- Hypermedia as the Engine of Application State (HATEOAS)
- Returning concrete mediatypes (standard is great, custom is OK) instead of generic 'application/json' or 'application/xml'
It also contains some misunderstandings:
- Sending a sha1 of the password to the server is bad, for two reasons:
- - First, and more importantly, if you send the hash of the password over the wire, the hash becomes a plain-text password! Seems strange? Think about it: if the attacker somehow gets the hash, he can just use it as-is to authenticate to your API - he doesn't need to crack it.
If you're using HTTPS, just use Basic Auth. Otherwise, you should implement (read: use a library!) proper request signing.
- - Second, sha1 by itself is pitiful - it can be cracked in mere seconds. Use bcrypt (this, on the server).
Once you know the top level objects and actions in your product,
designing the endpoints becomes easier and clearer. For example,
to “add” a new venue, you would probably have to call a method
similar to /venues/add
Sorry, but no, no.In REST, there should be a single endpoint. Everything else is done by navigating.
And in REST, there are no method calls! As Roy Fielding would say, this screams RPC! To add a venue you should just POST to /venues/ (URL which you discovered by navigating the API).
Read his blog post with some of the rules that make a REST API: http://roy.gbiv.com/untangled/2008/rest-apis-must-be-hyperte...