Egregoros

Signal feed

Timeline

Post

Remote status

Context

4
@newt @yakumo_izuru Pleroma does not even enforce that I think, only Mastodon and Acoma recently does. GTS also probably does but who even uses that.

If it is signed, the signature is valid and the key is fetchable, you will get the Object no matter if the instance is on the MRF reject list or not.

So it prevents only for scraping for those that don't properly sign the requests (most scrapers). The current scraper tries to sign requests, but it doesn't have a domain name associated.

Replies

3