[API] Authenticating a server request
#5

You could check the source IP addresses using $_SERVER["REMOTE_ADDR"], which cannot be spoofed. Any other IP headers can be easily spoofed, and you shouldn't rely on them.

Alternatively, you could use API keys, which you would include in every request made by the client and verify it on the server side. However, any sensitive data (the key for instance) should be transmitted using SSL encryption (https), which is not supported by SA-MP.
Reply


Messages In This Thread
[API] Authenticating a server request - by Sinner - 14.07.2014, 06:38
Re: [API] Authenticating a server request - by rickisme - 14.07.2014, 06:49
Re: [API] Authenticating a server request - by Sinner - 14.07.2014, 06:59
Re: [API] Authenticating a server request - by rickisme - 14.07.2014, 07:34
Re: [API] Authenticating a server request - by Johnson_boy - 14.07.2014, 15:56
Re: [API] Authenticating a server request - by playbox12 - 14.07.2014, 16:10
Re: [API] Authenticating a server request - by Mauzen - 14.07.2014, 16:37
Re: [API] Authenticating a server request - by Sinner - 14.07.2014, 17:10
Re: [API] Authenticating a server request - by playbox12 - 14.07.2014, 18:48
Re: [API] Authenticating a server request - by Johnson_boy - 14.07.2014, 21:41

Forum Jump:


Users browsing this thread: 3 Guest(s)