2022-05-13 UTC
# aaronpk saying every web server should only serve .well-known from an admin writable folder is kind of silly, that's like saying every web server should make sure they are aware of every possible mechanism anyone might use and block access to those paths. which also kind of goes to show the problem with .well-known to begin with, that if a path there enables some sort of functionality then anyone who might be