• Hi Matthias,

    I updated to 1.0 and have been testing since then on my 2 blogs.

    The main one (WWW) seems broken at multiple levels (not specifically with AP – but the css for AP in admin doesn’t load…), still investigating…

    On the AMF one, I tried to send a comment from Mastodon to a post published 2 days ago. I use the plugin “All In One WP Security” as firewall, antispam etc.

    The only way to receive a message is to disable AIOWPS completely.
    I tried changing various options, step by step, from disabling 5G/6G Blacklist firewall protections to downgrading the firewall, etc. But nothing works, except totally disabling the plugin, although I probably might have missed an option somewhere to test.
    When disabled, the comment arrives almost immediately (the first time someone sends a comment, it is marked as spam).

    FYI, I tried a direct message sent to the blog, but it never arrived…

    Choosing between security and interoperability is a tough choice ??

    PS: when testing a few weeks ago, the Fediverse Embeds WordPress plugin by Stefan Bohacek, I already had to disable a few options such as against “malicious queries via XSS” and “bad character matches from XSS” from this same plugin…

    Sincerely
    DJM

    The page I need help with: [log in to see the link]

Viewing 3 replies - 1 through 3 (of 3 total)
  • Thread Starter cybeardjm

    (@didierjm)

    Hi, I did multiple tests with AP 1.0 & AIOWPS to check what works or not.

    Context:
    – WP 6.3.1
    – AP 1.0
    – AIOWPS 5.2.4

    I created a specific WP user for these tests: https://amf.didiermary.fr/wp-json/activitypub/1.0/users/9/outbox

    1 – AIOWPS on – default configuration (score = 330/575)

    Post appears in WP-JSON = yes
    Post appears on Mastodon = yes
    Edit appears on Mastodon = yes
    Comment on Mastodon appears on WP = no
    Post removed from Mastodon after deletion = no

    2 – AIOWPS on – Firewall downgraded

    Post appears in WP-JSON = yes
    Post appears on Mastodon = no

    2 – AIOWPS off (plugin deactivated)

    Post appears in WP-JSON = yes
    Post appears on Mastodon = yes
    Edit appears on Mastodon = yes
    Comment on Mastodon appears on WP = yes
    Post removed from Mastodon after deletion = no

    Although, during these tests, no post ever appeared on FireFish, this worked previously.
    Never got any post on Pixelfed…

    Sincerely
    DJM

    Thread Starter cybeardjm

    (@didierjm)

    More info: the fact that posts are not deleted on Mastodon or FireFish, although they have been trashed in WordPress and don’t appear in the WP-JSON Outbox is a “problem”, as this creates ghost posts that generate 404 errors when visited by other instances’s bots…

    Thread Starter cybeardjm

    (@didierjm)

    Tested publishing new posts this morning: although they appear in the outbox for user 1 https://amf.didiermary.fr/wp-json/activitypub/1.0/users/1/outbox – they don’t appear on Mastodon 4.2.0

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Comments blocked by Firewall’ is closed to new replies.