Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • linearchaosEnglish
    arrow-up
    1
    arrow-down
    0
    ·
    10 months ago
    link
    fedilink

    Don’t worry, it’ll sort itself out when it becomes truly painful.