Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

  • sugarfreeEnglish
    arrow-up
    9
    arrow-down
    2
    ·
    10 months ago
    link
    fedilink

    A private forum may be useful in that case.

    • AdaEnglish
      arrow-up
      4
      arrow-down
      3
      ·
      10 months ago
      link
      fedilink

      Why even bother with that comment?