Public API for mobile apps (Android, iOS) #44
Labels
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: anas/divan#44
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Owner direction (2026-10-08): reading features and account features (sign-in, library, word collection, …) must be usable by external clients such as Android and iOS apps.
Already in place: JSON endpoints; Bearer-token sessions (
/api/auth/signinreturns a token an app can keep); the site is itself a client of the same API.To do
/api/v1/...(keep the current paths as aliases for the site until it moves).https://<domain>/api/v1), with HTTPS only.x-client-ip, which only the site should send. Trust that header only from the site (loopback/private network or a shared secret); otherwise use the connection/proxy IP.