Hi, I'm trying to make a HTML5/Jquery app to use against The Movie Database API. So far so good, havn't had a single problem.
But I would like to understand the process of athenticating the user a bit better, cause I'm suspecting that I am doing it wrong to some degree.
As of now I:
However, I'm doing it this way every time. Is the token, when validated with login once, a substitute for username and password for that user forever? If so I could just store the authenticated token localy and use the preffered 2a-method the next time? The expires_at:"..." parameter makes me confused.
Yes, I'm a novice :) You were to once.
Regards, me.
Не можете да откриете филм или сериал? Влезте, за да го създадете.
Искате ли да го оцените или добавите към списък?
Нямате профил?
Отговор от Bene8493
на 13 март 2015 в 1:06 PM
The token is just for validation. If a account has been successfully validated, you only need the
session_id
and append it to your request."The results of this query will return a
session_id
value. You should treat this value like a password. Store it securely. This is the value required in all of our write methods."Отговор от Travis Bell
на 14 март 2015 в 10:02 AM
There's this document that helps explain the required steps as well: https://www.themoviedb.org/documentation/api/sessions
Cheers.