CONVIO_API_IP_FILTER for browser-based applications
quick question ... we are running into a potential issue with our Convio OPEN implementations.
apparently, an IP address must be declared on the back end (CONVIO_API_IP_FILTER) to allow an API call to the Convio servers. unfortunately, the three projects we have in the pipeline are all distributed, browser-based ajax programs which won't conform to the notion of an IP address and subnet mask, at least not one that is meaningfully enforced.
for the upcoming fiscal year, we won't have time/resources/infrastructure to develop server-hosted interactive applications. i am pretty sure that means we won't be able to have IP restrictions that are meaningful (ie. not wildcards for all for aspects) as our calls to the API will be coming in from all over the interweb.
has anybody else run into this issue? if this is actually a problem, is it going to be addressed in the near future? if not, i'm afraid we'll have to shelve our plans to use OPEN for this fiscal year.
Comments
-
Creating mash-ups that use AJAX to access APIs hosted on another server is one of the real challenges on the Internet today, and fortunately there is a fair amount of innovation going on to help solve it. The first versions of the Open APIs used the technique of requiring a proxy server to get around the browser's same site security restrictions, but we recognize that this isn't a viable option for many folks. Other techniques that folks have been using historically are to use JSONP (JSON with padding) along with injection of script tags and using a Flash proxy to execute the cross-domain calls. I've been looking into a technique that is being embraced pretty widely now that uses hidden iframes for cross-domain communication. Here's a link to a pretty good article that explains it .
Bottom line is that we expect to have a solution to recommend to customers this summer. As more information develops, I'll keep the community posted.
Dave
0 -
DavidHart :
Creating mash-ups that use AJAX to access APIs hosted on another server is one of the real challenges on the Internet today, and fortunately there is a fair amount of innovation going on to help solve it. The first versions of the Open APIs used the technique of requiring a proxy server to get around the browser's same site security restrictions, but we recognize that this isn't a viable option for many folks. Other techniques that folks have been using historically are to use JSONP (JSON with padding) along with injection of script tags and using a Flash proxy to execute the cross-domain calls. I've been looking into a technique that is being embraced pretty widely now that uses hidden iframes for cross-domain communication. Here's a link to a pretty good article that explains it .
Bottom line is that we expect to have a solution to recommend to customers this summer. As more information develops, I'll keep the community posted.
Dave
Dave, does that mean you guys are allowing the crossdomain.xml file now? Last time I asked about that, it was shot down roundly... the SWFProxy works great, but it requires the destination server have a properly configured xml file at the root specifying the domain the client is in is allowed to make remote requests. I was under the impression Convio wasn't going to do this.
-mike
0 -
Michael :
Dave, does that mean you guys are allowing the crossdomain.xml file now? Last time I asked about that, it was shot down roundly... the SWFProxy works great, but it requires the destination server have a properly configured xml file at the root specifying the domain the client is in is allowed to make remote requests. I was under the impression Convio wasn't going to do this.
-mike
No, we're not currently considering allowing a crossdomain.xml file. We did look at Flash proxying as a potential solution, but it's a really bad fit with our configuration. I think that if you look at Yahoo, which has a wide-open policy file, you'll see that all the APIs hit a totally separate URL namespace from any of the interactive traffic. We're looking at implementing a javascript solution that leverages the iframe-based communication model described in the link that I referenced earlier. This should be easier for you to use, applicable to a broader set of constituents, and more secure. I hope to have some more details and some prototype code to post in the next few weeks. Unfortunately, I have several other commitments for our next release, so I had to put this on the back burner after getting a proof-of-concept done.
0 -
DavidHart :
No, we're not currently considering allowing a crossdomain.xml file. We did look at Flash proxying as a potential solution, but it's a really bad fit with our configuration. I think that if you look at Yahoo, which has a wide-open policy file, you'll see that all the APIs hit a totally separate URL namespace from any of the interactive traffic. We're looking at implementing a javascript solution that leverages the iframe-based communication model described in the link that I referenced earlier. This should be easier for you to use, applicable to a broader set of constituents, and more secure. I hope to have some more details and some prototype code to post in the next few weeks. Unfortunately, I have several other commitments for our next release, so I had to put this on the back burner after getting a proof-of-concept done.
Dave, yes indeed. In fact, Yahoo has two completely seperated APIs. They have a very open policy for things that don't require authentication or access to member data. Things like maps, search etc. I think that there IS a fit for Convio in that area in places like TAF or advocacy posting APIs... anything really that a user could do on a Convio site without being formally logged in yet.
