<ill_logic>
Also notable that I can't really connect an application to it without making the thing public.
<ill_logic>
Though I suppose I could just not tell anyone the share URL.
<pdurbin>
Is Tiny Tiny RSS the only example of the sort of reduced security you're talking about?
<ill_logic>
That I can think of. I might make a new such app myself though.
<ill_logic>
I haven't played around with a whole lot of the applications.
<pdurbin>
ok
<ill_logic>
Assuming that's actually reduced security. I thought applications were closed off by default, is all.
<ill_logic>
So does anybody know how to connect to Tiny Tiny RSS to the Android application? I gave it a share link but it wants to try to hit api endpoints.
<ill_logic>
I'm not sure how APIs work with Sandstorm since it tries to hide endpoints.
<ill_logic>
Okay I'm reading about SS api tokens now...
<ill_logic>
And I have an authentication problem on my app.
<ill_logic>
Why would the API URL have a # in it? The server doesn't see it. An arbitrary client wouldn't know what to do with it. I don't see the point.
<ill_logic>
Looks like one of those things Sandstorm hasn't had time to smooth over.
mnutt_ has joined #sandstorm
<kentonv>
ill_logic, TinyTinyRSS takes advantage of a hole we punched specifically for it that we plan to fill in eventually. Technically all apps can use this same hole to make outgoing HTTP requests. It's a confinement violation, though it's worth noting that most other server infrastructure doesn't consider confinement to be an important property in the first place.
<kentonv>
ill_logic, to connect the android client you need to generate a webkey rather than a share link.
<kentonv>
ill_logic, use the key icon in the top bar
<kentonv>
a webkey has the format <host>#<token>
<kentonv>
the token is meant to be sent in the Authorization header
<pdurbin>
kentonv: do a lot of sandstorm apps make outgoing http requests?
<kentonv>
pdurbin, very few. TTRSS is the only one I can think of off the top of my head.
<pdurbin>
gotcha
moromi has joined #sandstorm
jrmg has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
mnutt_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
<moromi>
hi there, I'm trying to install sandstorm and receive a "400 Bad Request" when trying to register a sandcats domain with a recovery mail. any idea?
<TimMc>
kentonv: TinyTinyRSS can talk to other hosts on the LAN, which seems maybe undesirable. It would be nice if the outbound HTTP permissions could in the future allow/deny private IPs.
jrmg has joined #sandstorm
mnutt_ has joined #sandstorm
<moromi>
I tried with another email and it just worked. May be some non-cooperative email domain?
prettyvanilla_ has joined #sandstorm
prettyvanilla has quit [Ping timeout: 258 seconds]
samba_ has joined #sandstorm
Telesight has quit [Remote host closed the connection]
mnutt_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
FredFredFred_ has joined #sandstorm
mnutt_ has joined #sandstorm
FredFredFred has quit [Ping timeout: 264 seconds]
mnutt_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
mnutt_ has joined #sandstorm
mnutt_ has quit [Client Quit]
mnutt_ has joined #sandstorm
prettyvanilla has joined #sandstorm
prettyvanilla_ has quit [Ping timeout: 260 seconds]
samba_ has quit [Ping timeout: 245 seconds]
mnutt_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]