Sign in

julian

@julian.activitypub.space.ap.brid.gy
13 followers 5 following 564 posts

Co-Founder (NodeBB) | Husband 🤷‍♂️ and Dad 🙉 to three | Rock Climber 🧗‍♂️ | Foodie 🥙 | Conductor 🎵 | Saxophonist 🎷 ✅ Small teams craft better code […] 🌉 bridged from ⁂ activitypub.space/user/julian, follow @ap.brid.gy to interact

PostsRepliesMedia
julian @julian.activitypub.space.ap.brid.gy · 17/06/2026
> Carney is heard saying "less than three per cent of our market, 49,000 cars," in apparent reference to how many vehicles are allowed to be imported in Canada at the lower rate. > > He makes a horizontal motion with his hand, signifying a limit, while saying there's "a cap, we capped, a hard […]
activitypub.space
Original post on activitypub.space
000
Reposted by julian
Robert W. Gehl @rwg.aoir.social.ap.brid.gy · 11/06/2026
My latest FOSS Academic post is a doozy. It's "Reading the Digital Safety Act with My Mastodon Admin Hat On": fossacademic.tech/2026/06/11/readin… I'm reading Canada's proposed Digital Safety Act. My conclusion is that the proposed regulations could be very […]
aoir.social
Original post on aoir.social
1213
julian @julian.activitypub.space.ap.brid.gy · 11/06/2026
Oh joy... can't wait for the prompt injection shenanigans we'll see _now_ , now that we've linked LLMs and the credit card network. globalnews.ca/news/11899818/visa-pa…
globalnews.ca
ChatGPT can now shop and pay on behalf of customers using their Visas - National | Globalnews.ca
Visa says the feature will include spending limits and mandatory approval procedures, and that the agent will only be permitted to use customers' cards at approved retailers.
000
julian @julian.activitypub.space.ap.brid.gy · 01/06/2026
I think it's absolutely wild that people are surprised when LLMs do surprising things when given shell access, and furthermore, that a common remediation is "update CLAUDE.md and tell it not to do that" It's such an ass backwards way of solving a problem. Like finding out someone broke in to […]
activitypub.space
Original post on activitypub.space
110
julian @julian.activitypub.space.ap.brid.gy · 28/05/2026
Hi @thisismissem, apologies if this has been asked previously. I noticed upon looking at the IFTAS blocklists that `#severity` is either `silence` or `suspend`. My feeling is that this aligns with Mastodon's usages, since they adopted the format Mastodon uses for shared blocklists. Has the T&S […]
activitypub.space
Federation Policies and limit/suspend/etc.?
Hi @thisismissem, apologies if this has been asked previously. I noticed upon looking at the IFTAS blocklists that `#severity` is either `silence` or `suspend`. My feeling is that this aligns with Mastodon's usages, since they adopted the format Mastodon uses for shared blocklists. Has the T&S TF put together a recommended list of levels for federation policies, and if so, do they align with what FIRES would also publish?[...] This doc article notes that the levels are Reject media, limit, suspend, and blocklist, with "silence" being the former name of "limit". Right now NodeBB does a binary "if you're on the list everything is blocked" approach, but I'm looking to add some granularity. Thanks!
500
julian @julian.activitypub.space.ap.brid.gy · 24/05/2026
> A good architect’s most important skill isn’t designing systems. It’s knowing which systems not to build. It’s pushing back on complexity. It’s asking “why?” five times until the actual requirement emerges from the aspirational nonsense. It’s telling the CTO that their conference-inspired idea […]
activitypub.space
Claude Is Not Your Architect. Stop Letting It Pretend.
> A good architect’s most important skill isn’t designing systems. It’s knowing which systems not to build. It’s pushing back on complexity. It’s asking “why?” five times until the actual requirement emerges from the aspirational nonsense. It’s telling the CTO that their conference-inspired idea is a terrible fit for the team they actually have. > > Claude will never do this. It’s trained to be helpful. Helpful means agreeable. Agreeable means you get an attaboy and a Jenga tower that passes for architecture. https://www.hollandtech.net/claude-is-not-your-architect/
111
julian @julian.activitypub.space.ap.brid.gy · 22/05/2026
This is the discussion thread for the draft FEP-baf5: Administrator Collection > This FEP introduces a mechanism for discovering the administrators of an ActivityPub instance. It extends the "Group Moderator" pattern from [FEP 1b12][1b12] and the "Application Actor" concept from [FEP […]
activitypub.space
FEP-baf5: Administrator Collection
This is the discussion thread for the draft FEP-baf5: Administrator Collection > This FEP introduces a mechanism for discovering the administrators of an ActivityPub instance. It extends the "Group Moderator" pattern from [FEP 1b12][1b12] and the "Application Actor" concept from [FEP 2677][2677] by defining an `OrderedCollection` of administrators referenced from the instance's application actor. The full draft can be read here.
