Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
We Distribute
  1. Home
  2. Technical Discussion
  3. Mastodon may expose followers-only posts to public.

Mastodon may expose followers-only posts to public.

Scheduled Pinned Locked Moved Technical Discussion
iceshrimp
11 Posts 6 Posters 265 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • silverpill@mitra.socialS This user is from outside of this forum
    silverpill@mitra.socialS This user is from outside of this forum
    silverpill@mitra.social
    wrote on last edited by
    #1

    Mastodon may expose followers-only posts to public. Is it a feature or a bug?

    For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

    Link Preview Image
    kopper :colon_three: (@kopper)

    @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

    favicon

    not brain don't work (not-brain.d.on-t.work)

    But Mastodon says the reply is "public". Anyone can view it in this thread:

    jonny (good kind) (@jonny@neuromatch.social)

    @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

    favicon

    neurospace.live (neuromatch.social)

    #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

    @kopper Did you know about this?

    UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

    julian@activitypub.spaceJ kopper@not-brain.d.on-t.workK phnt@fluffytail.orgP finchhaven@sfba.socialF 4 Replies Last reply
    0
    • silverpill@mitra.socialS silverpill@mitra.social

      Mastodon may expose followers-only posts to public. Is it a feature or a bug?

      For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

      Link Preview Image
      kopper :colon_three: (@kopper)

      @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

      favicon

      not brain don't work (not-brain.d.on-t.work)

      But Mastodon says the reply is "public". Anyone can view it in this thread:

      jonny (good kind) (@jonny@neuromatch.social)

      @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

      favicon

      neurospace.live (neuromatch.social)

      #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

      @kopper Did you know about this?

      UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

      julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.spaceJ This user is from outside of this forum
      julian@activitypub.space
      wrote on last edited by
      #2

      That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

      If as:Public is not addressed, it is not public. End of story...

      Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

      silverpill@mitra.socialS 2 Replies Last reply
      0
      • silverpill@mitra.socialS silverpill@mitra.social

        Mastodon may expose followers-only posts to public. Is it a feature or a bug?

        For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

        Link Preview Image
        kopper :colon_three: (@kopper)

        @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

        favicon

        not brain don't work (not-brain.d.on-t.work)

        But Mastodon says the reply is "public". Anyone can view it in this thread:

        jonny (good kind) (@jonny@neuromatch.social)

        @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

        favicon

        neurospace.live (neuromatch.social)

        #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

        @kopper Did you know about this?

        UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

        kopper@not-brain.d.on-t.workK This user is from outside of this forum
        kopper@not-brain.d.on-t.workK This user is from outside of this forum
        kopper@not-brain.d.on-t.work
        wrote on last edited by
        #3
        @silverpill up until a few minutes ago my instance was doing per-instance visibility
        kopper@not-brain.d.on-t.workK 1 Reply Last reply
        0
        • kopper@not-brain.d.on-t.workK kopper@not-brain.d.on-t.work
          @silverpill up until a few minutes ago my instance was doing per-instance visibility
          kopper@not-brain.d.on-t.workK This user is from outside of this forum
          kopper@not-brain.d.on-t.workK This user is from outside of this forum
          kopper@not-brain.d.on-t.work
          wrote on last edited by
          #4
          @silverpill (to be clear, this was a patch i had on my own instance and isn't iceshrimp functionality)
          silverpill@mitra.socialS 1 Reply Last reply
          0
          • julian@activitypub.spaceJ julian@activitypub.space

            That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

            If as:Public is not addressed, it is not public. End of story...

            Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

            silverpill@mitra.socialS This user is from outside of this forum
            silverpill@mitra.socialS This user is from outside of this forum
            silverpill@mitra.social
            wrote on last edited by
            #5

            @julian The followers-only reply is also visible from NodeBB:

            Link Preview Image
            Alright it's late and i need to go to bed, but here's a draft FEP to do full account migration with posts and whatever other kinda objects you want to bring with you.

            @jonny still reading so not everything but:Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affecte...

            favicon

            ⁂ ActivityPub.Space (activitypub.space)

            1 Reply Last reply
            0
            • kopper@not-brain.d.on-t.workK kopper@not-brain.d.on-t.work
              @silverpill (to be clear, this was a patch i had on my own instance and isn't iceshrimp functionality)
              silverpill@mitra.socialS This user is from outside of this forum
              silverpill@mitra.socialS This user is from outside of this forum
              silverpill@mitra.social
              wrote on last edited by
              #6

              @kopper What does it mean? You return different objects depending on who signed the request?

              1 Reply Last reply
              0
              • silverpill@mitra.socialS silverpill@mitra.social

                Mastodon may expose followers-only posts to public. Is it a feature or a bug?

