<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://developer.myspace.com/Community/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>makeRequest</title><link>http://developer.myspace.com/Community/forums/30.aspx</link><description>Questions related to the OpenSocial makeRequest function and our proxy.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20910.1126)</generator><item><title>Re: Security: Ajax on profile</title><link>http://developer.myspace.com/Community/forums/thread/8851.aspx</link><pubDate>Mon, 28 Apr 2008 12:34:40 GMT</pubDate><guid isPermaLink="false">8e485011-333f-425c-b84a-1febdb8bfab0:8851</guid><dc:creator>Chak</dc:creator><slash:comments>0</slash:comments><comments>http://developer.myspace.com/Community/forums/thread/8851.aspx</comments><wfw:commentRss>http://developer.myspace.com/Community/forums/commentrss.aspx?SectionID=30&amp;PostID=8851</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Exactly - please use SIGNED makeRequest() calls. There&amp;#39;s &lt;/p&gt;&lt;p&gt;Thanks Jeremy for the post.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Chak&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Security: Ajax on profile</title><link>http://developer.myspace.com/Community/forums/thread/8794.aspx</link><pubDate>Sun, 27 Apr 2008 22:41:04 GMT</pubDate><guid isPermaLink="false">8e485011-333f-425c-b84a-1febdb8bfab0:8794</guid><dc:creator>Jeremy</dc:creator><slash:comments>0</slash:comments><comments>http://developer.myspace.com/Community/forums/thread/8794.aspx</comments><wfw:commentRss>http://developer.myspace.com/Community/forums/commentrss.aspx?SectionID=30&amp;PostID=8794</wfw:commentRss><description>&lt;p&gt;Well, if you&amp;#39;re using OpenSocial&amp;#39;s MakeRequest function, you can set it&amp;#39;s Authentication to Signed, which OAuth-signs the outgoing request, and also adds opensocial_viewer_id and opensocial_owner_id parameters so that you know whose profile (owner) it&amp;#39;s coming from, and who is looking at the profile at that time (viewer). &lt;/p&gt;</description></item><item><title>Security: Ajax on profile</title><link>http://developer.myspace.com/Community/forums/thread/8782.aspx</link><pubDate>Sun, 27 Apr 2008 16:51:20 GMT</pubDate><guid isPermaLink="false">8e485011-333f-425c-b84a-1febdb8bfab0:8782</guid><dc:creator>mike</dc:creator><slash:comments>0</slash:comments><comments>http://developer.myspace.com/Community/forums/thread/8782.aspx</comments><wfw:commentRss>http://developer.myspace.com/Community/forums/commentrss.aspx?SectionID=30&amp;PostID=8782</wfw:commentRss><description>&lt;p&gt;Is there a way to validate that an ajax call your making from the profile is actually comming from a myspace profile and validate whos profile its coming from?&amp;nbsp;&lt;/p&gt;</description></item></channel></rss>