Discuss Scratch

Jimbaloo
Scratcher
25 posts

Message Count

IT'S BEEN A LONG TIME SINCE I USED DISCUSSION FORUMS SO SORRY IF HIS IS THE WRONG SECTION

Hello, so most scratchers know about api.scratch.mit.edu, and some of you know that you can see someones message count. Now, I don't wanna do this because I'm not that popular and dont really mind. But is there a way to disable your account from the scratch API so no one can see those statistics.

Im not expecting an answer but if anyone knows anything about how scratch API functions please tell me!

Thanks -Jimbaloo
GIitchInTheMatrix
Scratcher
1000+ posts

Message Count

No. The API is public. Viewing it in the API isn’t gonna hurt your account, though.
Knightbot63
Scratcher
1000+ posts

Message Count

API is public to everyone and all it's api's are documented on the scratch wiki
Jimbaloo
Scratcher
25 posts

Message Count

GIitchInTheMatrix wrote:

No. The API is public. Viewing it in the API isn’t gonna hurt your account, though.
Oh ok I was just wondering because its a bit creepy that with the right link and username people can look at your information including stuff that they cant even see
GIitchInTheMatrix
Scratcher
1000+ posts

Message Count

Jimbaloo wrote:

GIitchInTheMatrix wrote:

No. The API is public. Viewing it in the API isn’t gonna hurt your account, though.
Oh ok I was just wondering because its a bit creepy that with the right link and username people can look at your information including stuff that they cant even see
Its just a number, though.
medians
Scratcher
1000+ posts

Message Count

GIitchInTheMatrix wrote:

Jimbaloo wrote:

GIitchInTheMatrix wrote:

No. The API is public. Viewing it in the API isn’t gonna hurt your account, though.
Oh ok I was just wondering because its a bit creepy that with the right link and username people can look at your information including stuff that they cant even see
Its just a number, though.
Also, you can't even see unshared projects using that method anymore because of the api changes.
Knightbot63
Scratcher
1000+ posts

Message Count

medians wrote:

(#6)
Also, you can't even see unshared projects using that method anymore because of the api changes.
Unless you pass a project token to that url.
Fun_Cupcake_i81
Scratcher
1000+ posts

Message Count

Knightbot63 wrote:

medians wrote:

(#6)
Also, you can't even see unshared projects using that method anymore because of the api changes.
Unless you pass a project token to that url.
True, but that doesn't seem like a huge security concern because you would have to get REALLY lucky to just GUESS a correct token.
Jimbaloo
Scratcher
25 posts

Message Count

Fun_Cupcake_i81 wrote:

Knightbot63 wrote:

medians wrote:

(#6)
Also, you can't even see unshared projects using that method anymore because of the api changes.
Unless you pass a project token to that url.
True, but that doesn't seem like a huge security concern because you would have to get REALLY lucky to just GUESS a correct token.

Uhhh what is happening
when green flag clicked
I was just
asking a question (OK?)
Fun_Cupcake_i81
Scratcher
1000+ posts

Message Count

Jimbaloo wrote:

Uhhh what is happening
when green flag clicked
I was just
asking a question (OK?)
I was just saying that you don't need to worry about people finding your unshared projects. As for your messages, they can only see your message count and not your actual messages. Users with multiple accounts often use the API to see if any of their alts have messages without having to sign in and out, so it can actually come in quite handy.
medians
Scratcher
1000+ posts

Message Count

Fun_Cupcake_i81 wrote:

Knightbot63 wrote:

medians wrote:

(#6)
Also, you can't even see unshared projects using that method anymore because of the api changes.
Unless you pass a project token to that url.
True, but that doesn't seem like a huge security concern because you would have to get REALLY lucky to just GUESS a correct token.
And plus it expires..

Last edited by medians (May 3, 2023 08:57:24)

Withered_Fredboi
Scratcher
100+ posts

Message Count

Nope. Any account would get loaded to that database upon account creation.

Powered by DjangoBB