Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

marius

@mariusor@metalhead.club
mastodon 4.7.3
  • Open on metalhead.club

Mostly a programmer.

Implementing #ActivityPub in the #Go programming language.

Current projects:

* #GoActivityPub - a library to use ActivityPub in Go.

* #FedBOX - a generic ActivityPub service supporting the client to server API.

* #brutalinks - a link aggregator inspired by (old) reddit, hacker news and lobste.rs built on top of FedBOX.

* #oni - a single user ActivityPub server with minimal fuss.

1017 Followers
880 Following
50 Posts
Joined November 20, 2018
alt:
https://marius.federated.id
Brutalinks:
https://brutalinks.tech/~marius
SourceHut:
https://sr.ht/~mariusor/
github:
https://github.com/mariusor/
Open post
marius @mariusor@metalhead.club
· 3w ago
The vocabulary part of #GoActivityPub is getting closer and closer to being able of generating and operating with custom #ActivityPub data types. :goose_hacker:https://go-activitypub.federated.id/lib/rfc/code-generation.html
go-activitypub.federated.id

The vocabulary/lexicon generation

7
6
3
0
Open post
marius @mariusor@metalhead.club
· 2w ago
Finally set up the plumbing for adding code coverage to the #FedBOX integration test containers. 💪 #ActivityPub #activitypubdev #fedidev
1
0
1
0
Open post
marius @mariusor@metalhead.club
· 3w ago
Replying to
@fentiger sure, I don't mean that. I'm thinking more about: send types other than Note, send more than 4 attachments, send mixed form attachments, support multiple attributedTo values, support multiple inReplyTo values, etc. Mastodon is bottom of the barrel for compatibility...
2
0
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
The community behind #jolla and #sailfishos making some videos trying to vie for the attention of the average user. https://www.youtube.com/watch?v=EdRT1MazTyA Actual review starts at about 5m.

Jolla Phone 2 & Sailfish OS: A Real Third Option

7
2
4
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
When I started the work on ActivityPub projects I fully embraced Maslow's Hammer adage. I wanted as much as possible in my services to go through the #ActivityPub vocabulary and I fully embraced the client to server API. But there are elements of a web application that require custom functionality no matter what, say changing a password. So for those I just added the capability of running commands through ssh. :goose_hacker:#ActivityPubDev #fedidev
5
5
3
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
I'm surprised at how many issues my new integration tests are finding. I already had an integration testsuite, but the way the #fedbox application was run was not in full isolation, and I expect some of the setup steps I had included don't really exist on a fresh install. We now build a fresh container image, start it up, provision it with mock data, and then run tests, but only through mechanisms that are available to a prospective server operator: CLI commands executed through SSH, and ActivityPub client to server operations. #fedidev #activityPubDev #activitypub
3
6
4
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to
@toddsundsted@epiktistes.com I got inspired by the Stegodon project, which uses some Go specific libraries that merge TUI libraries on top of an SSH server. What I did was to extract the CLI commands available to my server and allow execution through that interface.
2
3
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to

@julian for the implementors of Go ActivityPub applications that need RFC9421 signatures, it's important to note that it's not FedBOX that provides the functionality, but two modules in the GoActivityPub library:

  • the client module[1] wraps the signing of activities.
  • the auth module[2] wraps the verification functionality.

Also for lower level use, there's the underlying module being wrapped by GoActivityPub: dadrus/httpsig [3]

[1] https://github.com/go-ap/client [2] https://github.com/go-ap/auth [3] https://github.com/dadrus/httpsig

Fed@hongminhee@hollo.social

GitHub

GitHub - go-ap/client: A wrapper around regular http transfer package with some enhancements for using with ActivityPub services.

A wrapper around regular http transfer package with some enhancements for using with ActivityPub services. - go-ap/client

