Sign in

Matthieu 🦋

@matthieu.bsky.team
15K followers 289 following 314 posts

Protocol Engineer at Bluesky. Building the open social web on AT Protocol. Into web standards, OAuth, TypeScript, and over engineered code. Dad, gamer, Dire Straits fan, sailor and beer enthusiast. From Brussels 🇧🇪

PostsRepliesMedia
Matthieu 🦋 @matthieu.bsky.team · 26/08/2026
That makes sense !
080
Matthieu 🦋 @matthieu.bsky.team · 24/08/2026
Well, it depends on how you implement it... If you index everything from the firehose/jetstream then you don't need the did. Then you can actually implement this using RASL.
dasl.ing
DASL: RASL — Retrieval of Arbitrary Structures & Links
RASL is a URL scheme used to identify content-addressed DASL resources along with a simple HTTP-based retrieval method.
140
Matthieu 🦋 @matthieu.bsky.team · 22/08/2026
Yep, that's part of the reference PDS. Designed by @chadtmiller.com
180
Matthieu 🦋 @matthieu.bsky.team · 17/08/2026
So excited to have you back with us! Congratulations on the wedding 💙
030
Matthieu 🦋 @matthieu.bsky.team · 07/08/2026
Ironically, I wouldn't have seen this post with this
071
Matthieu 🦋 @matthieu.bsky.team · 04/08/2026
This is @divy.zone 's workaround: github.com/bluesky-soci...
github.com
Adopt TypeScript 7 stable and tune editor/lint config by devinivy · Pull Request #5306 · bluesky-social/atproto
TypeScript 7 now ships under the standard typescript package, with the compiler binary back to tsc (announcement). This replaces @typescript/native-preview with typescript 7.0.2 and updates every t...
150
Matthieu 🦋 @matthieu.bsky.team · 31/07/2026
AT protocol enthusiasts rejoice! He did it! @dholms.at fixed AT-URIs!
Screenshot of a git commit by @dholms "fix up at uris"
4925
Matthieu 🦋 @matthieu.bsky.team · 28/07/2026
This is different and won't be fixed by that other fix.
140
Matthieu 🦋 @matthieu.bsky.team · 24/07/2026
Turns out, it's ublock origin that prevents the page from loading successfully. I'll just add an exception!
030
Matthieu 🦋 @matthieu.bsky.team · 24/07/2026
Am I the only one unable to open @leaflet.pub websites on FF mobile? They just render a blank page...
240
Matthieu 🦋 @matthieu.bsky.team · 24/07/2026
Link where?
100
Matthieu 🦋 @matthieu.bsky.team · 23/07/2026
oauth.dad 🫣
2112
Matthieu 🦋 @matthieu.bsky.team · 22/07/2026
We know developing OAuth clients locally has been harder than it could be, partly because `localhost` isn't allowed as a `redirect_uri`. Please chime in on this discussion if you have any concerns about relaxing that particular rule.
github.com
Proposal: allow `localhost` redirect URIs in the localhost dev exception in the OAuth spec · bluesky-social atproto · Discussion #5255
This is a proposal carrying on discussion from this closed PR: bluesky-social/atproto-website#709. There is also a corresponding open issue, bluesky-social/atproto-website#699. Currently, http://12...
915033
Matthieu 🦋 @matthieu.bsky.team · 13/07/2026
Have you tried Velja by @sindresorhus.com ? I love that app
140
Matthieu 🦋 @matthieu.bsky.team · 07/07/2026
All the reginos !
050
Matthieu 🦋 @matthieu.bsky.team · 05/07/2026
@divy.zone has been wanting this since forever.. a service definition document that specifies both the lexicons and auth methods supported.
160
Matthieu 🦋 @matthieu.bsky.team · 05/07/2026
This was right around the time I learned JavaScript thanks to @j11y.io 's video podcasts 💙
010
Matthieu 🦋 @matthieu.bsky.team · 05/07/2026
The initial thinking was that all these actions should be done through the account manager. But if you are able to go that far, we might as well allow account deactivation. Deactivating an account does clear all the associated (oauth) sessions. Would that be an issue?
170
Matthieu 🦋 @matthieu.bsky.team · 03/07/2026
Now that we have HTTP QUERY, should the atproto spec be updated to allow that HTTP method for XRPC query methods?
datatracker.ietf.org
RFC 10008: The HTTP QUERY Method
This specification defines the QUERY method for HTTP. A QUERY requests that the request target process the enclosed content in a safe and idempotent manner and then respond with the result of that pro...
1132
Matthieu 🦋 @matthieu.bsky.team · 30/06/2026
By defining authority as: [ userinfo "@" ] host [ ":" port ] rfc3986 fundamentally constraints the use of URIs in decentralized contexts Since there seems to be some energy in the IETF to adopt more decentralized protocols (as ATP is proof of), "moving the mountain" might not be that inconceivable.
1161
Matthieu 🦋 @matthieu.bsky.team · 25/06/2026
Yeah I've definitely done that toothat too 😅
010
Matthieu 🦋 @matthieu.bsky.team · 25/06/2026
Did you know you can start a testing ATProto OAuth client with this simple command? $ pnpx @atproto/oauth-client-browser-example 8080 You can then use the inspector console to interact with your PDS: `await bskyClient.get(app.bsky.actor.profile)` `await bskyClient.list(app.bsky.feed.post)` ...
Screenshot of a browser console showing the command "await bskyClient.get(app.bsky.actor.profile)" and its result
1459
Matthieu 🦋 @matthieu.bsky.team · 24/06/2026
Hey, as I said previously, I'm open to changing the way this work! However, since this is part of the spec, we need to do a full spec + implementation update (+ coms). This is not my priority at the moment but I'd be happy to see someone post PRs in the spec + implementation about it 👍
130
Matthieu 🦋 @matthieu.bsky.team · 24/06/2026
Answered in GH
120
Matthieu 🦋 @matthieu.bsky.team · 09/06/2026
From a design pov, I recommend you use "subject" instead of "standardSiteDocument" so that your upvote can be used to upvote anything ;-)
140
Reposted by Matthieu 🦋
Laurens @laurenshof.online · 28/05/2026
so it turns out the new papal encyclical has a pretty good diagnosis of why the fediverse and the atmosphere keep struggling to govern themselves. guess were doing catholic theology in a protocol blog now connectedplaces.online/reports/fr16...
connectedplaces.online
FR#164 – The Pope on Defederation
This week, the Catholic Church wrote one of the better diagnoses of why decentralised social networks keep struggling.
914742
Reposted by Matthieu 🦋
Firefox for Web Developers @webdevs.firefox.com · 18/05/2026
Chrome shipped an LLM Prompt API to the web platform. At Mozilla, we oppose this API. Here's why:
18419122
Matthieu 🦋 @matthieu.bsky.team · 28/04/2026
Ok I did it github.com/bluesky-soci...
github.com
Add applyWrites() method to Lex SDK Client by matthieusieben · Pull Request #4895 · bluesky-social/atproto
150
Matthieu 🦋 @matthieu.bsky.team · 28/04/2026
The main property I'd wanna keep is the options being optional when not needed ("literal" krey)
120
Matthieu 🦋 @matthieu.bsky.team · 28/04/2026
I'd definitely be down to support something like this:
declare const client: Client

