Public API for mobile apps (Android, iOS) #44

Open
opened 2026-10-08 21:32:10 +00:00 by anas · 0 comments
Owner

Owner direction (2026-10-08): reading features and account features (sign-in, library, word collection, …) must be usable by external clients such as Android and iOS apps.

Already in place: JSON endpoints; Bearer-token sessions (/api/auth/signin returns a token an app can keep); the site is itself a client of the same API.

To do

  • Versioned paths: /api/v1/... (keep the current paths as aliases for the site until it moves).
  • OpenAPI description of every endpoint, published with the site; example requests.
  • Expose the API publicly through Caddy (e.g. https://<domain>/api/v1), with HTTPS only.
  • Security fix before exposing it: rate limits read the client IP from x-client-ip, which only the site should send. Trust that header only from the site (loopback/private network or a shared secret); otherwise use the connection/proxy IP.
  • Rate limits per token as well as per IP; sign-in from apps without cookies; token revocation (sign out, sign out everywhere).
  • CORS stays closed (native apps do not need it); revisit if a third-party web client is wanted.
  • New endpoints from now on are written app-first: JSON in and out, Bearer auth, no site-only assumptions.
Owner direction (2026-10-08): reading features and account features (sign-in, library, word collection, …) must be usable by external clients such as Android and iOS apps. Already in place: JSON endpoints; Bearer-token sessions (`/api/auth/signin` returns a token an app can keep); the site is itself a client of the same API. To do - Versioned paths: `/api/v1/...` (keep the current paths as aliases for the site until it moves). - OpenAPI description of every endpoint, published with the site; example requests. - Expose the API publicly through Caddy (e.g. `https://<domain>/api/v1`), with HTTPS only. - **Security fix before exposing it**: rate limits read the client IP from `x-client-ip`, which only the site should send. Trust that header only from the site (loopback/private network or a shared secret); otherwise use the connection/proxy IP. - Rate limits per token as well as per IP; sign-in from apps without cookies; token revocation (sign out, sign out everywhere). - CORS stays closed (native apps do not need it); revisit if a third-party web client is wanted. - New endpoints from now on are written app-first: JSON in and out, Bearer auth, no site-only assumptions.
anas added this to the Phase 6: Operations and release milestone 2026-10-08 21:32:10 +00:00
Sign in to join this conversation.
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: anas/divan#44
No description provided.