2
1
2
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
The work is done, huzzah!! 🥳 With the coverage increased to +85% and with a couple of pending improvements to the common-fate/httpsig library. Until those land, I'm using a forked version. The auth module has transformed during this work to only have logic related to extracting authorized actors from either OAuth2 and HTTP-Signature headers (both the widely used draft and the new RFC9421 version). This makes me confident that the convergence of the library's modules that I'm planning for v1 is actually a good idea.
5
3
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to
@toddsundsted@epiktistes.com eh... for an admin interface it has a better UX than having to ssh to a machine where the service is already running and deal with executing commands in a container or whatnot, but for actual end-users it's probably far from ideal.
1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@mczachurski@mastodon.social welcome to the fediverse, where we test in production like real red flannel wearing Canadian men. :)
4
0
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to
@silverpill@mitra.social are we allowing Mastodon guide ActivityPub development again, when alternatives exist? @grishka@mastodon.social
1
1
1
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
In my interactions with other go library maintainers I realized I have really strong opinions about how code should look like, and I have a really low patience threshold for explaining why that is. I guess I've been long enough out of the loop of developing in teams, that I'm no longer able to patiently explain why I prefer certain ways of doing things.
2
2
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@david_chisnall@infosec.exchange ah, I see, I missed that somehow, but it makes total sense.
2
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan@cosocial.ca I added a comment there describing a counter-proposal for the actual mechanism described in the SocialCG document, if alternatives are still under consideration. @reiver@mastodon.social apologies for piggybacking on your ticket. :D 🐽
2
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@climagic the code I already run can probably exploit my passwordless sudo way easier... just saying. Why I trust it to not do that is that I run that code from my distribution's repository not from a random website that someone on the internet told me it's fine... The thing I was trying to emphasize is that most users don't operate under a threat model where this vulnerability is as drastic as you imply and official mitigations should be timely enough. Propagating this kind of alarmist news without any caveats is basically journalistic malpraxis, though if you don't consider yourself as being one, then... sure.
2
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@stefan@stefanbohacek.online does it have the fortune quotes? https://www.shlomifish.org/open-source/projects/fortune-mod/
shlomifish.org

fortune-mod - display random text quotes on the command line - Shlomi Fish’s Homesite

fortune-mod - display random text quotes on the command line

1
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@silverpill@mitra.social when you get a chance, please send another request. While waiting for the upstream to solve the issue, I fixed on my end trying to validate missing nonces. @Marius@marius.federated.id @marius@federated.id
marius.federated.id
1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan@cosocial.ca yes. I don't look at it as "2 POSTs" though. I look at it as a "file upload" followed by an ActivityPub Create activity. If you're looking for one POST request, just have /outbox do the work instead of mediaUpload. @hongminhee@hollo.social
1
10
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@mkljczk@pl.fediverse.pl it does, it does: https://support.mozilla.org/en-US/kb/website-translation#w_how-do-i-enable-the-translation-panel @david_chisnall@infosec.exchange
support.mozilla.org

Client Challenge

1
14
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@silverpill@mitra.social also, what the hell is that Activity? A Like without an object... o.O
1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@budududuroiu@hachyderm.io my experience is to abstain from trying to be funny when using popular tags. :D It's cat-nip for people that lack reading comprehension...
1
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@tychi@merveilles.town also I submitted my proposal alongside Reiver's submission: https://github.com/w3c/activitypub/issues/578#issuecomment-4366469692 @hongminhee@hollo.social
GitHub

resumable uploads for ActivityPub · Issue #578 · w3c/activitypub

ActivityPub-based applications often allow users to upload audio, images, videos, and other file types, though most currently rely on non-ActivityPub APIs for this functionality. These files can be...

1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to on hollo.social

@hongminhee@hollo.social like I mentioned in a thread where Evan and Reiver were talking about this, I think having a mediaUpload that has a very similar behaviour to an inbox/outbox, but with one small details is a bad API.

I would prefer there's either a two step process: upload media first, use resulting token in an object create, or use the outbox with for the binary data upload directly... The first one seems saner to me.

1
38
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@kopper@not-brain.d.on-t.work now that I had to think about it for 10m, I really like the idea of getting back a templated object that can further be amended by the client and sent in a Create. *By templated I mean an "incomplete" object which has filled only the properties that make sense: ID, URL, MediaType, Type, AttributedTo,etc... @hongminhee@hollo.social
1
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@kopper@not-brain.d.on-t.work for me ActivityPub servers are just ActivityPub servers, there's no using that media outside ActivityPub. There is only one GOD. 🙏 @hongminhee@hollo.social
1
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@hongminhee@hollo.social I haven't reached that point in GoActivityPub development to really think about it. Currently for binary uploads I use world's hackiest hack™️, where I encode the media as a base64 media URI and set it as the Content of a Image/Audio/Video object that I send through client to server. :goose_hacker: So far this has worked well enough between the clients and servers *I* developed, but I can't really ask anyone else to support that.
1
5
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@kopper@not-brain.d.on-t.work token can be anything: an URL at which the media can now be found, the "template" json document Evan was talking about with the URL filled in, etc... Whatever would make the most sense I guess. @hongminhee@hollo.social
1
12
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@yourfutureex@metalhead.club whoa, very nice... makes me think of a harsher Nils Petter Molvær.
1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@gotosocial do you mean "slough"?
1
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@x2ero then you should probably update. :)
0
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@silverpill@mitra.social I'm not sure which instance you mean, these two actors are different. @marius@marius.federated.id@marius@federated.id The first one is on an instance that should have RFC9421 enabled, but the second isn't. I enabled request debug on it, if you want to try again.
0
1
0
0
Open post
marius @mariusor@metalhead.club
· 1mo ago
Replying to
The size is not as large as it might be for other services, because ONI does not cache media, the stored data is strictly the received JSON-LD payloads, with additional objects fetched in order to keep the storage consistent.
0
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to

it's incumbent on you to make the case for it.

