What is Nostr?
Alex Gleason /
npub108p…yev6
2023-05-26 19:37:05
in reply to nevent1q…mazl

Alex Gleason on Nostr: Nope. It hits /api/v1/accounts/lookup where the username is the OAuth token encoded ...

Nope. It hits /api/v1/accounts/lookup where the username is the OAuth token encoded to look like a Nostr pubkey @ mostr.fedirelay.xyz. This causes your server to make a federation request where they simply monitor the logs and pull the token out of the username... absolutely nuts. Read the code. https://i.poastcdn.org/4ed28ef4fa5e18bfa5c1f75a5c1cc759f7b718c0b600e7e2fcc6d0cdb0215f15.txt
Author Public Key
npub108pv4cg5ag52nq082kd5leu9ffrn2gdg6g4xdwatn73y36uzplmq9uyev6