412
julian @julian.activitypub.space.ap.brid.gy · 21/05/2026
Started working on bringing ActivityPub Polls to NodeBB :clipboard: First step is adding in separate handling of the `Question` object. Right now NodeBB treats it as a "Note-like" and renders it like a post :smile: 50% of the way there... will need to link it to `nodebb-plugin-poll`... One […]
activitypub.space
Original post on activitypub.space
112
julian @julian.activitypub.space.ap.brid.gy · 20/05/2026
I received a security vulnerability report regarding NodeBB's handling of `Update` and `Delete` activities. **tl;dr** * NodeBB implementes FEP fe34, and treats `Update` and `Delete` activities as valid if the activity's `actor` and the object's `attributedTo` differ **but the origins are […]
activitypub.space
Question re: Origin Based Security Model (FEP-fe34)
I received a security vulnerability report regarding NodeBB's handling of `Update` and `Delete` activities. **tl;dr** * NodeBB implementes FEP fe34, and treats `Update` and `Delete` activities as valid if the activity's `actor` and the object's `attributedTo` differ **but the origins are identical**. * e.g. `@alice@example.org` is allowed to federate `Delete(Note)` on `@bob@example.org`'s `Note`. * The origin-based security model allows for moderator-style actions (third-party post editing and deletions) in the absence of explicit moderator claims. * The reporter disagrees that this should be allowed. Are they right? [...] I responded that FEP fe34 allows for this behaviour because we do not have ready access to an instance's admin or moderator list. By conducting same-origin checks and allowing `Update` and `Delete` through for same-origin (but different identifier), we allow for moderators to federate their actions across instances. Their response: > I respectfully disagree that FEP-fe34 permits this behavior. Below are direct quotes from the specification that contradict your assessment. > > 1. ActivityPub spec (quoted in FEP-fe34 Rationale, Section 7.3 Update Activity): > > > ▎ "The receiving server MUST take care to be sure that the Update is authorized to modify its object. At minimum, this may be done by ensuring that the Update and its object are of same origin." > > Note: "at minimum" means same-origin is the floor, not the ceiling. Authorization must still be verified. > 2. FEP-fe34 — Authorization > Ownership: > > ▎ "The actor that creates an object MUST be its owner." > ▎ "The owner of an object is permitted to modify and delete it." > ▎ "Update and Delete activities, and objects indicated by their object property are expected to have the same owner." > > "Same owner" means the same specific actor — not any actor on the same domain. I responded back with the following: > > "The actor that creates an object MUST be its owner." > > > Correct, the creator must be an owner, no impersonation allowed. > > > "The owner of an object is permitted to modify and delete it." > > > A strict reading of this does not preclude the ability of a same-origin moderator to modify and delete the object. This is my argument. > > > "Update and Delete activities, and objects indicated by their object property are expected to have the same owner." > > > Again, "expected to" does not rise to the level of MUST. > > I agree out of principle that the security implications exist, but if you follow through with the exploit, it requires a non-compliant server to allow users to publish Update and Delete for other users on the same instance, and even then the exposure is limited to users of that origin only (e.g. your server cannot arbitrarily delete my posts). This is the foundation of the Origin-based security model. So we are at an impasse as to whether my strict reading of the FEP is adherent to the spirit of the FEP itself. Here's where you come in... do you agree with me, or the reporter? Directly tagging @silverpill@mitra.social (as FEP author), @trwnh@mastodon.social and @evan@cosocial.ca (both subject matter experts) for their thoughts.
703
julian @julian.activitypub.space.ap.brid.gy · 20/05/2026
Mm... it seems GitHub issues now comes with additional project management fields like **Priority** and **Effort**. When do we get **Story Points** , so I can play F/OSS Planning Poker? Just kidding, I'd rather gouge my eyes out. :anguished:
dbf8f99f-ab62-4ba2-bf97-ebe0989b727f-image.jpeg
010
julian @julian.activitypub.space.ap.brid.gy · 15/05/2026
About time! One down, twenty more to go (give or take 1000) xeiaso.net/notes/2026/amazonbot-res… @cadey@pony.social does this mean default bot policy will now let them through? Neat.
activitypub.space
Xeiaso blog: Amazonbot is finally respecting robots.txt
About time! One down, twenty more to go (give or take 1000) https://xeiaso.net/notes/2026/amazonbot-respecting-robots-txt/ @cadey@pony.social does this mean default bot policy will now let them through? Neat.
003
julian @julian.activitypub.space.ap.brid.gy · 14/05/2026
Hi @benpate@mastodon.social I've got a question about Activity Intents! I'm implementing it now (as you noticed) and have run into an interesting issue. The wording of 3b86 _suggests_ that the intents are distinct between users. That is, the end user inputs their **handle** , the **handle** is […]
activitypub.space
Multiple handles for Activity Intents
Hi @benpate@mastodon.social I've got a question about Activity Intents! I'm implementing it now (as you noticed) and have run into an interesting issue. The wording of 3b86 _suggests_ that the intents are distinct between users. That is, the end user inputs their **handle** , the **handle** is queried via webfinger, and supported Intents are returned. However, the intents themselves don't really distinguish between users.[...] So I could have a `localStorage` session with multiple handles registered (e.g. `julian@activitypub.space`, `nodebb@fosstodon.org`), etc. — this works fine. But if I had two handles _with the same domain_ , `alice@example.social` and `bob@example.social`, then my intents can't be targeted, can they... I just fire off the request (or rather, I have the end user's browser navigate) to the intent URL and whatever account is logged in will be the actor. Did I miss something, or was there a way to distinguish actors in Activity Intents? P.S. I find it highly amusing that you had to click through to activitypub.space to read my whole post, but because I don't support Activity Intents yet, you can't reply properly :rolling_on_the_floor_laughing:
023
julian @julian.activitypub.space.ap.brid.gy · 13/05/2026
@chocobozzz@framapiaf.org I have a question for you... I'm seeing in Are we HS2019 yet? that Peertube and Misskey both use your package: @peertube/http-signature NodeBB currently rolls its own cavage-12 support but and I did some preliminary research into updating to the latest HTTP Signatures […]
activitypub.space
Re: @peertube/http-signature
@chocobozzz@framapiaf.org I have a question for you... I'm seeing in Are we HS2019 yet? that Peertube and Misskey both use your package: @peertube/http-signature NodeBB currently rolls its own cavage-12 support but and I did some preliminary research into updating to the latest HTTP Signatures draft, but quickly got overwhelmed. For a variety of reasons, but mainly to avoid NIH, I'd consider switching to a dependency. My question is: does your library support verification for non-hs2019 signatures, or will I need to invoke your library in front, and fall back to existing cavage-12 verification otherwise? I suppose, same question re: double-knocking.
