Drupal Services module: Getting the API key or kid of the requester

The services_keyauth_get_kid() function.

I'm currently in the process of building a module to work with Analytics SEO. This module connects to Analytics SEO via the Services module. There has been some debate as to how to manage permissions. The 'correct' way is to log the user in and then use the usual Drupal access permissions system which would be great but I really don't like the way you submit the password in plain text.

My suggestion is to bind a user to the API key id (kid) although for a lot of people having a user per API key isn't needed or would be overkill - The services module works really well with anonymous calls, or key restricted function calls. But when different people are using the same functions with sensitive data there has to be a proper way of securing the data. The answer as I've suggested is to tie it all up with the API key or kid as it's stored in the database.

I spent several hours, trundling through Google and the module code itself before finally stumbling upon services_keyauth_get_kid(). Finally! I don't know why this was so hard to find, probably because it's quite easy to write your own function to query the database against the domain, but again I didn't want to do that because I was sure there would be some function that would do all of the security stuff for you:

services_keyauth_get_kid()

For those of you that are interested, I'm aiming to make this THE SEO module for Drupal. Yes there are other modules out there but they either don't do much, don't give ongoing analysis or are a pain to install. I'm pretty excited to be building this module because it will incorporate the best of both worlds: The awesome power of Analytics SEO with all its crawling, site audit to check all your pages, keyword and competitor analysis together with the advantages of being hooked right into your site e.g. to automatically analyse your page when you save it, suggest content changes and compare it against competitors, all in a well organised manner to make it quick to optimise your site.

Post new comment

By submitting this form, you accept the Mollom privacy policy.

User login

Author of...

  • Delving into LyX and LaTeX. So far I love it! One of those programs that is indisputably the best. 14 years 2 weeks ago
  • @Casablanca Come say hi! Lunch?! 14 years 2 weeks ago
  • Just seen: while($d = db_fetch_object($data)) { $_d = (array)$d; ... What's wrong with: while($d = db_fetch_array($data)) { ... 14 years 2 weeks ago
  • "Mark seems to understand Oliver perfectly..." Mark: "I do have two small children!" 14 years 2 weeks ago
  • If you're at a concert and your alarm goes off, don't hit snooze! 14 years 3 weeks ago
  • #google why can't I do something like this? 1293840000 unixtime in human readable date 14 years 3 weeks ago
  • @Casablanca I cycled to work today. 1 mile, 10 mins, not bad. 14 years 3 weeks ago
  • Doing the #drupal full project application. A warm fuzzy feeling from finally contributing back properly and great feedback from my reviewer 14 years 3 weeks ago
Oliver Polden