@pecet@f3d1.eu avatar pecet , to random
@dan@danq.me avatar dan , to Testing

Highlight of my workday was debugging an issue that turned out to be nothing like what the reporter had diagnosed.

The report suggested that our system was having problems parsing URLs with colons in the pathname, suggesting perhaps an encoding issue. It wasn't until I took a deep dive into the logs that I realised that this was a secondary characteristic of many URLs found in customers' SharePoint installations. And many of those URLs get redirected. And SharePoint often uses relative URLs when it sends redirections. And it turned out that our systems' redirect handler... wasn't correctly handling relative URLs.

It all turned into a hundred line automated test to mock SharePoint and demonstrate the problem... followed by a tiny two-line fix to the actual code. And probably the most-satisfying part of my workday!

Via: 🔗 https://danq.me/2026/01/28/mocking-sharepoint/

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random

Ayder – HTTP-native durable event log written in C (curl as client)

https://github.com/A1darbek/ayder

-native #C -source

@mgorny@pol.social avatar mgorny , to random Polish

You wouldn't status code a .

ALT
@heisedeveloper@social.heise.de avatar heisedeveloper , to random German

Verbindungsabbrüche bei heise online durch Cookies – eine Spurensuche

Die Webentwicklung von heise online berichtet von einer interessanten Suche nach einem Bug, dessen Ursache am Ende ganz simpel war.

https://www.heise.de/blog/Verbindungsabbrueche-bei-heise-online-durch-Cookies-eine-Spurensuche-11114731.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

How feasible would it be to host Mastodon, Pixelfed, Lemmy, Friendica, or Matrix over Tor/I2P?

Given the US recently made a bid to fast-track multiple censorship bills, KOSA included, and is also trying to kill Section 230 now, which will pose an existential threat to Fediverse instances hosted over the clearnet, how feasible would it be to host said instances over Tor/I2P?

ViatorOmnium , to Fediverse in How feasible would it be to host Mastodon, Pixelfed, Lemmy, Friendica, or Matrix over Tor/I2P?

One example is HTTP signatures. Servers sign their payloads and receiving servers should validate not just the hash but ensure the payload is not too old. Mastodon allows for a twelve hour difference (https://docs.joinmastodon.org/spec/security/#http-signatures) but other software might be stricter for security reasons. The a bunch of things like webfinger were designed around public dns and public key chains A mastodon server running on the open internet and/or expecting public keychain HTTPs will not be able to federate with something running in tor.

You could cut enough corners to make something that federates inside tor, but at that point it's better to design something around tor's features.

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@srxl@fedi.foxgirl.engineering avatar srxl , to random

​:neofox_thinking:​ http/1.1 servers can opt to send neither Content-Length nor Transfer-Encoding in a response, in which case a client should continue to read the response until the connection is closed. how do clients prevent themselves from getting DoSed by a malicious server that just sends an infinite stream their way, or something like that?

@astro@c3d2.social avatar astro , to random

Did the relay stop working for anyone who upgraded to Mastodon 4.5? If that's the case I need to find a Rust implementation of RFC9421 ASAP: https://docs.joinmastodon.org/spec/security/#http-message-signatures

@linuxuserspace@mastodon.social avatar linuxuserspace , to random

Today in User Space
🥾We'll need to resize the /boot
🤖Stuff an into
🦊Handle our profiles in
🕸️Let go of our sites
⚙️Inject malice into prompts
☄️And recap the Cosmic Desktop


https://youtu.be/RWGO3ZkBMQc

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@reiver@mastodon.social avatar reiver , to random

Is the HTTP protocol now largely a Google protocol?

(Possibility rubber-stamped by certain a specification organization.)

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@blindcoder@toot.berlin avatar blindcoder , to random

Recently seen a rant about how FOSS devs should stop naming things because "eks em pee pee" is a terrible name.

I guess "eidj titty pee" is out as well then.

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random

Sping – A HTTP/TCP Latency Tool That's Easy on the Eye

https://dseltzer.gitlab.io/sping/docs/

@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@blainsmith@snac.rblgk.sh avatar blainsmith , to random
@blainsmith@snac.rblgk.sh avatar blainsmith , (edited ) to random

Typically HTTP APIs speak JSON or XML, but what are some other human-readable formats folks have seen that was useful? How about text/plain and sending INI, TOML, RESP etc. for some simpler and smaller request/responses that are still self-describing? These seems nicer for languages that don't have good JSON/XML support or if they do their libraries are cumbersome and awkward to use.

@blainsmith@snac.rblgk.sh avatar blainsmith , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random
@h4ckernews@mastodon.social avatar h4ckernews Bot , to random