Reply to post:

THREE MILLION Moonpig accounts exposed by flaw


I'm not sure why he's making such a big thing about the API help documentation, It's fairly standard practice to make that info publicly available. Maybe he doesn't have much experience of working with APIs?

That doesn't in any way excuse the lack of OAuth, or the inclusion of the customerID in the URL though, they should be roasted for that...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon