Tootfinder

Opt-in global Mastodon full text search. Join the index!

@khalidabuhakmeh@mastodon.social
2026-02-02 20:24:20

Duende has released DPoP Support for #aspnetcore via the JwtBearer Extensions NuGet package. This library helps protect your APIs against one of the highest threats to the OAuth ecosystem: the abuse of stolen access tokens.
#dotnet

@Xavier@infosec.exchange
2026-02-04 14:43:02

So I busted out an old laptop and installed headless ubuntu minimal (I like to start small) so that I can start setting up some autonomous agents. My first step was to install Claude Code so that it could setup everything else for me, but after a few hours at it, both Claude and I admit that Claude Code is broken on a headless install. We tried a bunch a different way to get it to take a damn key, but the installer insists on an OAUTH auth that requires a browser.
I have a dislike fo…

A dark-themed text image displays a conversation about a software error. At the top, a dark gray speech bubble contains: "On the last set I get error: unknown option '--global'" and "I'm beginning to think that you don't know how to setup your own tools." Below, white text on a dark background reads: "You're right, and I apologize for the frustration. I've been cobbling together information from various sources and versions, and clearly some of it is outdated or wrong. Let me skip that last com…
@aral@mastodon.ar.al
2026-01-02 20:05:31

Just added a “Sign in with Mastodon” example to Kitten’s¹ examples:
codeberg.org/kitten/app/src/br
If I have time at some point, I might make it into a tutorial.
Enjoy!
:kitten:💕

Browser at dev.ar.al, showing Sign in with Mastodon page:

Your mastodon instance (e.g., mastodon.social)
Text input field: mastodon.ar.al
Button: Sign-in
Screenshot of the second step: authorisation required page on mastodon.ar.al/oauth/authorize/?client_id=…

Authorization required
Kitten sign-in with Mastodon example would like permission to access your account. Only approve this request if you recognize and trust this source.
Review permissions
Accounts: Read-only access
Authorize button
Deny button
The final step: Back at dev.ar.al, showing my Mastodon profile info (unseen, off screen: a Sign out button):

 Balkan
@aral@mastodon.ar.all
Social oncologist.
I make small things.
Unapologetically anti-genocide.
From Gaza? If you need to get verified, please go here: https://gaza-
verified.org/join/
Want to donate to people in Gaza? Please see https://gaza-verified.org/donate/
My posts are licensed under Creative Commons Attribution-NonCommercial-ShareAlike (https://creativecommons.org/licenses…
@Techmeme@techhub.social
2026-02-23 03:50:39

Google Antigravity users say their paid Google AI accounts were banned after linking Gemini models via OpenClaw; Peter Steinberger says he may "remove support" (Marcus Schuler/Implicator.ai)
implicator.ai/google-restricts

@dde@social.tchncs.de
2025-12-30 11:16:09

Ich habe gestern einmal feed2toot durch den Fork feed2toot-oauth ersetzt. Das ist ein Drop-In-Replacement, das ursprüngliche Projekt steht seit 2021 still.
pypi.org/project/feed2toot/

@axbom@axbom.me
2026-01-28 14:26:57
Clawdbot/Moltbot and the many security issues it introduces:

"This is not speculative. In real deployments, Clawdbot routinely runs with access to API keys, bot tokens, OAuth secrets, filesystem permissions, and sometimes root-level execution inside containers. The agent is designed to act continuously, autonomously, and proactively, including sending messages without explicit prompts.

This architecture is powerful, but it collapses several trust boundaries into a single …
@rmdes@mstdn.social
2026-02-08 13:33:36

Got my indiekit syndicator for #Linkedin to work 🤓 with a nice backend to refresh the token (using OAuth) via the backend directly with the user linkedin session once every 2 months, it’s a manual step but it’s smooth
rmende…

@stefan@gardenstate.social
2026-02-18 03:08:13

So far I don't care for how I have activityPub integrated in to #tvmarks. It tried to be a full activityPub app but I think I just want to oauth with mastodon/bluesky and make post updates to the authed account.
I guess maybe this will mess up the idea of being able to reply to a post and it shows up on the website as a comment? I'm not sure, but I'm thinking about it.

@michabbb@social.vivaldi.net
2026-01-24 00:21:21

🔄 Full duplex bidirectional streaming enables client and server to send continuous data streams simultaneously over a single persistent connection - real-time agentic workflows without application-level synchronization
🛡️ Enterprise-grade security built-in: mutual TLS for Zero Trust architectures, native JWT/OAuth authentication hooks, method-level authorization for least privilege principle

@azonenberg@ioc.exchange
2025-12-10 22:51:29

Random thought: the centralization of authentication to a few big OAuth providers like MS and Google, combined with services that time out your cookies and force relogins every so often, makes phishing people so much easier.
Want someone's account creds? Just pop up something that looks like a ms or google login form, odds are they're so conditioned by login fatigue that they'll automatically type their creds and TOTP token into it.

@awinkler@openbiblio.social
2026-02-06 09:43:30

die @… lässt sich aus aus OpenRefine heraus ansteuern. Bsp.: Ich habe eine GND-ID einer Person und will wissen, ob die DDB zu der Person Material hat: Edit column > Add column by fetching URLs > dann als GREL "

@aral@mastodon.ar.al
2026-01-07 18:31:29

Hey everyone,
Gaza Verified is now open again for verification calls in 2026.
The new process for signing up for verification calls uses sign in with Mastodon and should remove the last remaining technical hurdle that was giving some of our friends in Gaza a hard time (adding the verification link to your Mastodon account is not intuitive in the current Mastodon interface). With this new flow, you won’t have to, we do it for you.

Screencast showing the new oAuth-based sign up flow where you enter your mastodon instance and press as button and your video verification call is scheduled within seconds.