Hi, I read your post about the new "/download/", and the new way to download attachments, specially for users using API.
https://trello.com/c/oIHLR6b1/85-authenticated-access-to-s3
I had to do similar implementation using other API, and I think that you're the only one who will "always" require to pass the token + key.
I think that will make it too easy to get our token lost in the public, as I can just click a url in a browser to give it to a friend, and I don't know that my secret key is in it.
If someone uses a browser, and it is already logged to trello, is it possible that, followint the download link WITHOUT key / token, opens the url?
https://api.trello.com/1/cards/xxx/attachments/yyy/download/
Automatically starts download if if the user is connected to trello UI and has the right to download it.
Or, redirect to the "login page" if the user is not connected, then start download.
I understand that, from server-side, it's impossible to do that, and it's very nice to be able to get the document using the key-token querystring.
But, in all other cases, like in a browser, or if I export some informations, including download links of files, I really don't want to include these informations.
Actually, we provide functionality to export attachments (descriptions), including download urls. We know that these were insecure, and I totally understand why you now require an authentication.
But, again, I think that, from the download link, WITHOUT querystring, the download should start if the user is logged, or if he "can" login from your login page, and then be redirected to that file.
That's the behavior I see in all other application API that need to provide attachments download.