000
julian @julian.activitypub.space.ap.brid.gy · 08/05/2026
Ran across this gem from HN about AI. I'll let it speak for itself: > We've got a QA agent that needs to run through, say, 200 markdown files of requirements in a browser session... For the longest time we tried everything to get a prompt like the following working: "Look in this directory at […]
activitypub.space
Original post on activitypub.space
313
julian @julian.activitypub.space.ap.brid.gy · 30/04/2026
Unfortunately I was only able to join for the third and last day of FediForum, but the energy was quite strong even then! There were some interesting discussions with @ozoned@btfree.social @reiver@mastodon.social and others (@johannab@cosocial.ca, @j12t@j12t.social, etc) about fediverse […]
activitypub.space
Combining groups and payments into a fedi-forward service for content creators
Unfortunately I was only able to join for the third and last day of FediForum, but the energy was quite strong even then! There were some interesting discussions with @ozoned@btfree.social @reiver@mastodon.social and others (@johannab@cosocial.ca, @j12t@j12t.social, etc) about fediverse payments and growing the open social web — this spanned two session slots, actually! One thing that came out strongly was the need for content creators to get paid. This _directly_ echoes @paige@masto.canadiancivil.com's talk from @fedimtl earlier this year. The other half was reflecting on the lack of appropriate value-adds for donators, such as **private groups**. We have all of these things, but separately. Perhaps combining them into an easy-to-use service is the secret sauce that will open up the fediverse to content creators. There is work with the Interledger Foundation (@jeremiah@alpaca.gold) to make the financial side happen. There's ongoing work with CrowdBucks (@reiver@mastodon.social) to connect fediverse accounts with payment gateways. On the threadiverse side, each of us (NodeBB, Lemmy, Piefed) have support for private groups, but not federated private groups. This might be an opportunity for the threadiverse implementors to work together (especially with @mayel@bonfire.cafe and the rest of the SWICG Groups Task Force (@groups)) to bring federate private groups out of the realm of theoretical possibility and into reality.
012
julian @julian.activitypub.space.ap.brid.gy · 30/04/2026
Trying Pulp Fiction coffee house in Kelowna 🙂☕
177757741153862662419424603438.jpg
000
julian @julian.activitypub.space.ap.brid.gy · 24/04/2026
I'll be on a mini-break to Kelowna, BC for the week, so will be back in the swing of things only on the last day of the conference! @j12t@j12t.social one of these days I'll do another demo. @johannab@cosocial.ca say hello to my doppelgänger for me :laughing:
activitypub.space
Sadly will have to miss FediForum this time around!
I'll be on a mini-break to Kelowna, BC for the week, so will be back in the swing of things only on the last day of the conference! @j12t@j12t.social one of these days I'll do another demo. @johannab@cosocial.ca say hello to my doppelgänger for me :laughing:
200
julian @julian.activitypub.space.ap.brid.gy · 22/04/2026
Hey @panos@catodon.rocks, now that I'm tracking errors encountered, I've got a bit more visibility into things that normally would've just been caught and ignored. Today I received a `Delete(Object)` from Catodon associated with a user from `catodon.rocks`. Two things: 1. Its `object` […]
activitypub.space
Catodon federating deletes of objects it doesn't own
Hey @panos@catodon.rocks, now that I'm tracking errors encountered, I've got a bit more visibility into things that normally would've just been caught and ignored. Today I received a `Delete(Object)` from Catodon associated with a user from `catodon.rocks`. Two things: 1. Its `object` referenced an item outside of `catodon.rocks`, and so it failed NodeBB's actor-object match check. Normally people can't delete other peoples' posts, so I think this might be a mistake? 2. The activity's `audience` matches the activity's `attributedTo`. While you're certainly allowed to put anything you want in there, threadiverse software uses it to point to a group actor. Wondering if this was intentional. Thanks!
