The alt stalking plugin EchoVault (successor of PlayerScope and Memoria) currently relies on your API for features of it's public website:
Mount/minion collection icons
Renders one icon per mount/minion the character owns (per their Lodestone's public collection)
<img src="https://v2.xivapi.com/api/asset?format=webp&path=ui%2Ficon%2F004000%2F004282_hr1.tex"
alt="Alpaca" title="Alpaca 59%" style="height:32px;width:32px;border-radius:4px" loading="lazy"/>
Glamour icons
Renders one icon per equipped piece from a character's outfit, and a history of past outfits the character was seen wearing.
Those glamours are scoped directly from in-game sightings.
What can be done?
It currently doesn't filter out the referer from the browser, meaning you are fully aware these requests are refered from echovault.gg and accepting them:
GET /api/asset?format=webp&path=ui%2Ficon%2F004000%2F004282_hr1.tex HTTP/2
Host: v2.xivapi.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Accept: image/avif,image/webp,image/png,image/svg+xml,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br, zstd
Referer: https://echovault.gg/
Sec-GPC: 1
Connection: keep-alive
Sec-Fetch-Dest: image
Sec-Fetch-Mode: no-cors
Sec-Fetch-Site: cross-site
Priority: u=4, i
Pragma: no-cache
Cache-Control: no-cache
You may also be able to notice request patterns from EchoVault's backend and block them.
Please try your best to make sure your API isn't being abused for unreasonable amounts of user data collection and stalking behaviors.
The alt stalking plugin EchoVault (successor of PlayerScope and Memoria) currently relies on your API for features of it's public website:
Mount/minion collection icons
Renders one icon per mount/minion the character owns (per their Lodestone's public collection)
Glamour icons
Renders one icon per equipped piece from a character's outfit, and a history of past outfits the character was seen wearing.
Those glamours are scoped directly from in-game sightings.
What can be done?
It currently doesn't filter out the referer from the browser, meaning you are fully aware these requests are refered from echovault.gg and accepting them:
You may also be able to notice request patterns from EchoVault's backend and block them.
Please try your best to make sure your API isn't being abused for unreasonable amounts of user data collection and stalking behaviors.