                For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

                Link Preview Image
                kopper :colon_three: (@kopper)

                @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

                favicon

                not brain don't work (not-brain.d.on-t.work)

                But Mastodon says the reply is "public". Anyone can view it in this thread:

                jonny (good kind) (@jonny@neuromatch.social)

                @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

                favicon

                neurospace.live (neuromatch.social)

                #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

                @kopper Did you know about this?

                UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

                phnt@fluffytail.orgP This user is from outside of this forum
                phnt@fluffytail.orgP This user is from outside of this forum
                phnt@fluffytail.org
                wrote on last edited by
                #7
                @silverpill It breaks FO, so this is a feature.
                1 Reply Last reply
                0
                • silverpill@mitra.socialS silverpill@mitra.social

                  Mastodon may expose followers-only posts to public. Is it a feature or a bug?

                  For example, this reply is addressed to the followers collection (to) and the mentioned user (cc😞

                  Link Preview Image
                  kopper :colon_three: (@kopper)

                  @jonny@neuromatch.social still reading so not everything but: > Supporting instances MUST indicate their support of this FEP by including its namespace in the @context of affected Actor objects. the recent archive.org downtime made all objects with contexts con...

                  favicon

                  not brain don't work (not-brain.d.on-t.work)

                  But Mastodon says the reply is "public". Anyone can view it in this thread:

                  jonny (good kind) (@jonny@neuromatch.social)

                  @kopper@not-brain.d.on-t.work i was looking for an instance metadata item that was just some list of tokens that was "the list of things that the instance supports," and i could have sworn it existed, but i couldn't find it when i looked. most fedi apps (and even most LD apps) don't actually dereference the URIs in a context and treat them as tokens anyway, but yes failure to resolve terms is a big problem and am not a fan of DNS-based linked data.

                  favicon

                  neurospace.live (neuromatch.social)

                  #Iceshrimp also doesn't require authorization, but you need to know the post ID to view it.

                  @kopper Did you know about this?

                  UPDATE: https://not-brain.d.on-t.work/notes/admrkcvj3hfn5crj is now addressed to public; apparently its audience was being modified by the originating instance depending on the delivery target.

                  finchhaven@sfba.socialF This user is from outside of this forum
                  finchhaven@sfba.socialF This user is from outside of this forum
                  finchhaven@sfba.social
                  wrote on last edited by
                  #8

                  @silverpill

                  "Mastodon may expose followers-only posts to public. Is it a feature or a bug?"

                  I hate to break this to you, but I'm seeing this on a v4.4.3 #Mastodon instance in my /home only because of the #Hashtag #Iceshrimp you've used, which I #Follow

                  Don't know if this is good news or bad news, or none of the above

                  cc @kopper

                  1 Reply Last reply
                  0
                  • julian@activitypub.spaceJ julian@activitypub.space

                    That is a little odd, and I'd think that is a violation of the implicit addressing conventions...

                    If as:Public is not addressed, it is not public. End of story...

                    Edit: oh, I loaded up the AP resource. to contains public, so that's ok.

                    silverpill@mitra.socialS This user is from outside of this forum
                    silverpill@mitra.socialS This user is from outside of this forum
                    silverpill@mitra.social
                    wrote on last edited by
                    #9

                    @julian Well, it's public now. But it wasn't when I posted 🙂

                    elvecio@wizard.casaE 1 Reply Last reply
                    0
                    • silverpill@mitra.socialS silverpill@mitra.social

                      @julian Well, it's public now. But it wasn't when I posted 🙂

                      elvecio@wizard.casaE This user is from outside of this forum
                      elvecio@wizard.casaE This user is from outside of this forum
                      elvecio@wizard.casa
                      wrote on last edited by
                      #10

                      @silverpill One thing that has always been different in Mike's software is that only authorized people can see non-public things. It is of little use to have the right address for the image, video, or file (as instead happens and happened in Mastodon Diaspora and others - almost all of them). In the software created by him, you cannot see even if you have an address/id or whatever you like.

                      silverpill@mitra.socialS 1 Reply Last reply
                      0
                      • elvecio@wizard.casaE elvecio@wizard.casa

                        @silverpill One thing that has always been different in Mike's software is that only authorized people can see non-public things. It is of little use to have the right address for the image, video, or file (as instead happens and happened in Mastodon Diaspora and others - almost all of them). In the software created by him, you cannot see even if you have an address/id or whatever you like.

                        silverpill@mitra.socialS This user is from outside of this forum
                        silverpill@mitra.socialS This user is from outside of this forum
                        silverpill@mitra.social
                        wrote on last edited by
                        #11

                        @elvecio Further investigation showed that this wasn't a Mastodon's fault. There was some weirdness on behalf of the originating instance.

                        Mastodon server received a post addressed to public and I received a post addressed to followers.

                        1 Reply Last reply
                        1
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • World
                        • Users
                        • Groups