102
Reposted by julian
Evan Prodromou @evanprodromou.socialwebfoundation.org.ap.brid.gy · 06/04/2026
The call for proposals is open for the COSCUP Fediverse track in Taipei, Taiwan. ActivityPub-related software, including server and client implementations, are great topics for the event. COSCUP ("Conference for Open Source Coders, Users, and Promoters") is the FOSDEM of East Asia. Run by the […]
socialwebfoundation.org
Fediverse Track at COSCUP: Call for Proposals
The call for proposals is open for the COSCUP Fediverse track in Taipei, Taiwan. ActivityPub-related software, including server and client implementations, are great topics for the event. COSCUP (“Conference for Open Source Coders, Users, and Promoters”) is the FOSDEM of East Asia. Run by the Open Source community in Taiwan, it brings together people excited about FOSS across the region. For the first time, this year, members of the Korean ActivityPub developer community FediDev KR are joining up with FediLUG of Japan to program and run a Fediverse track at COSCUP. This has the potential to be a huge step forward for the Fediverse developer community. Although many major projects, like Fedify and Misskey, are created and promoted in East Asia, distance and language barriers make it hard for East Asian devs to participate in European and North American in-person events. The Fediverse track is open to proposals about ActivityPub implementations, clients for ActivityPub platforms, ancillary services, libraries and toolkits. But also, as at FOSDEM, talks about the human aspects of Fediverse technology, like moderation, policy and governance, are welcome and encouraged. This event looks like it will cover as much interesting conceptual space as its twin at FOSDEM. Hong Minhee, hongminhee@hollo.social, was one of the main speakers at FOSDEM’s Social Web devroom this year. Their talk about Fedify was important, but even more important was their effort to bridge the gap between Asia’s and Europe’s Fediverse development communities. I (Evan) hope that COSCUP brings together many Asian developers, but I also hope that North American and European individuals and teams put in proposals as well. Knitting together these two important communities on the Fediverse requires effort from both sides. That’s why I’m applying to speak (about ActivityPub 1.1), and why I hope to see many familiar faces among the new ones in Taiwan.
025
julian @julian.activitypub.space.ap.brid.gy · 04/04/2026
So now that I am now effectively priced out of upgrading my hardware... Hopefully we'll see some additional attention turned towards software optimization. I remember the day maybe a decade(?) or so ago, when Linux seemingly overnight improved their boot system to the point that a cold boot to […]
activitypub.space
So now that I am now effectively priced out of upgrading my hardware... Hopefully we'll see some additional attention turned towards software optimization. I remember the day maybe a decade(?) or so ago, when Linux seemingly overnight improved their boot system to the point that a cold boot to desktop took something like 10 seconds, compared to Windows' 2+ minutes. Hopefully we'll see some crazy improvements like that soon, now that we can't just throw more money at faster consumer hardware.[...] My HTPC is old, I think it has one of the first AMD Ryzen CPUs. It runs decently well on Ubuntu, but it's sounding like I'm going to have to be reliant on this PC for another 5-10 years. P.S. when I built that PC I remember saying 2GB ought to be enough for anybody 😂😂
300
julian @julian.activitypub.space.ap.brid.gy · 03/04/2026
Just realized I'm going to have to add "hand-crafted" to the list of adjectives to describe my code. Didn't think that needed to be said, yet here we are.
032
julian @julian.activitypub.space.ap.brid.gy · 02/04/2026
Just testing a post from NodeBB to FediBook 😊
000
julian @julian.activitypub.space.ap.brid.gy · 28/03/2026
Fill out the survey here: www.surveymonkey.ca/r/F9WBTLZ
001
julian @julian.activitypub.space.ap.brid.gy · 27/03/2026
Successfully rewired a broken fluorescent light fixture to accept LED tubes, with the assistance of AI. I look forward to this future of DI-Why where I eventually electrocute myself.
000
julian @julian.activitypub.space.ap.brid.gy · 26/03/2026
Hi @peertube@framapiaf.org I am looking to debug some potential federation issues between NodeBB and Peertube and I am wondering if there is a test server I can federate against. Thanks!
011
julian @julian.activitypub.space.ap.brid.gy · 24/03/2026
Friend came to me to ask why their phone was full of ads. They'd show any time she opened an app, even legit ones. Turns out a solitaire app she downloaded also installed a new launcher, and that launcher was just serving up ads all the time. Crazy how much a third party launcher can do. As a […]
activitypub.space
Original post on activitypub.space
000
julian @julian.activitypub.space.ap.brid.gy · 17/03/2026
TFW when this is what you've been working on for the past decade :crying_cat_face:
3181bf73-6736-4ccd-be0b-326d2cf7390a-image.jpeg
211
julian @julian.activitypub.space.ap.brid.gy · 17/03/2026
This article really resonated with me. www.better-simple.com/django/2026/0… Especially this part: > If you do not understand the ticket, if you do not understand the solution, or if you do not understand the feedback on your PR, then your use of LLM […]
activitypub.space
Give Django your time and money, not your tokens
This article really resonated with me. https://www.better-simple.com/django/2026/03/16/give-django-your-time-and-money/ Especially this part: > If you do not understand the ticket, if you do not understand the solution, or if you do not understand the feedback on your PR, then your use of LLM is hurting Django as a whole. > > Django contributors want to help others, they want to cultivate community, and they want to help you become a regular contributor. Before LLMs, this was easier to sense because you were limited to communicating what you understood. With LLMs, it’s much easier to communicate a sense of understanding to the reviewer, but _the reviewer doesn’t know if you actually understood it_. > > In this way, an LLM is a facade of yourself. It helps you project understanding, contemplation, and growth, but it removes the transparency and vulnerability of being a human. > > _For a reviewer, it’s demoralizing to communicate with a facade of a human._ Emphasis mine. It puts into words exactly how I feel about the latest spate of AI generated content, and why I push so hard (sometimes offensively so) for the human behind the PR/work to be revealed.[...] Part of it is standing up and owning the work produced, even if it was produced wholly or in part by AI, and part of it is ensuring that that peer that I want to talk to is actually capable of understanding the problem and solution. Most fixes, every feature, and every PR adds maintenance burden to a project maintainer. If someone sends me a drive-by PR authored by AI, I have no idea whether the submitter intends to stick around.
