We're phasing OStatus out of Mastodon (we've supported it 2 years longer than we've used it) which removes a lot of cognitive load from further development of features and maintenance #mastodev

There is a new optional feature in the master branch called authorized-fetch mode, which requires all fetches of ActivityPub resources to be signed, which in turn allows to reject fetches from domain-blocked servers.

Enabling this right now is not a great idea because current Mastodon versions don't sign all requests, so some functions would be impacted, a slow roll-out is advised #mastodev

Show thread

@Gargron I assume even with this enabled public posts can not be viewed by anyone running something other than mastodon? Or does it not effect public posts and one effects posts you share friends-only?

As always thanks for your hard work.

Follow

@Gargron Cool, so its really just a way to make the followers-only posts actually enforcable. Makes sense.

This also means it wont work with anything but mastodon servers right? Its not ActivityPub standard compliant I presume?

Β· Β· 1 Β· 0 Β· 0

@freemo No, followers-only posts are already enforcable. It's a way to make public posts enforcable. And no, signatures are a basic component of ActivityPub, so it's not a break away from standards.

@Gargron Ahh wonderful, thank you for all the info. Good luck. As always if i can help with anything just let me know.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.