By the way, the IFRAME element was omitted from the XHTML 1.1 spec. It wasn't actual deprecated (which is odd in and of itself), but an eye for forward compliance would dictate you not use iframes for anything. The alternative is to use the OBJECT element, but there are clearly some differences there.
0 -
Michael :
Dave, does that mean you guys are allowing the crossdomain.xml file now? Last time I asked about that, it was shot down roundly... the SWFProxy works great, but it requires the destination server have a properly configured xml file at the root specifying the domain the client is in is allowed to make remote requests. I was under the impression Convio wasn't going to do this.
-mike
I've actually got an update to my last response on crossdomain.xml files. We're beta testing a configuration now where you can configure crossdomain access for Flash applications through SDPs. It does not allow a site-wide crossdomain.xml file, but does allow you to provide access specifically to the APIs from Flash hosted on other systems. Here are some bullet points from an internal presentation that I did on how it works:
Convio automatically creates a policy file for each of the APIs so that they can be accessed using Flash from other domains.
To load the policy file for the CRConsAPI on organization xyz, you would use this URL:
The list of sites that should be allowed access is controlled by a site data parameter
The policy for each API needs to be loaded separately by the Flash movie
Calls to the API need to include a trailing slash (e.g. CRConsAPI/?v=1.0… not CRConsAPI?v=1.0…
0
Categories
- All Categories
- Shannon parent
- shannon 2
- shannon 1
- 21 Advocacy DC Users Group
- 14 BBCRM PAG Discussions
- 89 High Education Program Advisory Group (HE PAG)
- 28 Luminate CRM DC Users Group
- 8 DC Luminate CRM Users Group
- Luminate PAG
- 5.9K Blackbaud Altru®
- 58 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 409 bbcon®
- 2.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- donorCentrics®
- 1.1K Blackbaud eTapestry®
- 2.8K Blackbaud Financial Edge NXT®
- 1.1K Blackbaud Grantmaking™
- 527 Education Management Solutions for Higher Education
- 1 JustGiving® from Blackbaud®
- 4.6K Education Management Solutions for K-12 Schools
- Blackbaud Luminate Online & Blackbaud TeamRaiser
- 16.4K Blackbaud Raiser's Edge NXT®
- 4.1K SKY Developer
- 547 ResearchPoint™
- 151 Blackbaud Tuition Management™
- 1 YourCause® from Blackbaud®
- 61 everydayhero
- 3 Campaign Ideas
- 58 General Discussion
- 115 Blackbaud ID
- 87 K-12 Blackbaud ID
- 6 Admin Console
- 949 Organizational Best Practices
- 353 The Tap (Just for Fun)
- 235 Blackbaud Community Feedback Forum
- 55 Admissions Event Management EAP
- 18 MobilePay Terminal + BBID Canada EAP
- 36 EAP for New Email Campaigns Experience in Blackbaud Luminate Online®
- 109 EAP for 360 Student Profile in Blackbaud Student Information System
- 41 EAP for Assessment Builder in Blackbaud Learning Management System™
- 9 Technical Preview for SKY API for Blackbaud CRM™ and Blackbaud Altru®
- 55 Community Advisory Group
- 46 Blackbaud Community Ideas
- 26 Blackbaud Community Challenges
- 7 Security Testing Forum
- 1.1K ARCHIVED FORUMS | Inactive and/or Completed EAPs
- 3 Blackbaud Staff Discussions
- 7.7K ARCHIVED FORUM CATEGORY [ID 304]
- 1 Blackbaud Partners Discussions
- 1 Blackbaud Giving Search™
- 35 EAP Student Assignment Details and Assignment Center
- 39 EAP Core - Roles and Tasks
- 59 Blackbaud Community All-Stars Discussions
- 20 Blackbaud Raiser's Edge NXT® Online Giving EAP
- Diocesan Blackbaud Raiser’s Edge NXT® User’s Group