001
julian @julian.activitypub.space.ap.brid.gy · 16/03/2026
I was talking to my marketing guy about integrating a tags-based onboarding workflow for freshly installed forums. The gist of it is, the forum admin adds a couple tags for the forum to globally follow, and achieves this via fedibuzz relay or tags.pub. Auto-categorization rules are […]
activitypub.space
Native discovery of related tags (fedibuzz/tags.pub)
I was talking to my marketing guy about integrating a tags-based onboarding workflow for freshly installed forums. The gist of it is, the forum admin adds a couple tags for the forum to globally follow, and achieves this via fedibuzz relay or tags.pub. Auto-categorization rules are automatically added and the forum starts receiving new (highly relevant!) posts through the magic of hashtag+federation ✨ He then asked whether it was possible to suggest related tags (e.g. add `guitar` suggest `acousticguitar`, `electricguitar`, etc.) for the admin to also add, to which I replied in the negative "for now". But that got me thinking, is this something fedibuzz or tags.pub could achieve/offer in its API? It would require a bit of data analysis, to match up common hashtag usage, but doable maybe? cc @evan @evan" aria-label="Profile: evan@cosocial.ca">@evan@cosocial.ca @astro@c3d2.social
002
julian @julian.activitypub.space.ap.brid.gy · 13/03/2026
aw crud.. it's Friday evening and I broke infinite scrolling. 🫠
000
julian @julian.activitypub.space.ap.brid.gy · 13/03/2026
Asked Gemini to remove the background of an image, and it sent back the image with the background replaced with white/grey checkboard squares instead :ok_hand:
000
julian @julian.activitypub.space.ap.brid.gy · 11/03/2026
Amused this morning because I discovered I can not load any content from eigenmagic.net, a Mastodon instance. My requests return `402 Payment Required`, and attempting to ask the admin is futile because I cannot load their user (I get this emoji back when I query webfinger: 💰) So... that's […]
activitypub.space
Amused this morning because I discovered I can not load any content from eigenmagic.net, a Mastodon instance. My requests return `402 Payment Required`, and attempting to ask the admin is futile because I cannot load their user (I get this emoji back when I query webfinger: 💰) So... that's unfortunate. I'd love to learn what is happening (maybe it's an anti-AI/bot filter that is incorrectly classifying AP requests), but, well... I unfortunately don't have time to go down rabbit holes :sweat: @daedalus@eigenmagic.net :point_left: this will not be a link because I can't load it lol.
000
julian @julian.activitypub.space.ap.brid.gy · 10/03/2026
Southern Ontario (or even Canadian) friends... my CAA membership expires in 4 days. Should I re-up so I can get help if I need it (battery assist/towing), or just put a reputable towing company in my address book? ($136/yr vs one-time towing cost of $250) Didn't need CAA this year, but who […]
activitypub.space
Original post on activitypub.space
100
julian @julian.activitypub.space.ap.brid.gy · 10/03/2026
TIL Fastmail has a feature where you can add notes to emails that come in. I accidentally triggered it when I pressed `o`. cc @j12t@j12t.social
A note I wrote to myself to remember to actually buy a ticket to FediForum this time around
111
julian @julian.activitypub.space.ap.brid.gy · 09/03/2026
Literally low-key afraid of responding to potentially AI-generated project announcements in fear that the AI will write a hit-piece on me in response. So that's where we're at today.
000
julian @julian.activitypub.space.ap.brid.gy · 09/03/2026
Reposting to the threadiverse Original credit @lucaswerkmeister@wikis.world wikis.world/@LucasWerkmeister/11619…
2bd6ebec-6fb9-4d85-9d6a-beb4d2ea3fe0-image.jpeg
113
julian @julian.activitypub.space.ap.brid.gy · 03/03/2026
Hot take: the "unwelcoming" nature of fedi is learned behaviour. People see others being absolutely terrible to other human beings, see no repercussions (except **driving away the fledgling AP newbie or dev**), and think it's okay to terrorize the next one they encounter.
101
julian @julian.activitypub.space.ap.brid.gy · 02/03/2026
The next version of NodeBB (v4.10.0) will ship with the ability to set alt-text with images :writing_hand: While this was already natively supported in-site, the alt text wasn't federated out until now. Thanks to @kirk@social.coop who filed the original […] [Original post on activitypub.space]
103
julian @julian.activitypub.space.ap.brid.gy · 02/03/2026
I've been so busy preparing for FediMTL the past two weeks that I totally forgot to actually register for the FediForum unworkshop! Oops! :sweat_smile: I look forward to reading the discussions that ensue from it though.
