This message was deleted.
# questions
b
This message was deleted.
👀 1
r
“Magic links” A.K.A. sharing links do not exist in the current iteration of Stacker, so it wouldn’t be possible to construct or otherwise get them from the app. It’s possible that we may be able to build a similar feature in the future, but there are fundamental security problems with having an authentication link that never expires, so another approach would be necessary, as otherwise they can easily be acquired and reused at any time.
While they could be revoked, it was a manual process, and in order to know that you should you’d first need to know that one was compromised, and which one, and then it’s really too late. With that in mind, we’d love to understand the use case better, where users can’t (won’t?) enter their email to get a one-time password to have a login session on that device, without even needing to know a password. It’s worth exploring.
g
We want to present clients with specific options. There are no sensitive information in these options so even if the link would be compromised it would not be a problem in this specific usecase. If there was any way of requesting a time based token for a user via api that would also work. And even the option to revoke the token via api once the client has made their decision that would also work. In essence we just want the client to have a seamless experience accessing the options we want to present them. Hope that makes sense but please let me know if I need to elaborate more. As it happens, I have 2 clients with similar use-cases that would immediately be able to use this feature
❤️ 1
👍 1
r
It sounds like some sort of “public access” option could potentially work in that case. What do you think?
Sharing links are, effectively, a sort of public access. But people don’t think about them that way because it’s a “login”. It may not seem like much, but it’s the difference between sending someone a link to www.example.com/mypublicpage and https://testsalescrm-2.my.stacker.app/login?api_token=80d8d0f4-b1e0-45dc — the second one looks like it’s secure, when really there’s nothing secure about either: anyone and everyone going to either URL would be able to access it freely.
g
Hi @rough-ability-90113 the public access link could be cool but its not access to a general page that I am after in this usecase, I need the person with the link to have access to only certain data in the app and limiting like you would a user makes sense to me? but you could technically have it defined by other parameters in the url also?
r
Understood. But URL parameters would also not be secret, so I don’t see how that would be different. There’s a feature request somewhat in this area, if you’re interested: https://stacker.canny.io/feature-requests/p/public-permissions
g
I understand - again in this usecase the intention/requirement is not security or secretness as much as it is exposing certain data to people dynamically i.e. blue people can be sent the blue link and they will only see the fields relevant to blue people and the same would apply to red. The fact that in this case it would be a single person is almost irrelevant. There are just "infinite" derivatives or combinations so manually building out these sets is not feasible, so using stacker/airtable to build the interface and logic could be a (low-code) option.
👍 1
I could in essence have a public site with filters and then have them go there and ask them to filter. What I am wanting is to send them a link that would pre-filter the data based on parameters coded in the link.
💯 1
I will check the feature suggestion mentioned above,
h
@gentle-refrigerator-17157 wouldn't you achieve the same with any kind of form tool with url prefill functionality? google forms or jotform has this, for example. the data submitted this way would then be passed via integration into your backend, whatever that is..
g
Hey @helpful-caravan-75149 - Lets say the client is a library and I want to display books related to their interests ranked based on how popular the book is. I also do not want to show the books they have already checked out or tagged as not interested. All this is possible if I had them login the normal way but as this info is not sensitive I would love for the experience to be simple where they just click on a link and get taken to their personalized view. Using form prepopulation would work in simple use cases but wont cut it in this instance - thanks for taking the time to make the suggestion though, really appreciate the help 😊
h
@gentle-refrigerator-17157 context is everything 🙂 thx for the details - indeed, in this case, a form isn't suitable. hope you find a way, though!
👍 1