akkoma/test
Oneric 9d1e169472 webfinger/finger: allow WebFinger endpoint delegation with FEP-2c59
The ban on redirects was based on a misreading of FEP-2c59’s
requirements. It is only meant to forbid addresses other than
the canonical ActivityPub ID being advertised as such in the
returned WebFinger data.
This does not meaningfully lessen security and verification still
remains stricter than without FEP-2c59.

Notably this allows Mastodon with its backwards WebFinger redirect
(redirecting from the canonical WebFinger domain to the AP domain)
to adopt FEP-2c59 without causing issues or extra effort to existing
deplyoments which already adopted the Mastodon-recommended setup.
2026-03-13 00:00:00 +00:00
..
config remove default emoji file 2022-08-11 19:05:41 +01:00
credo/check/consistency giant massive dep upgrade and dialyxir-found error emporium (#371) 2022-12-14 12:38:48 +00:00
fixtures add some more webfinger tests 2026-03-12 00:00:00 +00:00
instance_static URL encode remote emoji pack names (#362) 2023-01-15 18:14:04 +00:00
mix frontend: print warning for third-party frontends 2025-11-23 00:00:00 +00:00
pleroma webfinger/finger: allow WebFinger endpoint delegation with FEP-2c59 2026-03-13 00:00:00 +00:00
support webfinger/finger: normalise mention resources to more common format 2026-03-12 00:00:00 +00:00
test_helper.exs test: raise default assert_receive timeout 2025-11-23 00:00:00 +00:00