found a bug in pleroma miniapps deploying after I take a shower
Timeline
Post
Remote status
Context
17
@sun@shitposter.world lmk when you merge my pr so i can drop my workaround from my misskey fork
@anemone ok I'm reading it after I take a shower.
@anemone it won't break existing installation right?
@sun@shitposter.world yeah it will unfortunately because your current registration system conflicts with OAuth2 DCR. I'm not intending to push you to do it right away I just want to know when it happens so I can remove the shim I have in place
@anemone oh woops already merged. I guess we just force everyone to log in again?
@anemone tell me what I need to do to support this right away
@sun@shitposter.world it wont invalidate existing sessions
@anemone ok so it is actually ok, it will just make people log in again? there's already a bug on pleroma thats forcing that anyway
@anemone incidentally if there's a way to generalize how we get identity and post statuses so it supports both mastodon and misskey so its not a terrible burden for miniapp developers, I am okay with supporting just these two
@sun@shitposter.world yeah I'm still looking at that aspect. probably some fairly simple stuff I can do. my PR was just focused on making the app registration path work with Oauth2's dynamic client registration and discovery specs
@anemone no problem just saying.
I am looking at maybe getting some money from someone to work on this, and it may be possible for me to maintain patches for mastodon and misskey if those projects won't upstream
I am looking at maybe getting some money from someone to work on this, and it may be possible for me to maintain patches for mastodon and misskey if those projects won't upstream
@anemone like, just a patch for each system that is updated for every stable release.
I would like to get it in mitra too but one issue is miniapps don't work in tor browser it turns out because cross domain sharing is disabled
I would like to get it in mitra too but one issue is miniapps don't work in tor browser it turns out because cross domain sharing is disabled
@anemone this is an issue because silverpill uses tor browser lol so he wasn't able to experiment with them on egregoros to see if it was something he'd want.
@anemone another thing I'm gonna integrate later is, optional embedded crypto wallet, this one is a bit difficult but then crypto works on mobile, the selling point Im going for is, this can open up social media game monetization again
@sun@shitposter.world it wouldn't be too hard to integrate something like walletconnect right? asking about that one in particular because I like being able to just use my ledger without installing yet another extension
@anemone my current idea is, I add an option in your settings to turn on the embedded wallet, otherwise it just detects your injected wallet, wherever it comes from. for that, all that is really needed is Viem. walletconnect is too big, requires an api key and payment
@anemone I am not sure that works with ledger because ledger decided to do some app bullshit instead of just making an extension
Replies
3
@anemone for embedded I am looking at a small provider called www.jaw.id they seem competent. the wallet is stored in a passkey associated with your site. the miniapp sdk proxies wallet actions so you shouldn't have to attach for every miniapp
@sun@shitposter.world you can use ledger with extensions like metamask i just like not having to use an extension
@anemone i hate ledger so much right now but I can't switch because my passphrase is in a safe on the other side of the planet