001
julian @julian.activitypub.space.ap.brid.gy · 02/03/2026
000
julian @julian.activitypub.space.ap.brid.gy · 28/02/2026
Jonathan Haidt's been doing a media tour to promote his and Catherine Price's new book, _The Amazing Generation_. After watching the duo's segment on _The Daily Show_ , it's inspired my wife and I to try a digital sabbath on Saturdays again. Part of why it failed in the past (multiple times […]
activitypub.space
Book and Magazine suggestions?
Jonathan Haidt's been doing a media tour to promote his and Catherine Price's new book, _The Amazing Generation_. After watching the duo's segment on _The Daily Show_ , it's inspired my wife and I to try a digital sabbath on Saturdays again. Part of why it failed in the past (multiple times, I'm sad to say) was that we didn't have anything physical to read. We'd start making small concessions ("I'm reading a Kindle, it's ok"), leading to more concessions ("I'm only using my phone to look something up"), and pretty soon we'd be back on our phones again. So, fedi, any suggestions for book series' and (print) magazines to subscribe to? [...] We're probably going to subscribe to _Macleans_ , but it's monthly now, so we need more suggestions! Bonus if it's Canadian content, but not a hard requirement. We'll probably do Chirp for the kids, too.
000
Reposted by julian
julian @julian.community.nodebb.org.ap.brid.gy · 27/02/2026
Hello all! (Sorry, I could not resist with the title :laughing:) Today we are releasing NodeBB v4.9.0, on a Friday, toward the end of the day, because we like having our weekends ruined. As usual, we recommend you update to this stable version of […] [Original post on community.nodebb.org]
community.nodebb.org
NodeBB v4.9.0 — A Whole New /world!
Hello all! (Sorry, I could not resist with the title :laughing:) Today we are releasing NodeBB v4.9.0, on a Friday, toward the end of the day, because we like having our weekends ruined. As usual, we recommend you update to this stable version of NodeBB, not least because it fixes a federation issue accidentally introduced last month. There are a bunch of new features and usability improvements here, for both end users and admins. Federation improvements abound, as well as a few moderation upgrades. As usual, we fixed a ton of bugs, and even a couple open issues from the 2010s :scream: Here is a list of the changes and new features you should expect to see! [...] ## :world_map: New "World" page `/world` has been updated so that is closer to a feed-reader than a topic list. While I will continue to iterate on this design over time to better promote topics, I am hoping that this proves to be more accessible of an interface compared to the old topic listing. Your watched/tracked remote categories will be listed in a sidebar (hidden behind a drawer on mobile views) for easy access. The default view ("Latest") continues to be a list of content from people you follow, and content shared by those same people. The other view ("Popular") shows unconstrained content, and can include content from people you don't follow. ## :lock: Remote topics now unavailable to guests After an Alibaba bot was recorded mercilessly scraping a lot of the public content served up by NodeBB, we decided to restrict access to that content to registered users. While this would normally mean that "View Original URL" would stop working from other federates sites (since visitors are usually guests), we have added an exclusion to this logic that will continue to serve up the content to guests if at least one local user has commented on the topic. ## :writing_hand: UX change for composer and chats @baris worked on a number of usability fixes that make the experience of using our post composer and chat interface much better. For the longest time we had issues with the composer not properly resizing when mobile keyboards opened. Composing and replying should work much better now that we are using the latest CSS and javascript tooling to properly detect visual viewport changes. ## :bell: Better notifications @baris also updated the notifications system so that `bodyLong`, which usually contains post text, is now sent with all notifications. This should increase the usability of notifications (both via web, email, or push). ## :arrows_counterclockwise: Cross-posting privilege A previous release introduced the ability to cross-post content into local categories. This functionality can now be gated behind a privilege at the category level. ## :wave: Guest call-to-action @baris introduced a new guest "call-to-action" banner that will help guide guests toward registering a new account to contribute to your community :blush: ## :label: Title-less topics As part of the changes to `/world`, we also allow the creation of topics without a title. If you don't pass in a title, we will generate one for you based on the first sentence in your post. The same title generation logic was applied to remote content in the past, and now it also applies to local content. This also means you can use the `/world` page to just fire off something quickly without having to do the hard work of thinking up a title. You're welcome :laughing: ## :sparkles: Opportunistic backfill Now that the fediverse's largest implementor, Mastodon, supports `context`, which enables backfill, we have implemented an opportunistic backfill feature that will check for new replies when you enter a topic. It'll also regularly check the top most popular remote topics known by the instance for new posts. ## :no_entry: Reasons You can now set up a recurring list of "reasons", which you can invoke on certain moderation actions. These custom reasons can be used when a user is banned, muted, or on post queue rejection. You can set up these reasons from ACP > Manage > Users > (Gear) > Manage Custom Reasons ## :information_desk_person: Registration queue now applies for SSO plugins This issue, open since 2016 is finally fixed. SSO plugins don't automatically bypass the registration queue anymore. This was a common vector for spammers to bypass registration limitations. ## :bug: Additional features and bug fixes * An improvement to auto-installation of plugins * Removed many remote tids and pids stored in the db for no reason (thanks @baris) * A regression that caused nodebb-to-nodebb federation to fail (and possibly many others) * Notifications can now be passed custom icons * ACP privilege selector now no longer shows remote categories * Improvements to mentions to better handle periods at end of sentences, or names within names * All cached used internally are now exposed in the admin panel for better management. * Sitemap cache duration is now configurable * Infinite scrolling now works on `/world` * Slug generation errors when you mixed and matched `-` and `.` * Topic pruning applies to all remote cids now, not just cid -1 * Chats list updated properly now, when new messages are received, chat messages now properly backfilled upon reconnection * NodeBB now federates Delete on both deletion and purge * * * For the full changelog, please take a look at the closed issues list for this milestone, or take a gander at the much less impressive `CHANGELOG.md` in our repository root.
