Re: Why Publ won’t support magic auth links

In response to a Publ blog post, Kicks Condor writes:

One question, though—could the Atom feed list rel alternate versions of the feed? (That would have type application/atom+xml?) It also seems like rel self could have the non-authenticated version of the feed. It doesn’t make sense for credentials to be in that URL. These are possibly naive suggestions—apologies, if so. Again, fantastic write-up!

The problem is that it’s up to the sharing news reader to know which URL to use for the sharing, and there’s no way to control what URL the reader happens to use. I know that Feed On Feeds will use the URL for the actual subscription (since that’s the only source URL it tracks in the first place), and who knows what other readers with sharing features will do!

And changing the rel="self" URL has a different problem – some readers (again, such as Feed On Feeds) treat that as the canonical URL and will update their subscriptions to point to that URL instead, so setting rel="self" to the unauthenticated feed means most users will be unable to remain logged in.

Basically, it’s a tricky issue that has no right answer with the Atom spec as it currently exists. So if some other mechanism has to be designed, it might as well be done in a safe, unambiguous way from the beginning. If some other use case for magic auth links comes up I’ll reconsider implementing them, but at least for friends-only subscription access, the privacy risks are simply not worth it.

GeekGirlCon 2019 Merch!

Hey everyone! I just thought I’d give folks a preview of the items I’ll be selling at GeekGirlCon.

Read more…

Gah

Why didn’t anyone tell me that the previous blog post was posted as a very-broken comics post

Diagnostic process

Today was a travel day to Portland, for Retro Game Expo. So of course just as the train was ready to take off was when my HMO decided to call me to do the ADHD diagnostic intake. I asked if I could just call back later when I wasn’t likely to lose coverage in 3 minutes, and eventually I got the phone number to call.

So, when I got to Portland I called the number, where they immediately put me on hold for 30 minutes. After which they asked me what I was calling about, and when I said I was calling about getting my ADHD screening, they put me on hold for another 15 minutes. Not a great start.

Read more…

ADHD

So, this post about signs of undiagnosed ADHD showed up on one of my fibro communities and so much of it seemed PRETTY FAMILIAR, and I also found out that fibromyalgia and ADHD are highly comorbid, and then I was realizing that I stopped being able to focus on work and Getting Stuff Done when I had to go cold turkey on caffeine when my panic disorder started in 2011, and, wellp.

Read more…

💬 Random reply Notes

In reply to: Random reply

FYI this is a webmention sent as mastodon reply :)

Using Firefox as my primary browser

For a while my browser usage has been Safari as my primary and Firefox as my backup (for the rare site that didn’t work in Safari, usually due to the “modern” web being terrible), mostly because it gave me good integration with the iCloud Keychain as well as a few nice little handoff things (migrating sessions between computers/my phone, autofilling SMS OTP keys, etc.).

However, ever since the most recent Safari update, I’ve been finding it to be incredibly unstable or troublesome in a lot of ways (like entering a URL causing it to not actually load said URL, or feedback just plain being lost), and of course the recent loss of the 1Password 6 extension has made it less pleasant as well. (I have reasons for not wanting to upgrade to 1Password 7, but that’s a whole other rant.) Also, as nice as the iCloud Keychain is, Safari’s password autofill has always had problems on a lot of sites, and the fact I had to run it side-by-side with 1Password to get my passwords available on Windows machines was getting pretty annoying.

So, I decided to actually try Firefox as my full-time browser on macOS, and so far I’m liking it.

Read more…

Stop it with the zero-calorie sweeteners

I love my Sodastream carbonator. But I don’t like how all of its soda syrups have “50% less sugar” by them replacing it with Stevia or sucralose. Yesterday at Target I saw that they had a new line of syrups that claimed to be made of just fruit juice, and I looked at the ingredients, and didn’t see anything problematic, so I bought some.

Just now I made a cup of soda with it, and at the first sip realized that they’d snuck Stevia in. I looked at the ingredients again, and there was at the very end, steviol glycosides – the distilled essence of what makes Stevia Stevia.

So, that’s $10 down the drain, literally.

Read more…