eh,

The solution to this is Authorized Fetch. It trades a little bit of efficiency (individual AP messages being re-shareable by intermediaries) for proper authorization (every server must fetch the messages directly from the source, with the correct authorization). Mastodon implements it behind an env variable, and implementations like GoToSocial force it. No idea how kbin or Lemmy work but they should look into it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fediverse
  • rosin
  • everett
  • thenastyranch
  • magazineikmin
  • ngwrru68w68
  • DreamBathrooms
  • modclub
  • Youngstown
  • slotface
  • PowerRangers
  • osvaldo12
  • InstantRegret
  • kavyap
  • hgfsjryuu7
  • anitta
  • Durango
  • vwfavf
  • khanakhh
  • tester
  • GTA5RPClips
  • ethstaker
  • mdbf
  • cubers
  • tacticalgear
  • normalnudes
  • cisconetworking
  • Leos
  • provamag3
  • All magazines