Sorry, but requiring requests to public activitypub objects to be signed is completely whack, merveilles.town

Sorry, but requiring requests to public activitypub objects to be signed is completely whack, merveilles.town

@profpatsch@mastodon.xyz isn't this "authorized fetch", a Mastodon safety feature?
(The efficacy of the safety feature is debated, but it's a safety feature nonetheless.)
@Profpatsch interesting command line! What is that?
@evan xh, a rust rewrite of httpie, both are a nicer UX alternative to curl for http-only use-case
@Profpatsch ohhhh. I thought it was AP-specific, probably because of the `--follow` flag. Thank you!
@evan haha, no, but AP is such a plain protocol that you “usually” can use plain tools … unless people require weird signatures on GET requests. Then you need a full-on domain and an AP server just to fetch a json file …
@evan The “funny” thing here is that avoiding the restriction is absolutely trivial, e.g. I can spin up a new (sub)domain or just `tailscale funnel` myself around the blocklists.
@profpatsch@mastodon.xyz right. Yeah it is definitely annoying from an AP dev perspective, I've tried debugging requests tons of times only to find out... oops, my requests are coming from localhost, so the signature can't be verified
<img class="not-responsive emoji" src="https://activitypub.space/assets/plugins/nodebb-plugin-emoji/emoji/android/274c.png?v=0c477ea069b" title="
" />
There is a minor legitimate use case for requiring signatures on GET though, and that's for retrieving user specific objects (like non-public notes and such)
@julian @Profpatsch oh, yeah, definitely. It's really our only way to authenticate requests right now.
Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.
Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.
Con il tuo contributo, questo post potrebbe essere ancora migliore 💗
Registrati Accedi
Citiverse è un progetto che si basa su NodeBB ed è federato! | Categorie federate | Chat | 📱 Installa web app o APK | 🧡 Donazioni | Privacy Policy