検索

返信元:

While working on #Fedify, I noticed something about how #Misskey handles #ActivityPub object access. When a remote server requests a followers-only post or DM with a valid HTTP Signatures (draft-cavage) from an authorized actor, Misskey still returns 404 instead of the content. It seems Misskey only checks the visibility field (public/home) without verifying the signature at all. #Mastodon takes a different approach—when #authorized_fetch is enabled, it validates the HTTP Signatures and returns the content if the requesting actor has permission. I think it would be beneficial if Misskey could adopt a similar mechanism, since it would better respect the access control semantics that ActivityPub intends. Has anyone else run into this, or are there specific reasons Misskey handles it this way? #fedidev
返信 1 · Renote 0
Fedifyを開発していて気づいたことなんですが、MisskeyのActivityPubオブジェクトへのアクセス処理について少し疑問があります。リモートサーバーから、アクセス権限のあるアクターの有効なHTTP Signaturesを含むリクエストでフォロワー限定投稿やDMにアクセスしようとしても、Misskeyは内容を返さずに404を返すようです。どうやらMisskeyはHTTP Signaturesを検証せず、visibilityフィールド(publicとhome)だけを確認しているようです。 Mastodonの場合、authorized fetchを有効にすると、HTTP Signaturesを検証して、リクエストしているアクターに権限があれば内容を返します。MisskeyもMastodonのような仕組みを採用してくれたら、ActivityPubが意図しているアクセス制御のセマンティクスをより適切に尊重できるんじゃないかと思います。他の方も同じようなことに気づかれたことはありますか?それとも、Misskeyがこのような処理をしている特別な理由があるのでしょうか? #Fedify #Misskey #ActivityPub #Mastodon #authorized_fetch #fedidev

❤ 1

返信 1 · Renote 0
While working on #Fedify, I noticed something about how #Misskey handles #ActivityPub object access. When a remote server requests a followers-only post or DM with a valid HTTP Signatures (draft-cavage) from an authorized actor, Misskey still returns 404 instead of the content. It seems Misskey only checks the visibility field (public/home) without verifying the signature at all. #Mastodon takes a different approach—when #authorized_fetch is enabled, it validates the HTTP Signatures and returns the content if the requesting actor has permission. I think it would be beneficial if Misskey could adopt a similar mechanism, since it would better respect the access control semantics that ActivityPub intends. Has anyone else run into this, or are there specific reasons Misskey handles it this way? #fedidev
返信 1 · Renote 0
Excited to share that I've joined #OSSCA (Open Source Software Contribution Academy) as a mentor for the @[email protected] project! OSSCA is a national program run by South Korea's NIPA (National IT Industry Promotion Agency) through their Open Source Software Support Center, aimed at fostering the next generation of open source contributors. We're currently in the process of selecting around 20 mentees who will start contributing to #Fedify once the selection is complete. I've been busy preparing good first issues to help them get started on their open source journey. Looking forward to working with these new contributors and seeing what amazing things we can build together! #opensource #mentoring #ActivityPub #fedidev
返信 0 · Renote 1
Hi friends! :senko_happy_3:

I want to tell you all about a new thing I'm trying, where I'll accept bounties to work on specific features or bug fixes for Sharkey. If there's something you really want implemented, then you can make a donation and I'll prioritize that work over whatever other ticket I was going to work on.

To be clear, this is an agreement to *work on* a particular project, not a promise to finish it! I'll dedicate a certain amount of time to the work based on the size of the donation, and if I finish the work - then great! If not, I'll upload my progress to branch to either finish later or hand off to another interested party. I may choose to complete the work anyway if it's something that I also want, but that's not a gaurantee! Pricing is in lose terms because tracking my hours or comtting to deadlines will take all the fun out of everything. Sorry if that's an issue, but I'm not willing to negotiate on this. I *will* make sure not to "count it" if I don't actually get much work done, so don't worry about picking a bad week and wasting your money. If I don't manage enough work when I initally plan to, then I'll just save my progress and resume when I have more time. Time slots are broken down like this: • $20 - I work on my lunch break. This is usually about an hour, so I probably won't complete a whole ticket unless it's something small. • $30 - I dedicate an evening or two. The exact number of hours varies, but it's usually 2-4 per evening. I'll aim for at least 3 hours in total. • $50 - It's my weekend project. Again, my availability varies - but sometimes I spend 12+ hours between Saturday and Sunday. • $100 - This is my focus for the week. I won't devote any more Sharkey time than I would normally, but all of that time is devoted to this work item. If this sounds like something you'd like, then please reply or send a DM! For this first trial phase, I've picked a curated list of tickets that I'm willing to work on. Assuming everything goes well, I'll add more options and open up the possibility of working on brand new ideas too. I hope this can be a good deal for everyone! --- Ticket options: • #499 - enhancement: Context menu button for muting the instance of a post • #548 - enhancement: Admin feature: Ability to safely reset MFA for end users • #675 - enhancement: API Endpoint for validating scoped tokens, returning a list of assigned scopes • #746 - bug: When editing a quote, the "quote" indicator and button are not aligned • #836 - enhancement: Log IP Address of Registrants • #910 - enhancement: Allow moderators to set a content warning on any post • #943 - enhancement: Allow moderators to force a content warning for all posts by an instance • #953 - enhancement: Investigate a better on-disk structure for drive files • #997 - enhancement: Increase options for number of poll options • #1001 - enhancement: Add option to delete all users from remote instance • #1002 - bug: "Force Content Warning" does not apply to boosts • #1008 - bug: Search menu does not lookup url containing emoji • #1034 - enhancement: Multi select for adding notes to clips • #1039 - enhancement: Add change UI language when logged out • #1040 - enhancement: Hide alt-text • #1065 - enhancement: Option to hide note that are replies to a reply of a note • #1069 - bug: Send abuse reports to contact email • #1070 - enhancement: Translate Content Warning • #1071 - enhancement: Translate Alt Text • #1072 - enhancement: Allow user to specify the source language for translation • #1076 - enhancement: Support multiple hosts for email delivery • #1106 - bug: Dont mark post as long for just including certain mfm • #1110 - enhancement: Allow admins to change bio length limit

