What is Nostr?
Alex /
npub1q3s…d26p
2024-10-02 17:59:19

Alex on Nostr: Mastodon's Web Push API sends back your own OAuth access token on every single ...

Mastodon's Web Push API sends back your own OAuth access token on every single push... that's insanity.

>The access_token is included because that's the only way to make API requests from the service worker in JS.

(Narrator: it isn't)

https://github.com/mastodon/mastodon/pull/7521
Author Public Key
npub1q3sle0kvfsehgsuexttt3ugjd8xdklxfwwkh559wxckmzddywnws6cd26p