await client.applyWrites((op) => {
  op.create(app.bsky.feed.post, {
    text: "yo",
  })

  op.update(app.bsky.actor.profile, {
    displayName: "John",
  })

  op.delete(app.bsky.feed.like, "123")
})
140
Matthieu 🦋 @matthieu.bsky.team · 27/04/2026
Alright y'all convinced me to push this.
1180
Matthieu 🦋 @matthieu.bsky.team · 27/04/2026
For example, we could definitely allow localhost for loopback clients.
120
Matthieu 🦋 @matthieu.bsky.team · 27/04/2026
We made it strict so we could relax it. Feel free to reach out to me or to @jimray.locket.computer & @alex.bsky.team with this kind of constructive comments. The best would probably be to tag us in a GH discussion. We definitely want to make OAuth as accessible as can be (while staying secure)
170
Matthieu 🦋 @matthieu.bsky.team · 27/04/2026
See here for more details github.com/bluesky-soci...
github.com
120
Matthieu 🦋 @matthieu.bsky.team · 27/04/2026
I agree. The reason for this is OAuth RFCs and BCPs... Here is the dev command from the OAuth example app, which will use 127.0.0.1 instead github.com/bluesky-soci...
github.com
130
Matthieu 🦋 @matthieu.bsky.team · 22/04/2026
I laughed
040
Matthieu 🦋 @matthieu.bsky.team · 21/04/2026
Yep. Oauth client is supposed to handle error propagation from every "hook"
100
Matthieu 🦋 @matthieu.bsky.team · 17/04/2026
On a technical POV, I think that we could support both behaviors by allowing the oauth-provider to be configured to use a particular (set of) collection & data mapping function so that actors with their own deployment of the Bsky PDS distro can customize where they get profile data from.
130
Matthieu 🦋 @matthieu.bsky.team · 17/04/2026
For "hosting only" PDS's (like Eurosky), this offers a great way to differentiate from other offerings (like "app tied PDSs"): allow users to update all their profiles from all their services from a centralized location (the PDS account mgt UI), by updating multiple records at once.
140
Matthieu 🦋 @matthieu.bsky.team · 17/04/2026
I am definitely not opposed to the idea. But I also see this as a way for PDS providers to differentiate from each other. For example; for PDS's tied to apps (Tangled, Spark, Blacksky, Bluesky), I makes more sense from a UX pov to use the app's namespace as profile data.
120
Matthieu 🦋 @matthieu.bsky.team · 16/04/2026
They are probably built on atproto...
000
Matthieu 🦋 @matthieu.bsky.team · 15/04/2026
<pds-url>/account
110
Matthieu 🦋 @matthieu.bsky.team · 15/04/2026
Should be fixed.
140
Matthieu 🦋 @matthieu.bsky.team · 15/04/2026
Hey y'all, I just released a new version of the PDS distribution that fixes that hCaptcha/COEP issue. Update to v0.4.219 and get the new account manager interface as added bonus.
25114
Matthieu 🦋 @matthieu.bsky.team · 15/04/2026
I'm personally open to both. They would both be "internal" features that don't require spec changes. The hcaptcha alternative might be harder to implement correctly though...
020
Matthieu 🦋 @matthieu.bsky.team · 13/04/2026
It does. And thank you. This is what I came up with too but I gotta admit it does sound a little weird... Like "Mon compte atmosphérique" makes more sense strictly speaking but then it sounds like it's referring to something different, which we don't want.
120
Matthieu 🦋 @matthieu.bsky.team · 13/04/2026
"pseudo Internet" then ?
100
Matthieu 🦋 @matthieu.bsky.team · 13/04/2026
Yeah, that's why I'm asking...
100
Matthieu 🦋 @matthieu.bsky.team · 13/04/2026
Yeah that makes sense
100
Matthieu 🦋 @matthieu.bsky.team · 13/04/2026
sneak peek
Screen shot of the PDS account manager interface, giving some context of where the "My Atmosphere Account" would show up
4365