Skip to content
  • A place to talk about whatever you want

    0 0
    0 Topics
    0 Posts
    No new posts.
  • Technical discussion about ActivityPub-related topics.

    6 109
    6 Topics
    109 Posts
    silverpill@mitra.socialS
    @julian I've done a review on FEP-fe34 and here's a more nuanced answer.The same-origin assumption is necessary for authentication, because it is not possible to not trust the server of origin.But it is not necessary for authorization. It is desirable, because that makes authorization procedures aligned with authentication procedures. But we can shift the burden of permission checks to the recipient.We might even have to do this, if we discover that servers accepting arbitrary payloads (C2S, FEP-ae97) can't reliably enforce the isolation of actors.But for the time being, you can accept same-origin admin deletions.
  • Blog posts from individual members

    1 1
    1 Topics
    1 Posts
    vainV
    a mediawiki dump of fedi.wiki.txt