---

Clarifications and Disclaimers:

1. As stated above, this is not a promise to complete any work item! I'll put effort in - that's the only gaurantee. 2. This is not a contract of employment or payment for services. 3. If something "important" comes up, then I may pause your work item to focus on that. Think urgent bugs, security issues, or project management responsibilities. This won't count against the promised effort. 4. If multiple donations are made around the same time, then I'll complete them in order of submission. 5. If a work item is completed before I get to your request, then I'll offer the chance to select another ticket instead. 6. You're welcome to ask how long I expect a particular item to take! I may not answer in hours, but I can give a relative estimate of complexity. #Sharkey #FediDevs #FediDev #SoftwareDev
返信 0 · Renote 0
As someone who has developed several #ActivityPub software implementations (Fedify, Hollo, BotKit, and Hackers' Pub), I believe one of the most frustrating features to implement in the #fediverse is #custom_emoji. The challenges are numerous: First, there's no standardization. ActivityPub specifications don't define how custom emoji should work, leading to inconsistent implementations across different servers like Mastodon and Misskey. Rendering is particularly problematic. Emojis must display properly across different contexts (in text, as reactions, in emoji pickers) while maintaining quality at various sizes. Animated emojis add another layer of complexity. Perhaps most concerning is the poor #accessibility. Most implementations simply use the emoji code (like :party_blob:) as the alt text, which provides no meaningful information to screen reader users (in particular, non-English speakers) about what the emoji actually depicts or means. What really dampens my motivation to implement this feature is knowing I'm investing significant effort into something that ultimately creates accessibility barriers. It's disheartening to work hard on a feature that excludes part of the community. #fedidev
返信 1 · Renote 0
The version 1.2.0 of #Fedify, an #ActivityPub server framework, released! The key changes include: Added InboxContext.recipient property. It's useful for determining whether it is a shared inbox or a personal inbox, and whose personal inbox is invoked. Added getNodeInfo() function, a NodeInfo client.





Added followedMessage property, which corresponds to _misskey_followedMessage, to Actor type in Activity Vocabulary API. Log messages now can be traced using LogTape's implicit contexts, which means you can filter log messages by requestId (an HTTP request identifier) or messageId (a background task identifier). Now you can choose an AMQP driver (which supports RabbitMQ) for the message queue in the fedify init command. Added the fedify node subcommand, which fetches the given instance's NodeInfo document and visualizes it in neofetch-style. For details, see the full changelog as well! Fedify 1.2.0 is available at JSR and npm. #fedidev
返信 0 · Renote 2
I've rewritten #Fedify several times and in several languages. The first time it was written in #TypeScript, then #Python, then C#, then back to TypeScript. (It was codenamed FediKit at the time of development.) I settled on TypeScript for the following reasons: • It has a decent JSON-LD implementation. • Lots of people use it. (I wanted Fedify to be widely used.) • It's type-safe enough. Even if I were to build Fedify again, I would choose TypeScript. #fedidev #CSharp #dotnet #JavaScript
返信 0 · Renote 1
My Software Projects, Security Research, and other Computery Stuff This is a list of my favorite side projects and open-source work, collected into a single list so I can pin it to my profile. Replies are welcome! - I'm the creator and lead dev of ModShark, a standalone auto-moderator for Sharkey instances. There's a severe lack of good moderation features for fediverse nodes, but I hope to improve the situation with ModShark and other independent tools. - I occasionally publish fedi-admin-scripts, a small collection of scripts, queries, and documentation for admins of Sharkey and Akkoma instances. The goal here is low-effort knowledge sharing for the benefit of other admins. - One of my larger projects is AP-WAF, a plugin-based extensible firewall for ActivityPub software. I hope it can bridge the feature gap between different fediverse servers by moving low-level moderation and security features into the middleware layer. - I'm building ActivityPubSharp, an implementation of ActivityPub in C#. I'm using a novel approach to model AP's dynamically-typed extensions model in a type-safe way without sacrificing C#'s efficient, strong typing model. - I built little-log-scan as a tool to track botnets and other internet threats. LLS ingests webserver logs through a series of heuristic rules to detect known vulnerabilities, identify payload types, and aggregate metadata. The output is structured for easy research analysis. - As time allows, I'm building Lavender FE - a "universal" frontend for fediverse instances. Lavender is designed to seamlessly integrate multiple accounts, regardless of the instance or backend software. - I curate a list of DotNet-ActivityPub-Projects, which is exactly what it sounds like. My goal is to index all projects that implement ActivityPub using C# or another CLR language. - What started as a meme is now the Expressions AS Extension, an ActivityStreams extension meant to introduce protocol-level support for non-text communication. I hope that Expressions can enable new federated communication modes that are more comfortable to neurodivergent people. - I contribute to Letterbook, a next-generation fediverse server offering simple operation and powerful safety tools. Letterbook incorporates a unique architecture that avoids many of the classic limitations faced by fedi server projects. - I also contribute to Sharkey, a soft-fork of Misskey offering extensive quality-of-life improvements. Sharkey is designed as a safe extension of Misskey's native feature set, providing widespread improvements with minimal risk. #OpenSourceSoftware #FediDevs #FediDev #Introduction
返信 0 · Renote 0