Authorized Fetch (also referred to as Secure Mode in Mastodon) was recently circumvented by a stupidly easy solution: just sign your fetch requests with some other domain name.

    • froggers
      link
      fedilink
      English
      -89 months ago

      About as triggered as those who downvoted me.

      • @[email protected]
        link
        fedilink
        English
        89 months ago

        No, you’re right. Everyone who downvoted probably also went on an angry tirade first, but they just didn’t type it out. Totally the same. 👍