@julian @silverpill we did not define this well in ActivityPub.
There's an implicit authorization model (creator can write the object, addressees can read and react) which will probably be more explicit in the next version, but we'd leave open other types of authorization.
I think it's likely in the future we'll have a property for defining additional access control options.
Same-origin is a good guess but it's not as good as explicit properties.
?