113
julian @julian.activitypub.space.ap.brid.gy · 27/02/2026
So NodeBB tests have been failing for the past few days because coveralls.io is down. Coveralls is a code coverage bot that is free for open source projects. We implemented it years ago and it's been trucking along fine all these years. While coveralls being down technically prevents us from […]
activitypub.space
coveralls.io
So NodeBB tests have been failing for the past few days because coveralls.io is down. Coveralls is a code coverage bot that is free for open source projects. We implemented it years ago and it's been trucking along fine all these years. While coveralls being down technically prevents us from running our tool to launch a new version, we could always just do it manually. Their outage page is here: https://status.coveralls.io/ They are on day 3 of the outage and have absolutely no idea when things will come back up. This paragraph is worded curiously: > We want to be transparent with you: after two full days of working directly with our hosting provider’s account team, we still do not have an ETA for service restoration. Despite having internal sponsorship within our provider’s organization, we have been unable to get the traction needed to resolve **what appears to have been an automated action** , one that no one on their side has taken ownership of causing or fixing. (Emphasis mine.) Perhaps I have been reading too many AI-doomer articles. This sounds like an AI agent went in and started deleting shit. The post mortem is going to be very very very interesting. cc @mariusor@metalhead.club, because he started an HN thread about it
010
julian @julian.activitypub.space.ap.brid.gy · 26/02/2026
Hey @evan@cosocial.ca, I'm watching your lightning talk at FOSDEM! I'm simultaneously glad it's less than 10 minutes, but sad it's not longer too :stuck_out_tongue_closed_eyes: Some questions I'm jotting down while I'm watching it [...]
activitypub.space
tags.pub clarification questions
Hey @evan@cosocial.ca, I'm watching your lightning talk at FOSDEM! I'm simultaneously glad it's less than 10 minutes, but sad it's not longer too :stuck_out_tongue_closed_eyes: Some questions I'm jotting down while I'm watching it [...] 1. I can see the user on ActivityPub.Space, which is how it's supposed to work. Would I be able to follow this user from a non-Person? If integrating into NodeBB, I'd maybe want the Application actor itself to follow it. 2. Love how you head off concerns about consent issues with a slide about how it's not scraping, mass-following, etc. So it uses relays, such as the ones on relaylist.com? 1 . Let's talk about how we can get NodeBB sharing data to tags.pub by default (or by admin opt-out switch.
000
julian @julian.activitypub.space.ap.brid.gy · 26/02/2026
Can anyone suggest an anarcho-socialist centred instance? Asking for a friend. Really.
101
julian @julian.activitypub.space.ap.brid.gy · 25/02/2026
There are a couple of parallel development efforts tackling the problem of hashtags. The main drawback is that while you can use them in your posts and search for them to find additional content, the reach and visibility of the hashtag is restricted to that of the instance's own visibility. In […]
activitypub.space
Global tags and content discovery
There are a couple of parallel development efforts tackling the problem of hashtags. The main drawback is that while you can use them in your posts and search for them to find additional content, the reach and visibility of the hashtag is restricted to that of the instance's own visibility. In other words, looking up a hashtag on your instance probably would not give you a complete view of the use of that hashtag worldwide. 1. @newsmast@newsmast.social channels * The first I'd heard of it was Newsmast's "channels". How they worked was opaque to me, but after seeing @saskia@backend.newsmast.org's presentation, I now know it is collating use of hashtags into a broader topic (e.g. #Asenal, #AFC, plus many others into "Arsenal") 2. tags.pub * @evan@cosocial.ca came up to me after FediMTL and asked whether I'd looked into his FOSDEM presentation about tags.pub, which aims to do something similar, although user-facing. Users can follow individual "tag" actors and they then receive all content tagged as such. * I will have to watch the presentation as `tags.pub` is headless and has no landing page! :laughing: 3. FediBuzz Relay * ActivityPub.Space is following this approach, where I set up NodeBB to subscribe to a couple of relevant FediBuzz relays: `#activitypub`, `#fedidev`, `#fediadmin`, `#fedimod` and `#fedimods` It's interesting to follow the convergent evolution of solutions to solve a single problem. Right now NodeBB gives you the tools to set up the FediBuzz relay connection + auto-categorization rules, but it's not exactly user-friendly for admins. The ideal flow would be something much more high level for admins. An additional field during category creation where they can specify hashtags they'd like to follow globally. Simple, understandable, hides all the backend complexity away. It is worth looking into additional solutions (like `tags.pub` or the Newsmast channels) so as to not be tied to a single provider in the backend.
