mirror of
https://git.ianrenton.com/ian/spothole.git
synced 2026-09-29 02:32:05 +00:00
Create the concept of API keys to allow third party clients to skip the CAPTCHA check on spot submission
This commit is contained in:
@@ -30,6 +30,14 @@ cp config-example.yml config.yml
|
||||
helpdesk ticket and explaining what you'll use it for. The admin team are happy with the rate of requests made by my
|
||||
Spothole server, so unless you change the source code of yours to radically increase the rate of querying Clublog,
|
||||
I'm sure they will be fine with your server too.</p>
|
||||
<p>If your server is public and allows spots to be submitted, you may want to protect it from bots and spammers by
|
||||
setting <code>protect_spot_submission</code> to <code>true</code> and setting the reCAPTCHA keys in
|
||||
<code>config.yml</code>. Users of the web interface will then need to solve a CAPTCHA to submit a spot. Third-party
|
||||
client software can't do that, so if you want to allow a particular client to submit spots, generate an API key for
|
||||
it, add it to the <code>api_keys</code> list in <code>config.yml</code>, and send it privately to the client's
|
||||
developer. They send it in the <code>X-API-Key</code> header of each request, and Spothole will accept their spots.
|
||||
To revoke a key, remove it from the list and restart Spothole. If <code>protect_spot_submission</code> is
|
||||
<code>false</code>, anyone can submit spots and API keys aren't needed.</p>
|
||||
<p>Once you're happy with the content of <code>config.yml</code>, you can proceed to running the software.</p>
|
||||
<p>To run the software this time and any future times you want to run it directly from the command line:</p>
|
||||
<pre><code>source .venv/bin/activate
|
||||
|
||||
Reference in New Issue
Block a user