(#5gb3dqq) Honestly, the entire follow system is flawed. Check my followers, #3 was a web crawler with a user agent that happened to fit the regex, and #17 was myself requesting my own feed with a simple curl command.
Unfortunately, I don't see a real solution to the problem while keeping the ability for external feeds to show up as "following" a user on a Yarn pod.
matched #udxx66a score:10.96
Search by:
Search by 3 tags:
(#5gb3dqq) The user agent regex was made a little more restrictive after my git issue, but I think someone could use this and really start breaking things. I want to poke around more than I already have, but I'm not doing it on a live production instance of Yarn.
matched #4kmq2qa score:10.96
Search by:
Search by 1 tags:
(#5gb3dqq) all really good points! Especially the one on privacy is quite valid and something I’d like to address immediately. Can we get some action items so that I can implement them as soon as possible?
matched #ovbtmpq score:10.96
Search by:
Search by 1 tags:
@lyse (#5gb3dqq) Sure but we’d have to replace it with something that provides the same utility:
* Know who has started following **you**
* Pod Admin can see who’s new to their pod
matched #wzk6pkq score:10.96
Search by:
Search by 1 mentions:
@lyse (#5gb3dqq) The way I originally "envisioned" this was basically a convenience around the whole `User-Agent` way of advertising your interest in following someone's feed. Of course you don't have to, it's actually optional. But I didn't really want to build a full-blown "notifications" system at the time, I just did the lazy thing of just publishing a `FOLLOW foo from bar using xyz` posted from a @twtxt bot at the pod level. Think of it as tailing the `access.log` looking for matching `User-Agent`(s) -- Because that's what it does 🤣
matched #i2mibha score:10.96
Search by:
Search by 2 mentions:
@lyse (#5gb3dqq) I _do_ agree about the privacy aspect though. If you recall an account on a pod has the notation of "show my followers publically" and "show my followings publically" and you an toggle these. So that's cool. But if we're going to do this then we _probably_ want to remove the @twtxt bot entirely and build a proper internal per-user notification?
matched #5fcmr3a score:10.96
Search by:
Search by 2 mentions: