#dev 2021-09-30

2021-09-30 UTC
capjamesg[d]: At HWC, petermolnar mentioned the opensearch description format. Are you familiar?
but praise aaronpk for that, I copied most of his stuff
plus `<link rel="search" type="application/opensearchdescription+xml" href="/opensearch.xml <view-source:https://petermolnar.net/opensearch.xml>" title="petermolnar.net">` in the html meta
oh, right: GWG, in theory, adding &json to my search, like https://petermolnar.net/search.php?qsub=search&q=indieweb&json results in a wordpress-compatible json blob.
petermolnar: I am giving you credit for reminding me that existed.
I forgot about it
But I thought it would interest capjamesg[d]
Thanks GWG! It is indeed. A few people suggested I add OpenSearch to the IndieWeb engine so I did. But I sort of wish there was more documentation around it.
petermolnar I am experimenting with JSON results for IndieWeb search too: https://indieweb-search.jamesg.blog/results?query=Hidden+gem&serp_as_json=results_page
I haven’t decided whether to include full HTML yet.
If I did it would basically give anyone the ability to build cool extensions which I think is nice.
Does JSON Feed have a Python parser? https://www.jsonfeed.org/code/
Silly question. Ignore that πŸ™‚
2 down 1 to go
home page is back
last machine... i don't see the X3 cert on it but it's still failing
↩️ I'd love if Mastodon had more active support for #IndieWeb protocols. Supporting IndieAuth as a login server, for example, and TicketAuth to allow friends-only content feeds. Also h-feed or better Atom support.
This X1 to X3 change seems to have caught a lot of the Internet by surprise. I'm lucky that all that broke for me was the cert chain on my dovecot server (which was because I was accidentally using `cert.pem` instead of `fullchain.pem`).
Which, incidentally, seems to be the correct fix for a lot of servers, just making sure you're using the full chain instead of the single cert.
and also doing a forced renewal if necessary
my problem is on the client side not the server side
If an IndieAuth client for something needing high security required the Authorization Endpoint Link to be in the header rather than HTML, would it still be considered an IndieAuth client? How about if a <link> was in the head? Maybe show a warning instead? HTML is more often user editable than headers
Such a mess though 😞
i don't understand, the X3 cert is *not* on this machine anymore but curl is still failing
removing it worked on 2 of the other machines
also weird, wget works on this machine that curl is failing on
i'm giving up on it, i think things are working again even tho command line curl doesn't
like, security is only as good as it is usable & maintainable
seems like one of those odd security vs. reliability compromises
It’s just a shame that in the cases of aged certificates you never know what could go down.
I read about an expired certificate that impacted businesses like Stripe earlier this year.
Can etag HTTP headers be used to check if content is the same on more than just RSS feeds?
different failure modes. they can overlap, but neither is a superset of the other. eg for some people, down/broken is preferable to compromised
regardless, agreed! like any feature, security adds complexity, maintenance burden, etc. we can have both security and maintainability, it just takes work
(not a great framing, security isn't really a feature, but no matter)
tantek++ for consistently raising awareness that security and privacy aren't free and have costs!
rather, my point is more of a behavioral one, that unmaintainable security is in practice no security at all, because users care more about things mostly working and somewhat secure than about having things barely/rarely working and very secure
common users that is. obv there are large sets of users that very much want failure instead of security compromise
ah, sure!
SMS is a good example of this
both points are good, security has to be usable/maintainable, and it's a spectrum, adding _some_ security (for some cost) can be worthwhile even if it's imperfect
totally. big believer in defense in depth πŸ™‚
(aside, no karma while Loqi subject to aforementioned breakage in functionality due to no fault to Loqi in particular)
on another topic, FYI [KevinMarks] KartikPrabhu [chrisaldrich] and anyone else into "annotations" https://groups.google.com/a/mozilla.org/g/dev-platform/c/NXvLZHeIqQw/m/PbGve3rRAwAJ (note my reply in thread directing folks here πŸ™‚ )
[fluffy]: Re ticket Auth...are we ready to start recommending it?
Wow this is some table (Hypothes.is Historical Survey of Annotation Efforts) : https://docs.google.com/spreadsheets/d/1f86L7vgHUW9wSLNNSunhjmtxtg6KlCOVpHGKbqUzW-Y/edit#gid=0
That deserves to be Wikipediafied
Lemmy, an open-source, federated link aggregator recently [added Webmention support](https://github.com/LemmyNet/lemmy/issues/1395). I thought that was pretty neat
[chrysn] #1395 Send webmentions
