the main server if you like, but if you want any control over
|
||||
reliability and downtime, please run your own copy instead.)</p>
|
||||
|
||||
<h3 class="mt-4" id="submitting-spots">Submitting Spots</h3>
|
||||
<p>As well as reading data, clients can submit new spots to Spothole using the "add spot" API endpoint, e.g.
|
||||
<code>https://spothole.app/api/v3/spot</code>. Spots can be added to Spothole itself, and optionally sent "upstream"
|
||||
to other services such as the DX cluster. Check the <code>spot_allowed</code> and
|
||||
<code>spot_submit_providers</code> fields in the "options" API response to see what the server allows.</p>
|
||||
<p>To stop bots and spammers abusing the spotting function, a Spothole server can be configured to protect against this,
|
||||
which means you will need an <strong>API key</strong>. API keys are issued by the operator of each Spothole server,
|
||||
so get in touch with the server owner and let them know what your software is and how it will use the API. Once you
|
||||
have a key, send it in the <code>X-API-Key</code> header of each add spot request. For example:</p>
|
||||
<pre><code>curl --request POST \
|
||||
--header "Content-Type: application/json" \
|
||||
--header "X-API-Key: your-api-key-here" \
|
||||
--data '{"spot":{"dx_call":"M0TRT","time":1760019539,"freq":14200000,"de_call":"M0TRT"}}' \
|
||||
https://spothole.app/api/v3/spot</code></pre>
|
||||
<p>Your API key identifies your software, so please keep it private. Don't commit it to a public code repository, and
|
||||
don't embed it in JavaScript or anywhere else your users could extract it. If a key is misused, the server operator
|
||||
can revoke it, and spot submission from your client will stop working. Servers that don't protect spot submission
|
||||
don't need an API key, and will accept spots with or without one.</p>
|
||||
|
||||
<h3 class="mt-4" id="terms">Conditions of Use</h3>
|
||||
<p>There are some simple, hopefully not onerous terms and conditions that you should agree to before writing a client
|
||||
for the Spothole API. These probably aren't legally binding, and I'm just a random guy on the internet, I'm not
|
||||
|
||||
@@ -30,6 +30,14 @@ cp config-example.yml config.yml
|
||||
helpdesk ticket and explaining what you'll use it for. The admin team are happy with the rate of requests made by my
|
||||
Spothole server, so unless you change the source code of yours to radically increase the rate of querying Clublog,
|
||||
I'm sure they will be fine with your server too.</p>
|
||||
<p>If your server is public and allows spots to be submitted, you may want to protect it from bots and spammers by
|
||||
setting <code>protect_spot_submission</code> to <code>true</code> and setting the reCAPTCHA keys in
|
||||
<code>config.yml</code>. Users of the web interface will then need to solve a CAPTCHA to submit a spot. Third-party
|
||||
client software can't do that, so if you want to allow a particular client to submit spots, generate an API key for
|
||||
it, add it to the <code>api_keys</code> list in <code>config.yml</code>, and send it privately to the client's
|
||||
developer. They send it in the <code>X-API-Key</code> header of each request, and Spothole will accept their spots.
|
||||
To revoke a key, remove it from the list and restart Spothole. If <code>protect_spot_submission</code> is
|
||||
<code>false</code>, anyone can submit spots and API keys aren't needed.</p>
|
||||
<p>Once you're happy with the content of <code>config.yml</code>, you can proceed to running the software.</p>
|
||||
<p>To run the software this time and any future times you want to run it directly from the command line:</p>
|
||||
<pre><code>source .venv/bin/activate
|
||||
|
||||
+2
-2
@@ -115,8 +115,8 @@
|
||||
const CARTODB_API_KEY = "{{ web_ui_options.get('cartodb_api_key', '') }}";
|
||||
</script>
|
||||
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790517300"></script>
|
||||
<script src="/static/js/map.js?v=1790517300"></script>
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790521968"></script>
|
||||
<script src="/static/js/map.js?v=1790521968"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-map").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
@@ -127,8 +127,8 @@
|
||||
|
||||
</div>
|
||||
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790517300"></script>
|
||||
<script src="/static/js/spots.js?v=1790517300"></script>
|
||||
<script src="/static/js/spotsbandsandmap.js?v=1790521968"></script>
|
||||
<script src="/static/js/spots.js?v=1790521968"></script>
|
||||
<script>$(document).ready(function () {
|
||||
$("#nav-link-spots").addClass("active");
|
||||
}); <!-- highlight active page in nav --></script>
|
||||
|
||||
@@ -96,7 +96,7 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script src="/static/js/status.js?v=1790517301"></script>
|
||||
<script src="/static/js/status.js?v=1790521969"></script>
|
||||
<script>
|
||||
$(document).ready(function () {
|
||||
$("#nav-link-status").addClass("active");
|
||||
|
||||
Reference in New Issue
Block a user