Should Fediverse Web apps show remote content to unauthenticated users?
-
@evan No (not by default to not implicate unsuspecting self-hosters with legal issues of the third-party content served through their site), but if the admin wants to offer such a service to the public internet they should have easy options to enable it.
-
@evan Yes but only because I can't think of a reason NOT to
@countablenewt @evan
Legal reasons instantly come to my mind. If you serve content through your domain you are initially responsible for it in many jurisdictions. And you really don't want your site serving CSAM... -
@evan I would say no, if I'm understanding correctly. The browser should load b.example's content from b.example, not a copy from a.example . I'm mostly concerned about privacy here.
If a post or profile is *clearly* meant to be fully public to the world (and ideally it's hard for an author to do this by mistake), then I guess it's meant to be shared around, so sure, why not serve copies. Depending on the use case, there could be advantages to that.
-
@evan No...but..
By default no.
Would prefer if this is user choice.
(in the Time of Scrapers, it gets even more complex than that tho)
-
@evan define `unauthenticated`
-
@evan define `unauthenticated`
-
@evan besides what appears to be smart arse comments (apologies if wrong.) I say no, due to privacy.
If something is completely public then it's okay the user has chosen to make it public but if anything is not public it should require at the very least an account to view if it is semi-public (only users of the platform can view)
Ideally it would be something the user controls.
-
For example, you point your browser at a.example. You are not logged in.
You navigate to a list of a local user's followers at a.example/user1/followers .
If you click on a profile in that list, it loads a.example/remote/user2@b.example , a profile page for a remote user.
If you click on an image posted by that remote user, it loads a.example/remote/b.example/image/33 , showing the remote image and all comments on it.
If this is not an interesting question to you, feel free to skip it!
Thanks to everyone who replied! I am a "yes, but...".
Yes, but you should clearly identify it as remote content or a remote profile.
People on here freak out sometimes when they see remote profiles or remote content on a Fediverse-enabled server. They say it has "shadow profiles" or "scraped content."
Clearly identifying that it comes from the Fediverse can help with this a lot.