question

Derevyaga Nikolay avatar image
Derevyaga Nikolay asked

Deleted secret dev key still working fine.

Hi. I revoked all secret dev keys, because I released it with the app by mistake.

But I can still easily use AdminApi with DELETED KEY from my unity editor successfully.

My title id is 497EC.

Please can you tell me what is going on asap?

Thanks

10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

1 Answer

·
Seth Du avatar image
Seth Du answered

I believe the deleting secret key is more like updating/deleting title data because it is a sharded. The time deletion synchronization takes to different shards is varies and when a server API is called, there is no guarantee that the target shard has been synced. Hence you may find different result (sometimes it shows the secret key is not valid, other time, it still returns the former result).

The synchronization will take few minutes and I have tested it in my title, and it takes 5 minutes to totally disable the deleted secret key.

Please inform us if it takes too long to disable it.

9 comments
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Derevyaga Nikolay avatar image Derevyaga Nikolay commented ·

Still working next day :) It is far far more than 5 minutes

0 Likes 0 ·
Seth Du avatar image Seth Du ♦ Derevyaga Nikolay commented ·

Thanks for the feedback I will file a bug that secret key is still working after the deletion.

0 Likes 0 ·
Derevyaga Nikolay avatar image Derevyaga Nikolay commented ·

So, please look into it

0 Likes 0 ·
Derevyaga Nikolay avatar image Derevyaga Nikolay commented ·

It is more than 12 hours past, and the key is still working fine. So, please look into it.

0 Likes 0 ·
franklinchen avatar image franklinchen Derevyaga Nikolay commented ·

Hi @Derevyaga Nikolay, may I ask the business impact of this issue? If this secret key is not shared with others, I'd like to understand the impact to set an appropriate priority. Thank you.

0 Likes 0 ·
Derevyaga Nikolay avatar image Derevyaga Nikolay franklinchen commented ·

I have released app into store with admin_api enabled, and app is pretty popular right now, so our playfab server is really vulnerable

0 Likes 0 ·
Show more comments

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.