this post was submitted on 11 Apr 2025
71 points (100.0% liked)
Fediverse
34764 readers
108 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
A blog entry on how it works and what it does at a high level could be nice. I'm not sure what I'm looking at, but there must be some API call to Lemmy and it's probably happening on the server due to CORS; not sure how this would work just in the browser if the Lemmy instance has CORS setup...
Edit: OK the instance 0d.gs does in fact not have CORS 😮 That's a little concerning...
Hold up, neither does programming.dev? Uh... @recursive_recursion@programming.dev and @Ategon@programming.dev is that safe? I'm not a security expert but doesn't this allow for cross site attacks?
Anti Commercial-AI license
I've noticed that a more detailed writeup is warranted! So I'll be working on that.
CORS is enabled on lemmy, you have to send the 'Origin' header in order to get the Access-Control headers. Which allows cross-origin for simple requests. No added headers, cookies or other data. So all API calls are made in JS by your browser.