@evan@cosocial.ca I was sure I managed to do that. :D

And so far, I don't think you provided me with any counter-factual arguments that I didn't address.

@hongminhee@hollo.social

0
5
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@david_chisnall@infosec.exchange to me both NMT and general purpose LLMs basically look like a duck and quack like a duck. Making a distinction between them seems needlessly persnickety, but I also agree that they don't qualify to the label of AI. (Unlike the majority of the people actively involved with the technology, who should know better.) @mkljczk@pl.fediverse.pl
0
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan that looks like a really unsanitary upload method to me. I always imagined that uploadMedia was used for keeping concerns separate between object creation and media upload. Having them both present in the same place would have made more sense to me directly in an inbox/outbox. @reiver
0
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@fentiger thanx, I'll check it out. This one had one large annoyance in the fact that they split all functionality in a thousand little packages...
0
1
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
  1. It doesn't include addressing,

As always it's the Clients that are responsible for addressing, therefore the second step should cover it, if the user/client chooses to perform it.

  1. What happens if the client doesn't post the Create activity?

Whatever the server desires: cleanup after a while, keeping the media, etc. Why do you think it's relevant for the specification itself?

ActivityPub, to my reading, is not about how to store content, but about how to distribute content. So after it was uploaded, it's no longer the concern of the spec, unless operated further through other ActivityPub requests.

@evan@cosocial.ca @hongminhee@hollo.social

0
13
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan@cosocial.ca I did on reiver's comment on github: https://github.com/w3c/activitypub/issues/578#issuecomment-4366469692 It's a compromise between the current SocialCG proposal, and what I said above. Do you think it warrants it's own ticket? @hongminhee@hollo.social
GitHub

resumable uploads for ActivityPub · Issue #578 · w3c/activitypub

ActivityPub-based applications often allow users to upload audio, images, videos, and other file types, though most currently rely on non-ActivityPub APIs for this functionality. These files can be...

0
15
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@fentiger the one you linked has a pretty decent API, switching between them might not be too difficult. 🙇
0
0
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@david_chisnall@infosec.exchange as far as I remember Firefox also bundles an LLM with the install (useful at least for in browser translations) but it still manages to keep the size reasonable...
0
20
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@freebliss@post.lurk.org the one bitter tasting pill I got from Drew's writing is that he's seemingly unable to accept that perhaps he interacted with people during their "asshole" phase of their lives and that others can change and grow too. Perhaps he needs them to write a mea-culpa blog post, who knows. I've seen him at the forefront of at least two vilification campaigns at least in the past couple of years... and that feels somewhat hypocritical...
0
2
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan@cosocial.ca if you want the simplest mechanism to upload media, why bother with multipart request bodies? Just do what I do in BOX->ONI, use a data URI for encoding the binary, either as Object.Content or Object.URL. Can you tell me what's the difference between a request containing JSON with a data URI property and a multipart request body? As far as I can tell the binary data is in both cases base64 encoded, so you're not saving on size, it can be malformed for both cases (but for multipart you now you need an extra check to not save the JSON-LD object if the bin-data is broken), etc... (this suggestion is not entirely serious, but...) etc...@hongminhee@hollo.social
0
9
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@evan@cosocial.ca to clarify for 1): before the Create is performed, and the media object gets created on the server, the binary data itself is not accessible/referenceable. @hongminhee@hollo.social
0
12
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to
@grishka@mastodon.social yeah, ed25519 for some of my actors supported by GoActivityPub. (Well, it could be anything that the Go crypto library supports, but only ed25519 is in some use)
0
22
0
0
Open post
marius @mariusor@metalhead.club
· 5mo ago
Replying to
@climagic I'm not just going to apply patches from a random web-site generated with AI... why would you even suggest that in earnest?
0
1
0
0
Open post
marius @mariusor@metalhead.club
· 2mo ago
Replying to
@toddsundsted@epiktistes.com as a user you login with your ActivityPub actor ID as a user, and your pw (if you have one) or your actor's private key (which you obtained somehow, it's not clear yet how that's going to work in real scenarios). In interactive mode you get a TUI to see your actor and its collections, and non-interactively you can execute the said commands.
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:42:53 UTC