- 2 Blackbaud Consultant’s Community
- 43 End of Term Grade Entry EAP
- 92 EAP for Query in Blackbaud Raiser's Edge NXT®
- 38 Standard Reports for Blackbaud Raiser's Edge NXT® EAP
- 12 Payments Assistant for Blackbaud Financial Edge NXT® EAP
- 6 Ask an All Star (Austen Brown)
- 8 Ask an All-Star Alex Wong (Blackbaud Raiser's Edge NXT®)
- 1 Ask an All-Star Alex Wong (Blackbaud Financial Edge NXT®)
- 6 Ask an All-Star (Christine Robertson)
- 21 Ask an Expert (Anthony Gallo)
- Blackbaud Francophone Group
- 22 Ask an Expert (David Springer)
- 4 Raiser's Edge NXT PowerUp Challenge #1 (Query)
- 6 Ask an All-Star Sunshine Reinken Watson and Carlene Johnson
- 4 Raiser's Edge NXT PowerUp Challenge: Events
- 14 Ask an All-Star (Elizabeth Johnson)
- 7 Ask an Expert (Stephen Churchill)
- 2025 ARCHIVED FORUM POSTS
- 322 ARCHIVED | Financial Edge® Tips and Tricks
- 164 ARCHIVED | Raiser's Edge® Blog
- 300 ARCHIVED | Raiser's Edge® Blog
- 441 ARCHIVED | Blackbaud Altru® Tips and Tricks
- 66 ARCHIVED | Blackbaud NetCommunity™ Blog
- 211 ARCHIVED | Blackbaud Target Analytics® Tips and Tricks
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- Luminate CRM DC Users Group
- 225 ARCHIVED | Blackbaud eTapestry® Tips and Tricks
- 1 Blackbaud eTapestry® Know How Blog
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)
- 1 Blackbaud K-12 Education Solutions™ Blog
- 280 ARCHIVED | Mixed Community Announcements
- 3 ARCHIVED | Blackbaud Corporations™ & Blackbaud Foundations™ Hosting Status
- 1 npEngage
- 24 ARCHIVED | K-12 Announcements
- 15 ARCHIVED | FIMS Host*Net Hosting Status
- 23 ARCHIVED | Blackbaud Outcomes & Online Applications (IGAM) Hosting Status
- 22 ARCHIVED | Blackbaud DonorCentral Hosting Status
- 14 ARCHIVED | Blackbaud Grantmaking™ UK Hosting Status
- 117 ARCHIVED | Blackbaud CRM™ and Blackbaud Internet Solutions™ Announcements
- 50 Blackbaud NetCommunity™ Blog
- 169 ARCHIVED | Blackbaud Grantmaking™ Tips and Tricks
- Advocacy DC Users Group
- 718 Community News
- Blackbaud Altru® Hosting Status
- 104 ARCHIVED | Member Spotlight
- 145 ARCHIVED | Hosting Blog
- 149 JustGiving® from Blackbaud® Blog
- 97 ARCHIVED | bbcon® Blogs
- 19 ARCHIVED | Blackbaud Luminate CRM™ Announcements
- 161 Luminate Advocacy News
- 187 Organizational Best Practices Blog
- 67 everydayhero Blog
- 52 Blackbaud SKY® Reporting Announcements
- 17 ARCHIVED | Blackbaud SKY® Reporting for K-12 Announcements
- 3 Luminate Online Product Advisory Group (LO PAG)
- 81 ARCHIVED | JustGiving® from Blackbaud® Tips and Tricks
- 1 ARCHIVED | K-12 Conference Blog
- Blackbaud Church Management™ Announcements
- ARCHIVED | Blackbaud Award Management™ and Blackbaud Stewardship Management™ Announcements
- 1 Blackbaud Peer-to-Peer Fundraising™, Powered by JustGiving® Blogs
- 39 Tips, Tricks, and Timesavers!
- 56 Blackbaud Church Management™ Resources
- 154 Blackbaud Church Management™ Announcements
- 1 ARCHIVED | Blackbaud Church Management™ Tips and Tricks
- 11 ARCHIVED | Blackbaud Higher Education Solutions™ Announcements
- 7 ARCHIVED | Blackbaud Guided Fundraising™ Blog
- 2 Blackbaud Fundraiser Performance Management™ Blog
- 9 Foundations Events and Content
- 14 ARCHIVED | Blog Posts
- 2 ARCHIVED | Blackbaud FIMS™ Announcement and Tips
- 59 Blackbaud Partner Announcements
- 10 ARCHIVED | Blackbaud Impact Edge™ EAP Blogs
- 1 Community Help Blogs
- Diocesan Blackbaud Raiser’s Edge NXT® Users' Group
- Blackbaud Consultant’s Community
- Blackbaud Francophone Group
- 1 BLOG ARCHIVE CATEGORY
- Blackbaud Community™ Discussions
- 8.3K Blackbaud Luminate Online® & Blackbaud TeamRaiser® Discussions
- 5.7K Jobs Board