clarify/extend security consideration B.2 "verification" for attached files #432
Labels
Needs errata
We need to add errata for this
Needs FEP
Needs a FEP
Needs Primer Page
Needs a page in the ActivityPub primer
Next version
Normative change, requires new version of spec
As a thought after Mastodon's GHSA-jhrq-qvrm-qr36 it might be a good idea to extend the security consideration B.2 with a bit of wording about what kind of user submitted content is meant, and what relevance the
Content-Type
and perhaps Content Type Negotiation has in that context.Especially when reading the 2nd paragraph the focus seems to me to be on ActivityPub Content, perhaps not taking into account that attached files/media may be hosted on the same host(-name).
In particular I'm thinking of wording like this:
And perhaps inserting another paragraph like this at the end of the section:
The text was updated successfully, but these errors were encountered: