@[email protected] Thanks. I think my preliminary notes are now complete.
One thing irks me though. AP works by "Everything is visible", and OCAP (now ZCAP?) wants to remove actions by adding a protocol? That seems naive to me, and "We'll just defederate non-compliant servers" is a recipe for data leaks. Is there no approach based on "We'll just encrypt everything"?
@[email protected] Thanks; Looks like I'll either dig into Epicyon, or roll my own.
As far as delivery and routing is concerned, are there some standards / common practices? Should I take care to deduplicate messages that reach me over multiple routes, or may that not happen? What's the best practice on limiting object visibility? Are there supplementary protocols besides OAuth2 that I really should provide?
@[email protected] Thanks. I'm indeed only starting to figure out what I want, and it does approach the ideal server you described. I start the server, it federates with other servers, maintains its corner of the social graph, allows sufficiently authenticated clients to do their thing on it. All social media functionality beyond that would be implemented as Applications.
So, I went through the C2S/S2S specs, I'm brushing up on Flask, I guess the world still needs such a server?
@onf According to https://de.wikipedia.org/wiki/Doom, from 1994 to 2011 they were classified as harmful to the youth by the BPjS, and no advertisement could be made for it.
Wolfenstein 3D however... From 1994 to be confiscated for its use of symbols of yadda yadda yadda. Until September 2019. I guess that answers the question.