Skip to content

Comment on OkCupid's “Removed” Visitor API

Comments

However, they gave no answer for why unnecessary data was being provided.

I mean, it was obviously a bug, right? I imagine the only "explanation" would involve detailing the origin and nature of the bug which would be unwise until they've gone through all their other endpoints to ensure that there's not another instance of this same information leaking.

I don’t think that this was a bug. Most probably, they have those DTO objects for viewing and editing. In that scenario the correct thing to do would be to create a new DTO object that exposes only the necessary information, but this is an extra effort.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.