kibicat / mastodon

A Mastodon‐compatible fediverse instance (the one used by https://glitch.cat.family).
GNU Affero General Public License v3.0
3 stars 0 forks source link

Allow user‐level (and/or post‐level?) opting out of (parts of) AUTHORIZED_FETCH #10

Open marrus-sh opened 2 years ago

marrus-sh commented 2 years ago

A bit contrary to #8, but also helps justify it. There are good reasons not to want AUTHORIZED_FETCH:

The main utility of preventingenforcing AUTHORIZED_FETCH is:

Users should be able to decide for themselves what their priorities are in this regard. Under no circumstances should timelines, follower/following information, &cetera be made available without AUTHORIZED_FETCH.

single-right-quote commented 2 years ago

i’m confused: how does preventing AUTHORIZED_FETCH enable the latter two bullet points? i thought those were things AUTHORIZED_FETCH enforces

marrus-sh commented 2 years ago

pardon, i meant enforcing AUTHORIZED_FETCH; preventing unauthorized access