I'm going to start doing some user research for #ActivityBot. I'd like to pay participants £20 / €20 for an hour of their time.
This has to be a voucher (no cash or cash-like cards) so which would you prefer?
Discussion
I'm going to start doing some user research for #ActivityBot. I'd like to pay participants £20 / €20 for an hour of their time.
This has to be a voucher (no cash or cash-like cards) so which would you prefer?
Woo! It's now official 😊
I'm getting some grant funding to further develop #ActivityBot.
If you have any feature requests or suggestions - or just want to build your own ActivityPub bot - check out https://gitlab.com/edent/activity-bot
I'm going to try and keep a record of all the bugs, errors, and inconsistencies I've reported in #ActivityPub and #Mastodon documentation.
First up, how big are the limits on what you can federate?
Mastodon lists some limits in KB/MB, but others are just raw numbers. That might make sense for an ASCII world - but emoji complicate everything.
Next is slightly more trivial - a broken internal link in the Mastodon documentation.
I think the #RFC9421 HTTP Signature algorithm should be explicitly included in #Mastodon's requests.
Feedback welcome - especially those explaining politely why I'm a wrong about this.
https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919
Hey, #Mastodon and #ActivityPub developers.
How much skew do you allow before rejecting a message?
I've just received something where the header is signed:
Mon, 31 Aug 2026 20:09:54 GMT
But the ActivityPub message was published:
Mon, 31 Aug 2026 19:58:36 GMT
That's a little over 10 minutes. Is that too much? Should I not care as long as the signature validates?
A weird #ActivityPub message from #Frendica.
Signed on 2026-09-01
Published on 2026-03-02
That's a skew of six months! The message type is "Undo" - so they're undoing a like they sent in March.
Is there *really* a worry about accepting requests like this? Given the message has been signed, what risk is there to replay attacks?
Bug report at https://github.com/friendica/friendica/issues/16150
Another Mastodon / ActivityPub signature question.
Alice reposts Bob.
Bob updates their post.
Alice's instance syndicates that update to her followers.
The message Alice's instance sends has an Actor of Bob. But the headers are signed by Alice. So the signature doesn't match the actor.
Which means Bob's embedded RsaSignature2017 *also* needs to be checked.
https://docs.joinmastodon.org/spec/security/#ld-sign
But that doesn't mean I can skip checking Alice's signature, right?
The documentation says:
> Strip type, id, and signatureValue from the signature, leaving only signature[creator] and signature[created].
> Base64-decode the signatureValue and verify it against the public key in signature[creator].
But it doesn't say *what* to validate the signature against!
Is it a JSON document just containing creator and created? Or is it something else?
@Edent oh.... it's against some wild RDF thingy that you obtain by putting the JSON document through some JSON-LD processing algorithms. My memory is fuzzy because I implemented that from scratch way back in 2019, but here's my known working implementation if that helps:
https://github.com/grishka/Smithereen/blob/master/src/main/java/smithereen/jsonld/LinkedDataSignatures.java
@Edent Well deserved! That thing was really useful to me while figuring out how ActivityPub all fits together. Nice one.
@Edent Yah. Congratulations
@Edent i guess i can find the MoU somewhere in nlnet ... is the reasoning attached?
@Edent congrats, that's awesome! 🎉
@Edent I voted books, but https://uk.bookshop.org/gift_cards rather than Kobo perhaps?
@Edent I voted books, but https://uk.bookshop.org/gift_cards rather than Kobo perhaps?
@Edent the Office for National Statistics, when they do surveys, give you one of these vouchers -- https://www.pluxee.uk/products/evouchers/ -- which the recipient can then choose from a bunch of different stores and restaurants and such. I turned mine into an M&S one one time and had a lovely dinner :)
No idea whether you have to buy 10,000 at a time or something, mind, or whether it'd work for you, but I found it useful, and the ONS presumably (hopefully?) did at least some due diligence on them being OK :)
@Edent Amazon voucher might have the widest appeal, unless you prefer not to support that company
@Edent een kadobon, maar let op geldigheidsduur: https://blog.gifty.nl/cadeaubonnen-wat-je-moet-weten-over-geldigheid-en-vervaldatum/
@wiert I don't really understand what you're trying to say, sorry. It is up to a recipient if they don't want to spend it in time.
@Edent sorry, thought you were Dutch. People are bad at remembering expiry dates, especially when they are years in the future. Luckily, there are still a few Dutch gift cards that don't expire.