@julian so, I read that as "You should use the hostname from the webfinger unless you don't want to or it's not there." Your directory idea sounds fine. I could see using it as a high-performance cache, for example.
"[...] If the query target does not contain a "host" portion, then the client chooses a host to which it directs the query using additional information it has."
"The host to which a WebFinger query is issued is significant. If the query target contains a "host" portion (Section 3.2.2 of RFC 3986), then the host to which the WebFinger query is issued SHOULD be the same as the "host" portion of the query target, unless the client receives instructions through some out-of-band mechanism to send the query to another host. [...]"
There's an implicit authorization model (creator can write the object, addressees can read and react) which will probably be more explicit in the next version, but we'd leave open other types of authorization.
I think it's likely in the future we'll have a property for defining additional access control options.
Same-origin is a good guess but it's not as good as explicit properties.
@julian srsly
@julian so, I read that as "You should use the hostname from the webfinger unless you don't want to or it's not there." Your directory idea sounds fine. I could see using it as a high-performance cache, for example.
@julian
"[...] If the query target does not contain a "host" portion, then the client chooses a host to which it directs the query using additional information it has."
@julian so, here's what RFC 7033 says:
"The host to which a WebFinger query is issued is significant. If the query target contains a "host" portion (Section 3.2.2 of RFC 3986), then the host to which the WebFinger query is issued SHOULD be the same as the "host" portion of the query target, unless the client receives instructions through some out-of-band mechanism to send the query to another host. [...]"
I am now following @tricentennial to stay informed.
@julian @silverpill we did not define this well in ActivityPub.
There's an implicit authorization model (creator can write the object, addressees can read and react) which will probably be more explicit in the next version, but we'd leave open other types of authorization.
I think it's likely in the future we'll have a property for defining additional access control options.
Same-origin is a good guess but it's not as good as explicit properties.
@Auster @NorskSud archive.org has a wonderful permanent s3-compatible API which would be great for this.
https://archive.org/developers/ias3.html
I bet @internetarchive would help out with this if software developers or administrators wanted to use it.
@julian I find the GitHub scans pretty helpful, but I guess there are more specific bugs that people report.
@julian This seems like something you could do yourself, and cut out the middleman.
@astro @julian I think channel.org and Surf are doing this at a higher level.
@smallcircles @hongminhee and the ActivityPub API task force at the W3C!
https://github.com/swicg/activitypub-api
@PugJesus source?
@faab64 @palestine@lemmy.ml @palestine@fedibird.com Propaganda. Western media has been portraying Palestinian people as irrational, bloodthirsty terrorists since at least the 1970s.
@sabreW4K3 good
@pete_link good.
@Die4Ever
https://datatracker.ietf.org/doc/html/rfc7565
@rimu web+acct
@julian @trwnh dooooooo iiiiiiiiit
@mattblaze@federate.social wow, fantastic.
@atomicpoet @movies This is a great film!