Mastodon Instance with 6 Files
justingarrison.com
justingarrison.com
It's definitely interesting to read how ActivityPub actually operates, but conflating the two may give the wrong idea.
(Even if it weren't that easy, I'd still agree that referring to it as a "Mastodon instance" is both wrong and weird, regardless of how popular and relatable Mastodon is.)
But it's clickbait that worked, so maybe discussing that is equally pointless.
> Those 6 files is all you need to create a Mastodon user. Here are some caveats you may have already noticed.
> - Following doesn’t work
> - Posts don’t work
> - Only 1 user per domain
The post might be technically interesting, but I find the title misleading.
Admittedly I've never looked at AP or Mastodon but query parameters on .well-known addresses is a terrible idea. Those resources should be static.
Anyway here's someone doing webfinger with a static file, in a way that works for serving for multiple users: https://gist.github.com/aaronpk/5846789
I’m not sure if you could implement something similar with s3
Sorry, but this is a form of equivocation[1] at best. More honestly, it's a simple contradiction; at the point where you're "map[ping] these URIs, params and all, to static files", you are being forced into running such an application.
Although it's not a rigorous, well-defined term, it's widely understood what a "static" site is. It's the sort of thing you get with e.g. Neocities or GitHub Pages or one of its clones—where you cannot rely on being able to mess with the server configuration (past the point of specifying the hostname your site should respond to, if even that). Any more involved configuration moves it out of this realm and towards the dynamic systems that many people are not running and not interested in running—for various reasons, including pricing, maintenance, and sheer complexity/brittleness. A static site is a place where you dump a directory of files and the host doesn't do much beyond serving that file with the appropriate media type when someone requests it, which is pretty much the only thing that people can trust to work reliably if and when they move all their crud to another host and/or server configuration someday.
(EDIT: Actually given it does a full regex match it might work; though it'll return supersets of the intended results if rel= constraints are preset, and possibly break if the rel= argument is put after the "resource=" in the URL so would need refinement; of course it depends on using a server which allows arbitrary regex based rewrites, which rules out a lot of object storage etc.)
It may happen to work for some clients some of the time, until it suddenly doesn't.
E.g. here's a suggested change to webfinger that wouldn't made this purely optional:
* Change the basic URL format to /.well-known/webfinger/<acct>
* Still allow the "rel" parameter, but allow the server to ignore it and return the full set of resources.
Now all you lose is the ability to do filtering with "rel=", and the "failure mode" is simply that you get the whole static file returned if it's not supported.
> well-known URIs are not intended for general information retrieval or establishment of large URI namespaces on the Web.
The WebFinger RFC appears to stuff its entire protocol into .well-known! And it includes some fine examples such as:
GET /.well-known/webfinger?
resource=acct%3Abob%40example.com&
rel=http%3A%2F%2Fwebfinger.example%2Frel%2Fprofile-page&
rel=http%3A%2F%2Fwebfinger.example%2Frel%2Fbusinesscard HTTP/1.1
Host: example.com
I would say that .well-known should be kept simple for both security and correctness. Dynamic content can be exploited more easily, as directly evidenced by you bringing CGI into the discussion. Additionally, .well-known is a global namespace and should not be a broad query interface when those queries can be reasonably furnished by other means.My experience with .well-known is that it's more or less an application level DNS and identity service. But this looks like those hacks where you can read Wikipedia using `dig`.
I've been failing to find a simple example server other than maybe Darius Kazemi's https://github.com/dariusk/express-activitypub
This little static file experiment is a great teaching tool. To folks complaining about conflating ActivityPub with Mastodon, part of his goal here is to do the minimum ActivityPub implementation so that his account looks a certain way on Mastodon. Other ActivityPub instances might be asking for different requests; he's doing the Mastodon minimum.
I plan to implant the active parts of the spec in future posts