Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. your daily dose of json+ld, #fedidev

your daily dose of json+ld, #fedidev

Scheduled Pinned Locked Moved Uncategorized
fedidev
10 Posts 3 Posters 9 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • profpatsch@mastodon.xyzP This user is from outside of this forum
    profpatsch@mastodon.xyzP This user is from outside of this forum
    profpatsch@mastodon.xyz
    wrote last edited by
    #1

    your daily dose of json+ld, #fedidev

    Link Preview Image
    phnt@fluffytail.orgP 1 Reply Last reply
    1
    1
    • R relay@relay.mycrowd.ca shared this topic
    • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

      your daily dose of json+ld, #fedidev

      Link Preview Image
      phnt@fluffytail.orgP This user is from outside of this forum
      phnt@fluffytail.orgP This user is from outside of this forum
      phnt@fluffytail.org
      wrote last edited by
      #2

      @Profpatsch@mastodon.xyz enjoy: https://github.com/swicg/activitypub-api/issues/1#issuecomment-3708524521

      profpatsch@mastodon.xyzP 1 Reply Last reply
      0
      • phnt@fluffytail.orgP phnt@fluffytail.org

        @Profpatsch@mastodon.xyz enjoy: https://github.com/swicg/activitypub-api/issues/1#issuecomment-3708524521

        profpatsch@mastodon.xyzP This user is from outside of this forum
        profpatsch@mastodon.xyzP This user is from outside of this forum
        profpatsch@mastodon.xyz
        wrote last edited by
        #3

        @phnt OAuth is another “standard” that we should develop some workaround for

        profpatsch@mastodon.xyzP thisismissem@activitypub.spaceT 2 Replies Last reply
        1
        0
        • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

          @phnt OAuth is another “standard” that we should develop some workaround for

          profpatsch@mastodon.xyzP This user is from outside of this forum
          profpatsch@mastodon.xyzP This user is from outside of this forum
          profpatsch@mastodon.xyz
          wrote last edited by
          #4

          @phnt If you depend on specialized “profiles” for a “standard” with multiple RFCs of thousands of branching MAYs and MIGHTs, your just sidelined any non-professional developers into never being able to interact with your protocol

          profpatsch@mastodon.xyzP 1 Reply Last reply
          1
          0
          • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

            @phnt If you depend on specialized “profiles” for a “standard” with multiple RFCs of thousands of branching MAYs and MIGHTs, your just sidelined any non-professional developers into never being able to interact with your protocol

            profpatsch@mastodon.xyzP This user is from outside of this forum
            profpatsch@mastodon.xyzP This user is from outside of this forum
            profpatsch@mastodon.xyz
            wrote last edited by
            #5

            @phnt corollary: if you need people to include libraries with the footprint of multiple garbage trucks just to interface with your thing, your thing is GARBAGE, sorry I don’t make the rules …

            1 Reply Last reply
            1
            0
            • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

              @phnt OAuth is another “standard” that we should develop some workaround for

              thisismissem@activitypub.spaceT This user is from outside of this forum
              thisismissem@activitypub.spaceT This user is from outside of this forum
              thisismissem@activitypub.space
              wrote last edited by
              #6

              @profpatsch@mastodon.xyz OAuth 2.1, which is what I've been steering people towards is much safer and easier to implement than OAuth 2.0 as a lot of the security footguns have been solved or very well documented. We will end up with an OAuth profile for ActivityPub, but it'll probably just be mostly identical to the OAuth profile from AT Protocol.

              Though, at the same time I'll often ask "do we really need OAuth for this, or would ... be a better solution?"

              1 Reply Last reply
              1
              0
              • profpatsch@mastodon.xyzP This user is from outside of this forum
                profpatsch@mastodon.xyzP This user is from outside of this forum
                profpatsch@mastodon.xyz
                wrote last edited by
                #7

                @thisismissem yeah, exactly.

                profpatsch@mastodon.xyzP 1 Reply Last reply
                1
                0
                • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

                  @thisismissem yeah, exactly.

                  profpatsch@mastodon.xyzP This user is from outside of this forum
                  profpatsch@mastodon.xyzP This user is from outside of this forum
                  profpatsch@mastodon.xyz
                  wrote last edited by
                  #8

                  @thisismissem but people discussing whether we need 20 or 50 permission settings really shows that the abstraction itself is fundamentally broken

                  thisismissem@activitypub.spaceT 1 Reply Last reply
                  1
                  0
                  • profpatsch@mastodon.xyzP profpatsch@mastodon.xyz

                    @thisismissem but people discussing whether we need 20 or 50 permission settings really shows that the abstraction itself is fundamentally broken

                    thisismissem@activitypub.spaceT This user is from outside of this forum
                    thisismissem@activitypub.spaceT This user is from outside of this forum
                    thisismissem@activitypub.space
                    wrote last edited by
                    #9

                    @profpatsch@mastodon.xyz and as you'll see in that conversation, I'm saying we don't actually need 20-50 permissions, but rather Rich Authorization Requests, which are specifically designed for this type of thing.

                    profpatsch@mastodon.xyzP 1 Reply Last reply
                    0
                    • thisismissem@activitypub.spaceT thisismissem@activitypub.space

                      @profpatsch@mastodon.xyz and as you'll see in that conversation, I'm saying we don't actually need 20-50 permissions, but rather Rich Authorization Requests, which are specifically designed for this type of thing.

                      profpatsch@mastodon.xyzP This user is from outside of this forum
                      profpatsch@mastodon.xyzP This user is from outside of this forum
                      profpatsch@mastodon.xyz
                      wrote last edited by
                      #10

                      @thisismissem I’m all for that, because splitting things up on GET/POST on endpoints leads to exploits (gap in intent vs mechanism)

                      1 Reply Last reply
                      1
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups