Home | Notifications | New Note | Local | Federated | Search | Logout
Federated Timeline
ジエンP@gientoP@social.mikutter.hachune.net boosted:
@17lifers@hollow.raccoon.quest (2026-03-26 06:01:03)
#hatsunemiku #vocaloid #初音ミク #ミク https://safebooru.donmai.us/posts/11023680 - surprise! 🫶
ささきち@ssk_chi@misskey.io (2026-03-26 08:34:25)
ヨーグルトにバナナと鳥の餌みたいな穀物ときなこ+はちみつかけるとウマい:ai_umai:
ささきち@ssk_chi@misskey.io (2026-03-26 08:25:42)
:ohayoo::murakamisan_teruterubouzu:
川音リオ@KawaneRio@misskey.io (2026-03-26 07:55:00)
令和だ。
古き良き袴羽織等の着物は古着屋に賣り出され、民は皆お洋服お洋靴、洋袴に洋羽織許り。あと幾年號去れば古着屋からすらも着物が消𛀁、愈〻(いよいよ)我が母國の着物は儀式や非日常のみの傳統的衣裝と成り果てるのではないかと憂し思ふ。まぁ、覺𛀁られてゐるだけマシだと乞へ(cope)るのも救ひ手か。
warabi餅@w4rabimochi@misskey.io (2026-03-26 07:04:22)
:ame::murakamisan_teruterubouzu::murakamisan_teruterubouzu::murakamisan_teruterubouzu::murakamisan_teruterubouzu::murakamisan_teruterubouzu:
warabi餅@w4rabimochi@misskey.io (2026-03-26 07:03:49)
:ohayoo:
Reply to @Profpatsch@mastodon.xyz
silverpill@silverpill@mitra.social (2026-03-26 06:31:20)
@Profpatsch @smallcircles @phntWhat hasn’t been considered is the ability of multiple people to speak with “one voice” yet.Imageboards?
There was one that federated using ActivityPub: https://github.com/FChannel0/FChannel-Server
silverpill@silverpill@mitra.social (2026-03-26 06:19:12)
@smallcircles Fediverse is not like email because ActivityPub has many different message types. What kind of client API developers use is irrelevant.
17lifers@17lifers@hollow.raccoon.quest (2026-03-26 06:01:03)
#hatsunemiku #vocaloid #初音ミク #ミク https://safebooru.donmai.us/posts/11023680 - surprise! 🫶
Reply to @stefano@mastodon.bsd.cafe
silverpill@silverpill@mitra.social (2026-03-26 04:42:14)
@stefano @rayslava @mitra If some Mastodon API endpoint or field is missing, please let me know. I'll add it.
Reply to @Profpatsch@mastodon.xyz
silverpill@silverpill@mitra.social (2026-03-26 04:39:41)
@Profpatsch2. Activity-Level Origin Checks
Same-origin is checked rather than exact equality so that servers with multiple actors can sign on behalf of any of their actors — a common legitimate pattern.For incoming activities, consider checking exact equality. See FEP-fe34, section "Signatures":In order to minimize damage in the event of a key compromise or insufficient validation, consumers MUST verify that the signing key has the same owner as the signed object. Consumers MUST also confirm the ownership of the key by verifying a reciprocal claim.This is not strictly necessary, but would help if the origin server does poor job at validating user input.3. Embedded Object Origin Checks
Owner origin: the object's owner (actor for Activity subtypes, attributedTo for Notes/Objects) must be same-origin as the signing actor. Anonymous objects (no owner field) are accepted.In this case I also recommend checking owner ID equality, as a rule of thumb. Because origin servers implementing C2S API may fail to validate all embedded objects (which can be deeply nested).Response body size limitsYou may also need to limit the number of redirects and set a timeout. Some HTTP libraries have bad defaults.
By the way, I collect such recommendations in this guide: https://codeberg.org/ap-next/ap-next/src/branch/main/guide.md#network. Contributions are welcome!
@liaizon
あさなつくね@asanatukune@misskey.io (2026-03-26 01:44:43)
:wipppu:
---Attachments---
image: https://media.misskeyusercontent.com/io/2ca2208d-636b-4867-bc52-043aebc68620.webp?sensitive=true
warabi餅@w4rabimochi@misskey.io (2026-03-25 23:30:42)
:oyasumisskey:
Reply to @Profpatsch@mastodon.xyz
Beady Belle Fanchannel@Profpatsch@mastodon.xyz (2026-03-25 23:20:51)
@liaizon @silverpill I want to write a blog post on this at one point, but I don’t know if I missed anything or misunderstand things.
Reply to @Profpatsch@mastodon.xyz
Beady Belle Fanchannel@Profpatsch@mastodon.xyz (2026-03-25 23:19:29)
@liaizon fwiw I made & deployed some security improvements, the current security mechanisms are documented in https://codeberg.org/Profpatsch/Profpatsch/src/commit/249aa389a2023814b328af8fc795750fd28d995d/users/Profpatsch/activitypub-go/security.md
maybe @silverpill wants to take a look at whether this all sounds sensible?
Reply to @tak4
🦉@aaa (2026-03-25 18:54:15)
出汁に牡蠣味が出ておいしいですよね
warabi餅@w4rabimochi@misskey.io (2026-03-25 17:34:40)
:sigo_owa::blob_dance3:
Coro@Coro@mstdn.maud.io (2026-03-25 15:53:10)
中国大使館に侵入した自衛官、士官(3尉 少尉)なのか...
Reply to @zundan@mastodon.zunda.ninja
Coro@Coro@mstdn.maud.io (2026-03-25 15:42:13)
@zundan ISS の放熱板(液体アンモニアが流れている)に似てなくもないですね。
Reply to @zundan@mastodon.zunda.ninja
zunda@zundan@mastodon.zunda.ninja (2026-03-25 15:26:00)
そういえば!映画版宇宙船の太陽電池パドルみたいに見えるものが何なのかは分からずじまいでした。十分な燃料は積んでるはずだし太陽電池が役に立つ条件が揃うことはそんなに無さそうだと思うんだけど。
Reply to @rayslava@mitra.do.rayslava.com
Stefano Marinelli@stefano@mastodon.bsd.cafe (2026-03-25 15:09:52)
@rayslava @mitra not yet - but I’ll check it
Reply to @zundan@mastodon.zunda.ninja
zunda@zundan@mastodon.zunda.ninja (2026-03-25 15:07:11)
原作を読んだからこそわかりやすい場面もあったけど、原作を読んでなくても充分楽しめそうです。日本に行けたら吹き替えでも観てみようかな
Reply to @zundan@mastodon.zunda.ninja
zunda@zundan@mastodon.zunda.ninja (2026-03-25 15:04:28)
そういうわけで原作に無かった場面すんごいよかった!
zunda@zundan@mastodon.zunda.ninja (2026-03-25 15:03:47)
16:40に映画館に着いたら16:30からのProject Hail Maryに入場できた。何をされたのか分からない(予告編をやってました)
warabi餅@w4rabimochi@misskey.io (2026-03-25 12:36:15)
:hiru_gohan::tabeta__ii::blobcat_nomming:
Reply to @aaa
たかし@tak4 (2026-03-25 11:48:27)
牡蠣鍋いいですよね
ささきち@ssk_chi@misskey.io (2026-03-25 11:18:13)
PC置いてる部屋北向きだからその影響で日中眠くなったりするのかな…iPadProで場所変えて作業できるようにしたい:blobcatmeow_teary_eyed:
ささきち@ssk_chi@misskey.io boosted:
@so_ryu_@misskey.io (2026-03-25 01:48:06)
るるかちゃん、16歳なっても小学校からの下着着用してて欲しい
---Attachments---
image: https://media.misskeyusercontent.com/io/b16643b5-f7f3-455f-bbf0-35866d98a54a.webp?sensitive=true
ささきち@ssk_chi@misskey.io (2026-03-25 11:09:19)
作業進めないといけないのにねむすぎる:mizumochi_cry:
すけさん@sksn@mstdn.thymefield.jp (2026-03-25 09:08:56)
普段飲んでる薬、前日飲み忘れて離脱症状で殆ど動けない。
Older Notes