Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • rglullis@communick.news
    link
    fedilink
    English
    arrow-up
    1
    ·
    8 months ago

    Right. Publicly available does not mean in public domain. But the issue here is not of copyright, but merely of gated access.