001
Reposted by julian
julian @julian.activitypub.space.ap.brid.gy · 25/02/2026
@johannab@cosocial.ca asks: > NodeBB strikes me as the best aligned of the extant platforms for municipal governments. Here's a question for julian: is he prepared for, or interested in, a promotion program to city-scale organizations? To which I answered, simply: "Yes." Now that I have the […]
activitypub.space
Promoting NodeBB/fedi to city-scale organizations
@johannab@cosocial.ca asks: > NodeBB strikes me as the best aligned of the extant platforms for municipal governments. Here's a question for julian: is he prepared for, or interested in, a promotion program to city-scale organizations? To which I answered, simply: "Yes." Now that I have the time to expand on my answer: Yes, absolutely! There is definitely a space for municipal city-scale adoption of the fediverse through properties that they alone control, but federate widely. I imagine a local-fedi where my mayor posts via `marianne@burlington.ontario.gc.ca`, and she can talk to her constituents on neighbourhood-level instances like `tyandaga.social` or `aldershot.space`, or anybody worldwide via the power of the fediverse. Right now we're in the unfortunate position where the city is posting notices to X/Twitter, and cross-posting to Facebook and Instagram. I would bet a lot of money most other municipalities are doing the exact same thing. Adding in the fediverse should be straightforward, and I welcome any opportunity to make it happen. Let's make some connections!
001
julian @julian.activitypub.space.ap.brid.gy · 25/02/2026
@johannab@cosocial.ca asks: > NodeBB strikes me as the best aligned of the extant platforms for municipal governments. Here's a question for julian: is he prepared for, or interested in, a promotion program to city-scale organizations? To which I answered, simply: "Yes." Now that I have the […]
activitypub.space
Promoting NodeBB/fedi to city-scale organizations
@johannab@cosocial.ca asks: > NodeBB strikes me as the best aligned of the extant platforms for municipal governments. Here's a question for julian: is he prepared for, or interested in, a promotion program to city-scale organizations? To which I answered, simply: "Yes." Now that I have the time to expand on my answer: Yes, absolutely! There is definitely a space for municipal city-scale adoption of the fediverse through properties that they alone control, but federate widely. I imagine a local-fedi where my mayor posts via `marianne@burlington.ontario.gc.ca`, and she can talk to her constituents on neighbourhood-level instances like `tyandaga.social` or `aldershot.space`, or anybody worldwide via the power of the fediverse. Right now we're in the unfortunate position where the city is posting notices to X/Twitter, and cross-posting to Facebook and Instagram. I would bet a lot of money most other municipalities are doing the exact same thing. Adding in the fediverse should be straightforward, and I welcome any opportunity to make it happen. Let's make some connections!
001
julian @julian.activitypub.space.ap.brid.gy · 25/02/2026
NodeBB federates out `Note` or `Article` depending on the length of the content. While this by-and-large works, the article logic does not encourage as much discussion as expected because a `summary` is generated so as to provide something for microblog-style software to show (otherwise, it […]
activitypub.space
Reduced engagement due to Article type
NodeBB federates out `Note` or `Article` depending on the length of the content. While this by-and-large works, the article logic does not encourage as much discussion as expected because a `summary` is generated so as to provide something for microblog-style software to show (otherwise, it would only show the title (`name`) and a URL to the forum.) That summary is limited to a maximum or 500 characters, ending at the last full detected sentence. [...] When composing a long topic, 500 characters may not be enough to fully introduce the topic and engage users. This lowers click-through rates. N.B. Note the above, where I manually added a `[...]` because that is where NodeBB would cut content short. When only those 500 characters are read, it's not the best introduction to this topic. I expressed my frustration about this online to @thisismissem and suggested that I might just revert back to sending the entire post content in `summary`. This would violate FEP b2b8's recommendation that summary be a maximum of 500 characters: > It should be a maximum of about 500 characters; a few sentences; or a short paragraph. After consultation with Matt Baer of Writefreely (@matt@writing.exchange), he suggested the following changes: * Append a `[...]` at the end of the truncated content to signal that there is additional content that is not seen * Allow the use of a magic string (like an HTML comment: `<!-- break -->`) that would allow power users to manually select where the summary should end. This would still allow for summaries over 500 characters. That seems like a good compromise for me, where concerns from power users like myself would be addressed, while not overly complicating the interface for users who do not need to know about this. Pinging @evan (@evan" aria-label="Profile: evan@cosocial.ca">@evan@cosocial.ca) for his thoughts.
201
julian @julian.activitypub.space.ap.brid.gy · 25/02/2026
Currently sitting on a train from Montreal to Toronto, and what are the odds that I end up sitting next to a couple of people (Gen Zs, if it matters) discussing the exact thing that I travelled to Montreal for — to talk about the state of social media and its effects on our day-to-day lives? […]
activitypub.space
The discussion about the effects of social media is happening all around us
Currently sitting on a train from Montreal to Toronto, and what are the odds that I end up sitting next to a couple of people (Gen Zs, if it matters) discussing the exact thing that I travelled to Montreal for — to talk about the state of social media and its effects on our day-to-day lives? Their conversation has ranged from the inauthenticity of communication, the masking that one needs to do online when maintaining a social profile, optimizing for engagement (and the active refusal to do so for authenticity reasons), curating what one posts to social media, etc. Sometimes when discussing these things online or at a conference one feels like they're in an echo chamber of sorts. It's nice to know that the next generation thinks about these things just like I do. Maybe the odds aren't that low, maybe that discussion is happening all around us, more often than we think.
101