Skip to content

Welcome to ActivityPub.Space 👋

This is a forum dedicated to fostering the ActivityPub development community and providing a space for archival of discussions related to ActivityPub.

This forum is fully federated, so you are able to contribute to any discussion here through your own software of choice (e.g. Mastodon, Misskey, Lemmy, Piefed, etc.)

  • General non-specific discussion about ActivityPub-related topics.

    2k 13k
    2k Topics
    13k Posts
    River 🏳️‍⚧️🐾 Develops ParleyR
    @evan thank you!
  • Technical discussion about ActivityPub-related topics.

    533 5k
    533 Topics
    5k Posts
    Sebastian LasseS
    @hongminhee Well, after the issues with the given ActivityPub "OAuth example", I looked up @fedify /vocab … In all the actor types like https://github.com/fedify-dev/fedify/blob/main/packages/vocab/src/person.yamlthe following properties would be missing [if the official OAuth demo should work] : grant_types_supported: ['authorization_code'],response_types_supported: ['code', 'code token'], code_challenge_methods_supported: ['S256'], token_endpoint_auth_methods_supported: [ 'client_secret_basic'// optional/*, 'private_key_jwt'*/], token_endpoint_auth_signing_alg_values_supported: ['RS256', 'ES256'], client_id_metadata_document_supported: true, optionalscopes_supported and ui_locales_supported:---anyway:I believe it is just misleading because of the order of querying the server and the actor description.I would expect it to meet the spec and pull above properties from the server wide .well-known oauth and just the endpoints from the Actor …#ActivityPub #OAuth
  • Topics about installing, maintaining, moderating a fediverse instance, and more.

    324 2k
    324 Topics
    2k Posts
    Gareth HarmerG
    @Tempest Oh, that's surprisingly nice!
  • SWICG Task Forces

    Some SWICG Task Forces host discussions and answer questions here.

    16 40
    16 Topics
    40 Posts
    benpateB
    I may be missing something, so please correct me: I think we already have authenticated messages and message repudiation. When you decrypt an MLS message, it could only have been encrypted by someone with the group key, and the MLS structure tells us specifically WHICH group member sent the message. However, this proof doesn't extend past your own device. You can't really export that cryptographic state out of your own machine because MLS has already thrown away the keys that bootstrapped that state to begin with. This is the issue facing the trust and safety folks who want to require some sort of message reporting system in E2EE messages. Screenshots aren't enough. So, they're looking at some kind of message hashing feature that could prove the contents of a message. It seems like we have a case of mutually-exclusive requirements. We can't build both message repudiation AND message reporting in the same conversation. It's likely that any solution will need to be build as some kind of extension mechanism, where group originators choose the specific features within that group.
  • Conferences & Meetups

    Topics about ActivityPub and Fediverse-related conferences and meetups.

    Unconferences too!

    3k 6k
    3k Topics
    6k Posts
    dansupD
    Night. #fedicon
  • Any non-ActivityPub discussion goes here.

    96 2k
    96 Topics
    2k Posts
    GrapheneOSG
    @ReclaimedComputing The plan is for the initial supported device will be the successor to the Motorola Signature (2026). It will be more time before we can add more devices since we need the devices to add support for MTE, secure element features and long term updates. Other flagships are likely going to be the first ones supported. We can work our way down from there once other devices meet our requirements.We'd still like to keep supporting new Pixels too so we have 2 choices instead of 1.
  • Not that Meta, but meta-discussions about this site, its contents, moderation concerns, governance, etc. all go here.

    22 167
    22 Topics
    167 Posts
    L
    I didn't receive it.
  • News

    Federated blogs and news outlets covering ActivityPub.

    115 441
    115 Topics
    441 Posts
    MaddyM
    @weekinfediverse wow we're tracking shoot now, that's awesome
  • Podcasts and Videos

    Podcast recordings and videos about ActivityPub.

    74 99
    74 Topics
    99 Posts
    O
    @phillycodehound@indieweb.social thank you! Love talking with everyone
  • Developer Announcements/Logs

    Federated blogs and official accounts from ActivityPub developers

    33 467
    33 Topics
    467 Posts
    6@possum.city6
    @MastodonEngineering@mastodon.social @shlee@aus.social @MOULE@mastodon.moule.world *​:boo:​-reacts mastodon anyway*
  • Related Communities

    ActivityPub-related communities outside of this forum (Lemmy, PieFed, etc.)

    828 20k
    828 Topics
    20k Posts
    rain_enjoyer@sopuli.xyzR
    There are so many dead instances. Some of them are federated widely, then got abandoned, domain expired and got taken by something like online casino. That would be useful entrypoint for evildoers, maybe allowlists should be linted from time to time