hey all

friendly reminder that all versions of mastodon before 3.0 allow ANYONE to pull ANY of the public timelines via an API call

mastodon 3.0 and up ALSO allows anyone to do this if you have the timeline preview turned on

this is important because it means that instances you have blocked can still access all of your site's public posts

making the API require authentication for all public timeline requests is an easy code patch:


That reminds me

Since I updated mastodon from 2.6 to 2.9, none of the pre-upgrade toots have shown up in hashtags. Is there something I can do to fix that, like run a necessary indexing task retroactively or something?


Toot Planet

The Planet is a small, unrestrictive community, and a customized Mastodon server. We have certain features that don't exist on most mastodon servers, such as being able to post to only other members of this server.

We welcome anyone who wants to come join and whatever language you speak! If you're a creative type, queer, a nerdy enthusiast of Something, you'll definitely feel right at home, but we're proud to be a friendly and welcoming community.

Toot Planet does not keep local image archives more than a year after posting. Don't use social media as a media archive!