Search found 17 matches

by lukeh
Mon Dec 13, 2021 7:28 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

I have pushed back on these policies hard many times over the years, including publishing information in this forum detailing how to get the information over the JSON API that is used by the Church's own website (rather than having to scrape it). All my posts have been deleted by moderators, and a c...
by lukeh
Fri Feb 28, 2020 7:28 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

It would be nice if LDS Tools had a "smart lists" option to make a list of everyone who has a certain calling, for example. I imagine something like this could happen. Despite this conversation revolving around an API, the OP use case would be completely solved if something like this woul...
by lukeh
Fri Feb 28, 2020 7:21 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

Well, I was warned off-list after posting the method for downloading ward data that "this matter has caused a big reaction at Church Offices, and has gone high in the hierarchy, higher than you want to know". I was told I could expect to be called in for a meeting with some very senior peo...
by lukeh
Fri Jul 27, 2018 10:50 am
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

Did you trust that clerks, bishoprics and RS/EQ presidencies would use the CSV exports from MLS appropriately before? (I did...). This is really no different than that. Nervous church lawyers in the end did not trust local leaders enough to deal with data appropriately, and/or the church wanted peop...
by lukeh
Mon Jul 23, 2018 9:31 am
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

You would put the same type of usage restrictions on the API as are currently shown on PDFs generated from lds.org, and printouts from MLS -- "For official Church use only" or similar (though you would maybe be more explicit about not transmitting the data to third parties or storing it in...
by lukeh
Mon Jul 23, 2018 12:32 am
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

So you're saying that if the Church created the API correctly, it would be impossible for an app created by a member-developer to create a situation that could result in membership data being leaked in a way that could have been prevented if the developer had not been able to have programmatic acce...
by lukeh
Sun Jul 22, 2018 10:46 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

Or do you have a suggestion for preventing a risk like that from occurring? Absolutely: as the developer, follow all the OWASP guidelines for preventing XSS/CSRF and similar attacks, or only use libraries that have certified that they follow those guidelines. More to your point, though, as a user o...
by lukeh
Sat Jul 21, 2018 4:57 am
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

Again devinbost you are over-complicating the problem. (1) The Church does already operate a Single Sign-On system that spans all their properties (e.g. your lds.org login works on FamilySearch). I assume it's OAuth2 under the hood, but I don't know for sure. The Church would have to authorize API k...
by lukeh
Fri Jul 13, 2018 6:42 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

Well right now, we already have local leaders having to copy and paste information from lds.org, or type it back in from printed records, because the Church pulled the plug on the CSV export option in MLS. It doesn't stop people using the information, it just makes life more difficult for everyone.
by lukeh
Thu Jul 12, 2018 10:22 pm
Forum: Links & Resources
Topic: API for Directory Web App
Replies: 86
Views: 27940

Re: API for Directory Web App

devinbost -- you are right, security is a hard problem in general. But you are very much over-complicating the problem. The Church already has a login system, with its own security measures in place, and to use the JSON API, you have to authenticate through that login system. That means that to crea...

Go to advanced search