Tom Purdue (tompurdue) wrote in lj_dev,
Tom Purdue
tompurdue
lj_dev

XML API and security

To get a user's friends list you must log in with that user's password. However, that restriction isn't completely general: I can get the same information much of the time on a user's info page.

Obviously there are good reasons to allow a user to hide their friends, but if they're permitting it, why not make it available through the API?
Subscribe
  • Post a new comment

    Error

    Anonymous comments are disabled in this journal

    default userpic

    Your reply will be screened

    Your IP address will be recorded 

  • 3 comments