Home | Notifications | New Note | Local | Federated | Search | Logout

Note Detail


Reply to @silverpill@mitra.social
Blurry Moon@sun@shitposter.world (2026-08-12 22:06:34)
@silverpill can you tell me though, is it true that there's really only one scope with most permissions on mitra oauth? I am going to be submitting some patch requests to some projects for a much-reduced oauth scope for just identifying a remote ap user, not including things like email address or other private fields.

---Reply--- silverpill@silverpill@mitra.social (2026-08-12 22:22:32) @sun Mitra doesn't support scopes, but I can start adding them if needed.

I saw your FEP draft, by the way. Is it ready for review?
Reply

---Replies---
silverpill@silverpill@mitra.social (2026-08-15 05:28:03)
@sun So, I think the biggest problem with this proposal is that it requires a publicly accessible HTTP server. Is there a good reason for that?

WebXDC, for example, is designed for offline first apps. I am reading WebXDC docs right now and it seems to be compatible with ActivityPub. Maybe we should work on this instead?