Forwarded activities are believed as far as their origin vouches
A thread's server passes on what happens in it, signed with its own key: Mastodon forwards the replies to its accounts' posts and their deletions, Friendica every activity in its threads. PrivaPub answered them 401, which also tells a sender its signature failed. Now they get 202 and nothing in them is believed: a forwarded Create or Update is taken as its object reads at the actor's origin, a Delete of a public or unlisted copy once that origin answers 404 or 410 (RemoteActorService.IsGone; FederationHttp remembers the status of a refusal), anything else is let go, and our own activities coming back are ignored. A forwarded copy has its own dedupe key, so one that failed never hides the author's own delivery. A reply in the thread of someone followed here is kept, as Mastodon keeps them. Mastodon delivers a reply to the followers of the account it answers; PrivaPub dropped those as unaddressed, which the pasture showed: the outsider's reply its Mastodon scenario said was never delivered had been, and was thrown away. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
01808fa644
commit
7eb7c017a5
12 files changed
+334
-21
No files matched your search
@@ -224,6 +224,11 @@ Posts with a location (shown to nearby users of this server) never leave the ser
|
||||
- **Origins.** An actor document is accepted only from the address it names as its `id`. A key only if its actor lists
|
||||
it with `owner` set to the actor and on the actor's origin. An activity's `id`, and any object it creates, updates or
|
||||
deletes, must be on its actor's origin. An embedded object from another origin is fetched from that origin.
|
||||
- **Forwarded activities** (ActivityPub's inbox forwarding: a thread's server passing on the replies in it, signed with
|
||||
its own key) are answered 202 and believed only as far as their origin vouches for them: a created or edited post
|
||||
is read again from its author's server, a deletion of a public or unlisted post is applied once that server answers
|
||||
404 or 410, and anything else is dropped. LD signatures are not verified. A reply forwarded this way is kept when
|
||||
someone here follows the author of the post it answers, as Mastodon does.
|
||||
- **Follow requests** still unanswered are sent again after 15 minutes, an hour, 6 hours, a day, two and four days, the
|
||||
same activity each time: a server can take a Follow and lose its answer (Lemmy 1.0 sends nothing it queued for a
|
||||
server before it started sending there), and one that holds the follow already answers the copy.
|
||||
|
||||
Reference in new issue
Block a user