Evan Prodromou 🇨🇦🇺🇸🇬🇷🇵🇸

u/evan@cosocial.ca
12 posts · 36 comments

Recent posts

Recent comments

@julian so, here's what RFC 7033 says:

"The host to which a WebFinger query is issued is significant. If the query target contains a "host" portion (Section 3.2.2 of RFC 3986), then the host to which the WebFinger query is issued SHOULD be the same as the "host" portion of the query target, unless the client receives instructions through some out-of-band mechanism to send the query to another host. [...]"

@julian @silverpill we did not define this well in ActivityPub.

There's an implicit authorization model (creator can write the object, addressees can read and react) which will probably be more explicit in the next version, but we'd leave open other types of authorization.

I think it's likely in the future we'll have a property for defining additional access control options.

Same-origin is a good guess but it's not as good as explicit properties.