ActivityPub was developed in literally the same W3C group that Webmention and Micropub were standardized in ;-) btw why no website in your twitter bio? Where can I follow your fediverse posts?
LOL I've never even seen that paragraph and it took me a really long time to find it. Also note that was written in 2013 when that was pretty much true. Feel free to update it, it's a wiki after all. indieweb.org/wiki/index.php?…
Super awesome writeup of the iOS IndieWeb reader app "Indigenous" and Eddie's motivations for writing it! Love seeing more IndieWeb tools like this! eddiehinkle.com/2018/05/02/1…
Heading to Homebrew Website Club SF, "502 Bad Gateway" edition! 🏰 5:30pm at MozSF! tantek.com/2018/122/e1/homeb… Join if you're in the area, or join for drinks after!
I'm going to be hosting a workshop on @OAuth_2 this fall in Nürnberg, Germany! 🔐 Only 15 spots available, so sign up now! colloq.io/events/tollwerksta…
Just downloaded my @instagram dump and I'm pretty disappointed. 😔
* My comments include only the comment text, a timestamp, and the photo author. No way to know what I'm commenting on
* Same for photos I've liked
* There's no indication of likes or comments on my own photos
Sadly there isn't a satisfying answer to that. Anything that your JS can use to store any token is vulnerable to XSS. The only secure option is cookies, but that won't work with OAuth. stormpath.com/blog/where-to-…
BCP for public UA clients:
* use the authorization code flow
* omit client secret
* strict redirect URI validation
Some citations and more info: aaronparecki.com/oauth-2-sim…
That page refers specifically to the thing you're talking about in email, services innovating in non-compatible ways, locking people in to their service. There's nothing wrong with commercial services in the IndieWeb as long as they're interoperable.