Some thoughts...

XIXXIX povedal

veľmi dávno | Príspevok #1
As I look at adding your api...

Just pass the players name in on root, I'm not really interested in waiting an unknown amount of time for a call back to complete for this information.


Don't use mx.delegate , I don't have it under mtasc so I'm going to have to edit your code. Just roll a small one of your own, the codes not that complicated just do something like this...

http://svn.zope.de/zope.org/z3c.reference/trunk/flash/src/net/hiddenresource/util/Delegate.as



Please just pass in the user name somewhere on root, even newgrounds does this nowadays :)


Cheers,

Kriss

ChrisChris povedal

veľmi dávno | Príspevok #2
Our username get works for external plays using our embed system, and is guaranteed to be an authenticated username, as in no faking, cheating etc.

XIXXIX povedal

veľmi dávno | Príspevok #3
Actually you can not guarantee that it is not faked, the attacker has the client and can tell the game anything. Its only secure when sending to your server if at all and even then the game client can never know what the real name of the player is.

Whatever you are doing, is not secure.

The issue I have with this is you have to wait for a response, and write timeout test code for when it never returns. In order to actually test all of this I need to write my own local copy/version of your server code. It just over complicates things, what should be one line of code that can never go wrong is now network message management that can go wrong in many horrible ways.

Keep it simple, pass the name in on site, people can still use the api call to pick up that name if they wish, nothing breaks.

Can I work with what you have?

sure,

I'm just not going to right now and thats exactly why, take that feedback and use it. Or not. It's your call..
Príspevok #4 zmazaný
Príspevok #5 zmazaný
Príspevok #6 zmazaný

ChrisChris povedal

veľmi dávno | Príspevok #7 | odpoveď na #3
The system uses the same auth mechanism as the site itself, unless you have a valid session on our site no data will be attached to your user, as of now the api will return whatever username you parse to the flash file, bit that will change very soon.

Additionally I do not believe a simple http request to be something that can go wrong in many horrible ways. If that was the case the internet would be unbearable with broken images and none working websites at random.

In the end its TCP/IP which is pretty damn solid.
Príspevok #8 zmazaný

Odpoveď na diskusiu

Zaregistruj sa a zapoj sa do diskusie

Flashky.sk

flashky.sk je herný portál kde môžeš hraj single- aj multiplayerové flashové hry.

Nástroje pre vývojárov

Ak si vývojár flash hier tak pre teba máme skvelé nástroje, ktoré ti pomôžu robiť ešte lepšie hry.

Skvelé hry

Vyskúšaj niektoré z najlepších online flash hier, ktoré tu máme! Samozrejme zadarmo

Copyright ©2007-2012 Flashky.sk™ - All rights reserved.46.8001ms on SERVER34096