this post was submitted on 27 Jul 2023
85 points (94.7% liked)

Fediverse

29028 readers
1902 users here now

A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, KBin, etc).

If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!

Rules

Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration), Search Lemmy

founded 2 years ago
MODERATORS
 

Is there a reason why all the services, that use the ActivityPub protocol don't have a unified API?

None of the mastodon apps allow me to log in with a lemmy/kbin account.

Also none of the lemmy apps allow me to log in with a kbin account.

Even though kbin has both mastodon (microblogging) and lemmy (threads, communities) functionality.

Also, Pixelfed recently introduced "login with Mastodon", but all it really does is just create a new user on it's instance and copy over the mastodon followers and profile info.

Why can't we just have one account to rule them all?

you are viewing a single comment's thread
view the rest of the comments
[–] adonis@kbin.social 2 points 2 years ago* (last edited 2 years ago) (3 children)

logging in with one account into another instance

I'd imagine a OAuth/JWT-like workflow, where pixelfed.social can ask a kbin-API whether my user exists on kbin.social.

If it does, I should be able to post images on the pixelfed app that show my username as @adonis.

Edit: by @adonis, I mean adonis @ kbin.social

[–] Crul@lemmy.world 6 points 2 years ago* (last edited 2 years ago) (1 children)

If it does, I should be able to post images on the pixelfed app that show my username as @adonis.

It cannot work as stated because there could be another @adonis accounts in other instances and the only way to prevent that would be to centralize all the signups which goes against the whole idea of decentralization. That's why the user must be @adonis1@kbin.whatever as it is shown now.

Regarding the OAuth/JWT, again... not an expert, but what I understand is that that kind of integration is much stronger than the current system. AFAIK, it could work as you say, but that would make things much more complex for the servers; you usually provide OAuth authentication for a few services, I don't know how well that scales with ... hundreds / thousands (?) of authentication provders. But, who knows, maybe in the future it's implemented in one way or another.

We should take into account that this technology is fairly new and people are still building on it.

[–] adonis@kbin.social 1 points 2 years ago* (last edited 2 years ago)

Sorry but the autoformatting miscommunicated my statement... by @adonis I meant adonis @ kbin.social.

And the domain is always part of the actual userhandle. Hence, there can only be one.

Regarding OAuth/JWT, these aren't new concepts. They've been around for while, if not decades.