Home | Notifications | New Note | Local | Federated | Search | Logout
Note Detail
Reply to @sun@shitposter.world
ロミンありん@romin@shitposter.world (2026-08-15 21:26:31)
@sun I mean a miniapp using the token to freely interact with another miniapp
---Reply---
Blurry Moon@sun@shitposter.world (2026-08-15 21:42:17)
@romin there’s no mechanism to share the token passed to a miniapp to another miniapp unless both are controlled by the same author (or collusion)
I’m already working on submitting an enhancement to pleroma for an identity token that contains no private information incidentally and then making the miniapp standard very strongly press only public identity verification without extra click through.
Reply
---Replies---
ロミンありん@romin@shitposter.world (2026-08-15 21:46:45)
@sun the scenario is more like rogue miniapp operator has access to all other miniapps out there for a particular user he got a token from