Home | Notifications | New Note | Local | Federated | Search | Logout
Note Detail
Reply to @romin@shitposter.world
Blurry Moon@sun@shitposter.world (2026-08-15 21:42:17)
@romin there’s no mechanism to share the token passed to a miniapp to another miniapp unless both are controlled by the same author (or collusion)
I’m already working on submitting an enhancement to pleroma for an identity token that contains no private information incidentally and then making the miniapp standard very strongly press only public identity verification without extra click through.
---Reply---
ロミンありん@romin@shitposter.world (2026-08-15 21:46:45)
@sun the scenario is more like rogue miniapp operator has access to all other miniapps out there for a particular user he got a token from
Reply
---Replies---
Blurry Moon@sun@shitposter.world (2026-08-15 21:50:07)
@romin let me go over the flow again to make sure that the handoff can’t be faked by a miniapp with an existing token. That is the only mechanism where that could happen.