943,682 Members | Top Members by Rank

Jun 21st, 2009
0

URL-Based API Key Restriction: How does validation works?

Expand Post »
Hi,

I don't know if this is the right area to post this, but it seems to be related.

I am interested to know how an URL-based api key restriction works, such as the one used by Google to protect its Google Maps service.

From what I understand from this article http://java.sun.com/developer/techni...pikeys/#urlres , there are two parts involved: first where the service creates a specific key for a given domain, using a one-way hash function; and second where the service validates the key based on the Referer header.

While the article is quite explanatory, I still have a problem trying to understand how safe is the validation method. I mean, if the key is checked only against the referer, isn't this quite easy to forge? I am thinking that a simple "127.0.0.1 www.mydomain.com" in the hosts file will be enough to trick the validation, and think that the referer is www.mydomain.com .

I might have misunderstood some things and a few clarifications will be appreciated.


Thank you for your time,
Standardt.
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
standardt is offline Offline
9 posts
since Nov 2007

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in RSS, Web Services and SOAP Forum Timeline: Problem sending the SOAP request message to weblogic session web service
Next Thread in RSS, Web Services and SOAP Forum Timeline: I need a description about RSS





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC