Home | Notifications | New Note | Local | Federated | Search | Logout

silverpill@silverpill@mitra.social

Developer of ActivityPub-based micro-blogging and content subscription platform Mitra. I help maintain the FEP repository and write my own FEPs too. Currently working on ActivityPub Next.

Code: https://codeberg.org/silverpill/
Matrix: @silverpill:unredacted.org
XMPP: silverpill@were.chat
$XMR: 48YM8jwJqDkeUvD38vepSXFeMZH1zsjbvGwTTuaNSSq6Q5GyeWaeiheAZUsSmNn72YdyLpw8geb4FL3opZfGbguJLUj8Mi9
XMR subscription: https://mitra.social/@silverpill/subscription
PGP: 0541 49E3 0F91 C6D7 8FFA C49C 955F 5A6E 2123 25F0
OMEMO fingerprint: 689a2fb0ec87a9481fb45cb7d8870da6aeb4d8247bd69a39017701133b901f04
Matrix (backup): @silverpill:poa.st Joined: 2026-01-05 16:03:27 435 notes, 1 following, 0 followers

Reply to @maddyunderstars@aus.social silverpill@silverpill@mitra.social (2026-06-04 17:34:52) @maddyunderstars The use of Invite as attributed object conflicts with Activity Vocabulary where Invite is defined as activity: https://www.w3.org/TR/activitystreams-vocabulary/#dfn-invite

Could it be replaced with an Invite activity? I think in that case instead of attributedTo it would have an actor property, and maybe also a target property pointing to actor's followers collection.

Reply to @xwyqi@fedi.xwyqi.org silverpill@silverpill@mitra.social (2026-06-03 16:45:29) @xwyqi Neat

Reply to @anotherdoesnm@har.mony.lol silverpill@silverpill@mitra.social (2026-06-03 16:18:54) @anotherdoesnm hello there

Reply to @setto@tooting.ch silverpill@silverpill@mitra.social (2026-06-02 19:53:48) @setto @mho There is no downward trend in development activity (source: weekly software updates https://mitra.social/@weekinfediverse). The number of active users remains ~constant but I think it means that quantity becomes quality: people who don't care about decentralization leave and are replaced by those who care, more people are self-hosting and/or migrating from mastodon to better fedi software, etc.

silverpill@silverpill@mitra.social (2026-06-02 19:37:59) I am working on a new FEP called Groups and permissions:

https://codeberg.org/silverpill/feps/src/branch/main/5219/fep-5219.md

It is an attempt to translate XEP-0045: Multi-User Chat to ActivityPub

#xmpp

Reply to @nutomic@lemmy.ml silverpill@silverpill@mitra.social (2026-06-02 04:56:21) Thanks!

Tried to follow a private community, and I have a problem with this Accept activity:

{"@context":["https://join-lemmy.org/context.json","https://www.w3.org/ns/activitystreams"],"actor":"https://voyager.lemmy.ml/c/privfedtest","id":"https://voyager.lemmy.ml/activities/accept/6a08b817-9dc2-498a-a637-9092c8ea15fc","object":{"actor":"https://mitra.social/users/silverpill","id":"https://voyager.lemmy.ml/activities/follow/3c08aca5-9e41-4d15-b134-326c4bd91bd0","object":"https://voyager.lemmy.ml/c/privfedtest","to":["https://voyager.lemmy.ml/c/privfedtest"],"type":"Follow"},"to":["https://mitra.social/users/silverpill"],"type":"Accept"}

The id inside Accept.object is not the ID of my Follow activity, it's something different. Its origin is not my server:

https://voyager.lemmy.ml/activities/follow/3c08aca5-9e41-4d15-b134-326c4bd91bd0

Reply to @phnt@fluffytail.org silverpill@silverpill@mitra.social (2026-06-01 17:48:30) @phnt Cool. It didn't occur to me at first that this is possible, but of course it is.

I am going to implement this in Mitra.

Reply to @phnt@fluffytail.org silverpill@silverpill@mitra.social (2026-06-01 17:38:07) @phnt So Pleroma allows you to use same OAuth token for MastoAPI and AP C2S endpoints?

silverpill@silverpill@mitra.social boosted: @fitpub@fosstodon.org (2026-06-01 15:48:28) FitPub 1.0 is here! 🚴🏃🥾

FitPub is a federated social fitness platform and Strava alternative built on ActivityPub, giving athletes control over their data, communities, and connections.

Today also marks the launch of the first official FitPub instance: > https://fitpub.social

Source code: > https://codeberg.org/fitpub/fitpub

#FitPub #ActivityPub #Fediverse #OpenSource #Cycling #Running #Hiking

silverpill@silverpill@mitra.social (2026-06-01 05:20:47) Hello @nutomic, could you add my instance to the allowlist? I'd like to test federation with private communities.

Reply to @julian@activitypub.space silverpill@silverpill@mitra.social (2026-06-01 04:52:32) If there is no forwarding of comments, then each cross post produces an independent context, right?

Reply to @Em0nM4stodon@infosec.exchange silverpill@silverpill@mitra.social (2026-05-31 04:39:46) @Em0nM4stodon

I made this: https://codeberg.org/silverpill/mitra

A federated social platform with Monero subscriptions.

silverpill@silverpill@mitra.social boosted: @tommi@pan.rent (2026-05-30 01:38:06) https://prikbord.page was just launched!

Super iper cool federated calendar for events in Rotterdam (and potentially beyond!) built with @11ty on top of @gancio, including a print function powered by @pagedjs ❤️‍🔥

Still WIP but already working (wonderfully) at @relay 👀

All the code is 100% Free Software, available at https://git.vvvvvvaria.org/prikbord.page 💕

#Prikbord #Gancio #11ty #Eleventy #BuildAwesome #Rotterdam #FreeSoftware #OpenSource #StimuleringFonds #events #Rotterdam #Fediverse #launch #MVP #software #OpenSource #PagedJS #WebToPrint #Web2Print ---Attachments--- image: https://media.pan.rent/media_attachments/files/116/658/817/098/759/089/original/c981db8f47c3c9a2.jpg
image: https://media.pan.rent/media_attachments/files/116/658/817/308/627/591/original/af91ad97aa05b1ab.jpg
image: https://media.pan.rent/media_attachments/files/116/658/817/518/032/511/original/f978d7d481999b94.jpg
image: https://media.pan.rent/media_attachments/files/116/658/817/865/698/134/original/e99a177aa2805490.jpg

Reply to @ozoramore_dev@social.t2arc.net silverpill@silverpill@mitra.social (2026-05-31 01:04:47) @ozoramore_dev Do you want to add a link to mitra-web page?

Reply to @innocentzero@social.tchncs.de silverpill@silverpill@mitra.social (2026-05-30 04:35:37) @innocentzero Have a look at this:

https://fediverse.codeberg.page/fep/fep/ef61/

It enables DID addressing in ActivityPub, and client-side signing.

Reply to @julian@activitypub.space silverpill@silverpill@mitra.social (2026-05-30 04:15:44) So you send a Create to the primary community, and then CrossPost to secondary communities. All comments are forwarded to the primary community. The primary communities also moderates the thread.

I am understanding it correctly?

This sounds similar to a "repost" in blogo-verse.

And the current implementation (with separate entities) is more similar to quote posts.

Reply to @julian@activitypub.space silverpill@silverpill@mitra.social (2026-05-30 03:59:26) If you were to implement federated cross-posting, how it would work? A post addressed to multiple communities (more than 1 item in audience)?

silverpill@silverpill@mitra.social (2026-05-30 01:02:22) @julian Hi, what's the status of this? Is cross-posting still done by making a copy of a post?

Reply to @lauti@bonfire.cafe silverpill@silverpill@mitra.social (2026-05-30 00:46:09) @lauti It's okay, Lemmy and Friendica put a server actor there.

>activity delivery issues

My server drops your Accept activity because you don't sign the Digest header.

Reply to @jae@mastodon.bsd.cafe silverpill@silverpill@mitra.social (2026-05-30 00:33:07) @jae @fionescu Mitra can connect to multiple networks at once, but one of them must be chosen as primary, usually it's clearnet. My instance connects to Tor, I2P and Yggdrasil instances.

I am not sure if that counts as clean interop.
I think seamless interop without touching clearnet may be achieved with Mitra Mini

Reply to @swetland@chaos.social silverpill@silverpill@mitra.social (2026-05-29 01:35:42) @swetland FEP-8b32 implementations use Ed25519:

https://codeberg.org/fediverse/fep/src/branch/main/fep/8b32/fep-8b32.md#implementations

But for HTTP signatures everyone still uses RSA because dominant implementations don't support Ed25519

Reply to @doesnm@holos.social silverpill@silverpill@mitra.social (2026-05-29 00:39:33) @doesnm Password login works for me. Could you ask your friend what login method they use? Maybe it's not a password login but something else?

silverpill@silverpill@mitra.social boosted: @phoenix_r_d@mastodon.social (2026-05-27 18:24:34) OpenMLS, our implementation of the Messaging Layer Security (MLS) protocol, has undergone a security audit conducted by @srlabs and sponsored by the @sovtechfund.

The security audit marks an important step toward making OpenMLS more secure. In this post, we share the results and take the opportunity to give a broader introduction to OpenMLS.

https://blog.phnx.im/openmls-independent-security-audit/

Reply to @morph2@morph.todon.de silverpill@silverpill@mitra.social (2026-05-27 16:04:38) @morph2

>'invalid access token'

This is because some clients don't support OAuth tokens with limited lifetime. I suggest opening an issue in the respective issue trackers.

Logging out may help. Alternatively, you can change the authentication_token_lifetime parameter in your configuration file to a bigger number:

https://codeberg.org/silverpill/mitra/src/commit/37eebd0e308f047612de433b6286a3f2ec731058/config.example.yaml#L63-L64

>Sengi never worked with Mitra which is sad anyway.

I just tried to log in to the web version at https://nicolasconstant.github.io/sengi/

It's working.

@apps

Reply to @phnt@fluffytail.org silverpill@silverpill@mitra.social (2026-05-26 04:36:25) @phnt Could you fix this? https://git.pleroma.social/pleroma/pleroma/issues/2413

Reply to @silverpill@mitra.social silverpill@silverpill@mitra.social (2026-05-24 18:39:56) @julian I've done a review on FEP-fe34 and here's a more nuanced answer.

The same-origin assumption is necessary for authentication, because it is not possible to not trust the server of origin.

But it is not necessary for authorization. It is desirable, because that makes authorization procedures aligned with authentication procedures. But we can shift the burden of permission checks to the recipient.

We might even have to do this, if we discover that servers accepting arbitrary payloads (C2S, FEP-ae97) can't reliably enforce the isolation of actors.

But for time being, you can accept same-origin admin deletions.

Reply to @silverpill@mitra.social silverpill@silverpill@mitra.social (2026-05-24 07:16:21) @tadano @MK2boogaloo I pushed the fix to the main branch. Also allowed media proxy to serve application/octet-stream

Reply to @0461fcbecc4c3374439932d6b8f11269ccdb7cc973ad7a50ae362db135a474dd@mostr.pub silverpill@silverpill@mitra.social (2026-05-24 06:28:33) @0461fcbecc4c3374439932d6b8f11269ccdb7cc973ad7a50ae362db135a474dd @8c593cc6084205228f9d5f826249596710bbbee6236d54e2c74b2826d00e4c83 The client is a separate project, Mitra Mini. Partially based on Mitra, but I had to rebuild other parts from scratch.

It is the only implementation, and has at least two users 😆

Reply to @phnt@fluffytail.org silverpill@silverpill@mitra.social (2026-05-24 06:23:24) @phnt

>Although you would still need some way to publish that key and a valid Actor for verification, a server.

I just realized that it could be effective in island networks, where domains are allowlisted.

Reply to @0461fcbecc4c3374439932d6b8f11269ccdb7cc973ad7a50ae362db135a474dd@mostr.pub silverpill@silverpill@mitra.social (2026-05-24 06:09:33) @0461fcbecc4c3374439932d6b8f11269ccdb7cc973ad7a50ae362db135a474dd @8c593cc6084205228f9d5f826249596710bbbee6236d54e2c74b2826d00e4c83 Yes. Relays are usually called gateways, but the architecture is very similar.

https://codeberg.org/ap-next/ap-next/src/branch/main/nomadpub.md
Older Notes