In case you were wondering: why does this lady boost her own messages? Well, sometimes it's for troubleshooting purposes.
Like today for instance: I had my Mastodon account boosting my latest federated Wordpress blog post because I can't seem to follow that account ( @ele@elenarossini.com ) from my GoToSocial. It keeps showing "user not found" in searches.
So sometimes I have to do weird things like boosting or DMing myself 😅
Questa voce è stata modificata (2 mesi fa)
wakest ⁂
Unknown parent • • •Matthias Pfefferle
in reply to wakest ⁂ • • •it is no general issue: acct:matthias@pfefferle.org" target="_blank" rel="noopener noreferrer">pfefferle.org/.well-known/webf…
have you added some extra routes/rules in your nginx or apache config?
Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •nginx / apache config? what config? 🙈🙉🙊 I'm on a shared webhosting plan where I used a one-click Wordpress install. I'm not even sure how to add / configure Nginx.
Considering I added it to my Ghost blog in order to install Varnish cache (which is amazing) I need to look into it.
Please just assume I am a normie who copies and pastes lines of code with success from time to time 😅
Matthias Pfefferle
in reply to Elena Rossini on GoToSocial ⁂ • • •I am sorry 🫣
Have you added something to your .htaccess file? Where do you host your site?
Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •thanks for the help Matthias.
I have very stringent security rules in place with All in One Wordpress Security so maybe it has something to do with that?
Honestly it's NO big deal if I cannot follow my Wordpress account from GoToSocial. I'm just testing things these days before making a big decision 😀
Matthias Pfefferle
in reply to Elena Rossini on GoToSocial ⁂ • • •Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •ok Matthias, you are the only person I would ever disable the security plugin for 😊 I'll do this for the next hour and clear my cache.
For caching I'm using WP Super Cache FYI.
Anyway feel free to look around now that my plugin is disabled. And thank you!
David B. Himself
in reply to Matthias Pfefferle • • •Matthias Pfefferle
in reply to David B. Himself • • •Matthias Pfefferle
in reply to Elena Rossini on GoToSocial ⁂ • • •Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •aw thanks for letting me know Matthias!
The GtS devs are on it too, something about the software being very strict with permissions re: content types.
Anyway I will happily re-enable that plugin now, I'm feeling so exposed 😅
David B. Himself
in reply to Matthias Pfefferle • • •Matthias Pfefferle
in reply to David B. Himself • • •wakest ⁂
in reply to Matthias Pfefferle • • •hmm so @pfefferle I just tried to load a post of yours notiz.blog/2025/03/24/blogtast… in SNAC and it doesn't come up at all even though it comes up in Mastodon. Have you been checking how your webfinger works with many things other then Mastodon in the first place?
Matthias Pfefferle
2025-03-24 13:31:07
Matthias Pfefferle
in reply to wakest ⁂ • • •David B. Himself
in reply to Matthias Pfefferle • • •Yes, I sometimes have this error showing up in the "site health" page.
What does it mean? This site only has one user account. I guess it's blocked by something then, but by what and how to unblock it?
I also noticed that on my other site (liminalweb.site) one user seems federated @David@liminalweb.site whereas the two other ones are not (but the backend tells me they are): @Gator@liminalweb.site and @BigKamo@liminalweb.site
Matthias Pfefferle
in reply to David B. Himself • • •Matthias Pfefferle
in reply to wakest ⁂ • • •can you try to follow @pfefferle@notiz.blog on GtS?
I would assume that this is not a general issue, but something interferes with the WebFinger output on elenas site.
@liaizon
Matthias Pfefferle
in reply to wakest ⁂ • • •Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •Matthias Pfefferle
in reply to Elena Rossini on GoToSocial ⁂ • • •Aslak Raanes
in reply to Matthias Pfefferle • • •snac2
Codeberg.orgMatthias Pfefferle
in reply to Aslak Raanes • • •hmmm... does anyone have a test instance where I can have an account to run some tests?
btw. feditest.org/contrib/results/2…
I think we are pretty standards complient, except of some error codes.
Test Run Session 81/84 (feditest-run-20241229-191246) | FediTest
feditest.orgAslak Raanes
in reply to Matthias Pfefferle • • •Welcome to snac.bsd.cafe
snac.bsd.cafewakest ⁂
in reply to Matthias Pfefferle • • •Elena Rossini on GoToSocial ⁂
in reply to wakest ⁂ • • •wakest
in reply to wakest ⁂ • • •Matthias Pfefferle
in reply to wakest • • •the lookup of posts is done by content negotiation and webfinger is it's own thing using the .well-known endpoint.
to look up a post url, you would not need webfinger at all.
Matthias Pfefferle
in reply to Matthias Pfefferle • • •Matthias Pfefferle
in reply to wakest • • •ok, I found the issue!
that is a tricky one!
SNAC seems to check if the URL you try to look up is a post or a profile url. And they test that using WebFinger. If WebFinger returns JSON it is a profile, otherwise it might be a post.
BUUTTT: I have enabled WebFinger also for my posts, so SNAC seems to think my posts are broken profiles!
webfinger.net/lookup/?resource…
THAT IS INTERESTING!
if I deactivate WebFinger for my posts it works...
WebFinger
webfinger.netMatthias Pfefferle
in reply to Aslak Raanes • • •mastodon.social/@pfefferle/114…
Matthias Pfefferle
2025-07-08 16:04:47
wakest ⁂
in reply to Matthias Pfefferle • • •Matthias Pfefferle
in reply to wakest ⁂ • • •Improve WebFinger lookup
Codeberg.orgThe Real Grunfink
in reply to wakest ⁂ • • •Hi. I've pushed some code to fix this. It seems to work, but code must be considered experimental.
CC: @pfefferle@mastodon.social @wake_st@snac.rohrmoser.name @elena@aseachange.com @pfefferle@notiz.blog
Matthias Pfefferle
in reply to The Real Grunfink • • •that is why I LOVE the #fediverse!!!
this is awesome @grunfink !!!
wakest ⁂
Unknown parent • • •The Real Grunfink
in reply to Matthias Pfefferle • • •Thank you very much for your help!
CC: @liaizon@wake.st @wake_st@snac.rohrmoser.name @elena@aseachange.com @pfefferle@notiz.blog
Elena Rossini on GoToSocial ⁂
in reply to Matthias Pfefferle • • •such a fast solution wow! 🏆✨ congrats all
@liaizon @wake_st @pfefferle @grunfink
Teapot Ben
in reply to Elena Rossini on GoToSocial ⁂ • • •I wonder how long it will be until my timeline is nearly 100% Elena accounts? 😂
You've still got a long way to go to catch up with @catsalad though who I'm convinced is responsible for at least half the accounts in the entire Fediverse!
David B. Himself
in reply to Matthias Pfefferle • • •Hi Matthias.
I found the source of the issue.
There's a checkable option that blocks profiles:
"Prevent discovery of usernames through '/?author=N' scans, the oEmbed API, the WordPress REST API, and WordPress XML Sitemaps"
Wordfence advises against unchecking it:
wordfence.com/help/firewall/br…
What do you think?
Matthias Pfefferle
in reply to David B. Himself • • •I understand why they might want to hide the IDs, but WordPress Core uses them extensively, for example, in its API endpoints.
To me, this feels more like 'security through obscurity' and I'd prefer to focus on strong passwords and two-factor authentication.