4 ms·
ActivityPub is like JWT. Simple on the outside but complex inside. For example I wanted to implement a simple server to connect to Mastodon. JSON via HTTP, what
by Shoothe 9y ago
ActivityPub is like JWT. Simple on the outside but complex inside. For example I wanted to implement a simple server to connect to Mastodon. JSON via HTTP, what could be simpler? Actually it's JSON-LD not JSON. But it doesn't matter as JSON-LD is JSON, right? No, as the standard requires normalizing JSON-LD for purposes of signing that includes all of RDF canonicalization, of course the standard do not require it [0] but it's akin to unencrypted HTTP2, theoretically it exists but practically doesn't.
What's interesting is that ActivityPub requires signing the data twice, first on a HTTP request level, then the JSON-LD itself. It seems like the designers tried to make it simple (let's use JSON-LD and HTTP) but after several edge cases the standard got out of control.
[0]: "Linked Data Notifications also supports a number of RDF serializations which are not required for ActivityPub implementations. However, ActivityPub implementations which wish to be more broadly compatible with Linked Data Notifications implementations may wish to support other RDF representations." source: https://www.w3.org/TR/activitypub/ https://www.w3.org/TR/activitypub/
- daveid 9y agoHTTP signatures and LD-signatures serve different purposes. HTTP sigs authenticate server-to-server requests, while LD-signatures allow to forward verified messages in the network. The forwarding part is a good extra for UX purposes but it's not necessary for your implementation, you can just stick to HTTP sigs which are really simple. I agree that LD-signatures are very complicated to implement. If you avoid LD-signatures then you don't have to mess with JSON-LD canonicalization either, you can just treat the JSON as simple JSON (though it's still a bit fiddly because a value can often be either a URI string, an array of URI strings, an object, or an array of objects).
- Shoothe 9y agoI know what the signatures are for but I wonder if there's a simpler way to achieve these objectives. Server authentication: For example XMPP uses client certificates to authenticate servers to other servers (TLS server certificates usually can be used for client authentication too). Message authentication: maybe exchanging OpenPGP messages would be easier? They already are signed and the payload can be anything. Of course it's not as easy to list a collection of these messages as it is with JSON (just collect into an array). > If you avoid LD-signatures then you don't have to mess with JSON-LD canonicalization either, I want to be interoperable with existing software so avoiding it is not a practical option (although allowed by the ActivityPub spec). Just like having non encrypted HTTP2 is not a practical option (although allowed in the spec).