Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
We Distribute
  1. Home
  2. Technical Discussion
  3. Mastodon may expose followers-only posts to public.

Mastodon may expose followers-only posts to public.

Scheduled Pinned Locked Moved Technical Discussion
iceshrimp
11 Posts 6 Posters 265 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • silverpill@mitra.socialS silverpill@mitra.social

    Mastodon may expose followers-only posts to public. Is it a feature or a bug?

    For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

    Link Preview Image
    kopper :colon_three: (@kopper)

    @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

    favicon

    not brain don't work (not-brain.d.on-t.work)

    But Mastodon says the reply is "public". Anyone can view it in this thread:

    jonny (good kind) (@jonny@neuromatch.social)

    @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

    favicon

    neurospace.live (neuromatch.social)

    #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

    @kopper Did you know about this?

    UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

    julian@activitypub.spaceJ This user is from outside of this forum
    julian@activitypub.spaceJ This user is from outside of this forum
    julian@activitypub.space
    wrote on last edited by
    #2

    That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

    If as:Public is not addressed, it is not public. End of story...

    Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

    silverpill@mitra.socialS 2 Replies Last reply
    0
    • silverpill@mitra.socialS silverpill@mitra.social

      Mastodon may expose followers-only posts to public. Is it a feature or a bug?

      For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

      Link Preview Image
      kopper :colon_three: (@kopper)

      @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

      favicon

      not brain don't work (not-brain.d.on-t.work)

      But Mastodon says the reply is "public". Anyone can view it in this thread:

      jonny (good kind) (@jonny@neuromatch.social)

      @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

      favicon

      neurospace.live (neuromatch.social)

      #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

      @kopper Did you know about this?

      UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

      kopper@not-brain.d.on-t.workK This user is from outside of this forum
      kopper@not-brain.d.on-t.workK This user is from outside of this forum
      kopper@not-brain.d.on-t.work
      wrote on last edited by
      #3
      @silverpill up until a few minutes ago my instance was doing per-instance visibility
      kopper@not-brain.d.on-t.workK 1 Reply Last reply
      0
      • kopper@not-brain.d.on-t.workK kopper@not-brain.d.on-t.work
        @silverpill up until a few minutes ago my instance was doing per-instance visibility
        kopper@not-brain.d.on-t.workK This user is from outside of this forum
        kopper@not-brain.d.on-t.workK This user is from outside of this forum
        kopper@not-brain.d.on-t.work
        wrote on last edited by
        #4
        @silverpill (to be clear, this was a patch i had on my own instance and isn't iceshrimp functionality)
        silverpill@mitra.socialS 1 Reply Last reply
        0
        • julian@activitypub.spaceJ julian@activitypub.space

          That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

          If as:Public is not addressed, it is not public. End of story...

          Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

          silverpill@mitra.socialS This user is from outside of this forum
          silverpill@mitra.socialS This user is from outside of this forum
          silverpill@mitra.social
          wrote on last edited by
          #5

          @julian The followers-only reply is also visible from NodeBB:

          Link Preview Image
          Alright it's late and i need to go to bed, but here's a draft FEP to do full account migration with posts and whatever other kinda objects you want to bring with you.

          @jonny still reading so not everything but:Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affecte...

          favicon

          ⁂ ActivityPub.Space (activitypub.space)

          1 Reply Last reply
          0
          • kopper@not-brain.d.on-t.workK kopper@not-brain.d.on-t.work
            @silverpill (to be clear, this was a patch i had on my own instance and isn't iceshrimp functionality)
            silverpill@mitra.socialS This user is from outside of this forum
            silverpill@mitra.socialS This user is from outside of this forum
            silverpill@mitra.social
            wrote on last edited by
            #6

            @kopper What does it mean? You return different objects depending on who signed the request?

            1 Reply Last reply
            0
            • silverpill@mitra.socialS silverpill@mitra.social

              Mastodon may expose followers-only posts to public. Is it a feature or a bug?

              For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

              Link Preview Image
              kopper :colon_three: (@kopper)

              @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

              favicon

              not brain don't work (not-brain.d.on-t.work)

              But Mastodon says the reply is "public". Anyone can view it in this thread:

              jonny (good kind) (@jonny@neuromatch.social)

              @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

              favicon

              neurospace.live (neuromatch.social)

              #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

              @kopper Did you know about this?

              UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

              phnt@fluffytail.orgP This user is from outside of this forum
              phnt@fluffytail.orgP This user is from outside of this forum
              phnt@fluffytail.org
              wrote on last edited by
              #7
              @silverpill It breaks FO, so this is a feature.
              1 Reply Last reply
              0
              • silverpill@mitra.socialS silverpill@mitra.social

                Mastodon may expose followers-only posts to public. Is it a feature or a bug?

                For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

                Link Preview Image
                kopper :colon_three: (@kopper)

                @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

                favicon

                not brain don't work (not-brain.d.on-t.work)

                But Mastodon says the reply is "public". Anyone can view it in this thread:

                jonny (good kind) (@jonny@neuromatch.social)

                @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

                favicon

                neurospace.live (neuromatch.social)

                #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

                @kopper Did you know about this?

                UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

                finchhaven@sfba.socialF This user is from outside of this forum
                finchhaven@sfba.socialF This user is from outside of this forum
                finchhaven@sfba.social
                wrote on last edited by
                #8

                @silverpill

                "Mastodon may expose followers-only posts to public. Is it a feature or a bug?"

                I hate to break this to you, but I'm seeing this on a v4.4.3 #Mastodon instance in my /home only because of the #Hashtag #Iceshrimp you've used, which I #Follow

                Don't know if this is good news or bad news, or none of the above

                cc @kopper

                1 Reply Last reply
                0
                • julian@activitypub.spaceJ julian@activitypub.space

                  That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

                  If as:Public is not addressed, it is not public. End of story...

                  Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

                  silverpill@mitra.socialS This user is from outside of this forum
                  silverpill@mitra.socialS This user is from outside of this forum
                  silverpill@mitra.social
                  wrote on last edited by
                  #9

                  @julian Well, it's public now. But it wasn't when I posted 🙂

                  elvecio@wizard.casaE 1 Reply Last reply
                  0
                  • silverpill@mitra.socialS silverpill@mitra.social

                    @julian Well, it's public now. But it wasn't when I posted 🙂

                    elvecio@wizard.casaE This user is from outside of this forum
                    elvecio@wizard.casaE This user is from outside of this forum
                    elvecio@wizard.casa
                    wrote on last edited by
                    #10

                    @silverpill One thing that has always been different in Mike's software is that only authorized people can see non-public things. It is of little use to have the right address for the image, video, or file (as instead happens and happened in Mastodon Diaspora and others - almost all of them). In the software created by him, you cannot see even if you have an address/id or whatever you like.

                    silverpill@mitra.socialS 1 Reply Last reply
                    0
                    • elvecio@wizard.casaE elvecio@wizard.casa

                      @silverpill One thing that has always been different in Mike's software is that only authorized people can see non-public things. It is of little use to have the right address for the image, video, or file (as instead happens and happened in Mastodon Diaspora and others - almost all of them). In the software created by him, you cannot see even if you have an address/id or whatever you like.

                      silverpill@mitra.socialS This user is from outside of this forum
                      silverpill@mitra.socialS This user is from outside of this forum
                      silverpill@mitra.social
                      wrote on last edited by
                      #11

                      @elvecio Further investigation showed that this wasn't a Mastodon's fault. There was some weirdness on behalf of the originating instance.

                      Mastodon server received a post addressed to public and I received a post addressed to followers.

                      1 Reply Last reply
                      1
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups