611abb58572a4660ba1e877c5b3d2e2d110014ef
S6 of the roadmap. An inbox POST is refused unless its signature covers (request-target) and host, as well as the digest and a date or (created). The Date or (created) may be at most an hour old and fifteen minutes ahead (it was twelve hours either way), and an (expires) in the past is refused. The request target is read raw from the server, so a percent-encoded path verifies as the sender signed it. Tests cover a Mastodon-shaped delivery and each way of tampering with it, plus a round trip of our own outbound signature. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
PrivaPub
A self-hosted ActivityPub server in C# (.NET 10, MongoDB) where one private login owns several unlinkable public personas. It federates with Mastodon, GoToSocial, Pleroma/Akkoma, Misskey and Lemmy.
- Live: https://privapub.thepra.dev
- Client: decePubClient, https://decepub.thepra.dev
- Architecture, conventions and deploy: CLAUDE.md
- Decisions and the plan to full ActivityPub interop: docs/ROADMAP.md
dotnet build PrivaPub.sln -c Release
Languages
C#
93%
Shell
6.4%
HTML
0.5%