Integrating with service Made in Spain. 1) Dev SOAP service has expired cert, 2) it throws 500s, 3) web UI uses SHA1 intermediate cert. Joy.
-
-
Replying to @marcan42
This is getting better. Turns out the 500s were an authentication error. Because I'm not supposed to use my user/pw, but a *shared one*.
1 reply 1 retweet 4 likes -
Replying to @marcan42
Then you call the "log-in" API, which doesn't take credentials. Then the actual *operation* API takes the real user/pw. WTF?
3 replies 0 retweets 6 likes -
Replying to @marcan42
Two-phase login sounds like some sort of anti-CSRF mechanism. I seem to remember MediaWiki API doing the same.
1 reply 0 retweets 0 likes -
Replying to @PinoBatch
This isn't two-phase login. It's just stupid enterprisy consultancy bullshit. Someone told them they needed "security"...
1 reply 0 retweets 0 likes -
Replying to @marcan42 @PinoBatch
... so they decided to use WS-security (it has security in the name!) with a hardcoded username and password, because SECURITY!!1!
1 reply 0 retweets 0 likes -
Replying to @marcan42 @PinoBatch
All WS-Security with user/password auth does is stick the username/password in the message header.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @PinoBatch
Then they decided they needed sessions, so you "log in" but the only secret needed is an OID they assign. Which you pass to every req anyway
1 reply 0 retweets 0 likes -
Replying to @marcan42 @PinoBatch
But then they wind up requiring the username/password used for humans to log in too... in the actual API that does stuff (not login).
1 reply 0 retweets 0 likes
The whole thing is just braindead and clearly designed by people who have no idea what they're doing.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.