Notices where this attachment appears
-
@i @Moon @graf @sjw That is a URL, not a username, and when you say "real", you do recall the caveat I gave that with /full/, I was essentially hijacking a dev endpoint, don't you? I mean, do you make shit up just to have something to complain about, or do you actually not pay any attention? It can't be the latter, because you'd have to have looked at the header to extract that ID and then constructed a URL for it, because that ID is safely tucked out of view for exactly the reasons mentioned.
It's not any worse than https://declin.eu/media/091d39ef8402b0d74232ba9c96a85448ab1dc4baad8452568d532b56032a5869.png or even https://declin.eu/objects/2d39c59a-1168-47a4-8407-6f3a71fc497e . Those are real Pleroma IDs supplied by your server! Not remotely out of view, those are in the URL.
Incidentally, that URL works if you hit any of the following:
https://screamshitter.club/rvl/full/0edee99513019215adb2871d7b076edcc4c50c026b721a594a40f4802434551b
http://zeke.freespeechextremist.com/rvl/full/0edee99513019215adb2871d7b076edcc4c50c026b721a594a40f4802434551b
http://u3z4meyhhsemqnsg6pv4zo6cylacyekxagmc2eklu2opns2cfqaokaid.onion/rvl/full/0edee99513019215adb2871d7b076edcc4c50c026b721a594a40f4802434551b (This one is served by Plan 9!)
https://freespeechextremist.com/rvl/full/0edee99513019215adb2871d7b076edcc4c50c026b721a594a40f4802434551b
As noted previously, if you do that with arbitrary hosts, the blocks will take a bit of time to propagate and they'll 404; refresh a couple of times. (I'll probably make the /rvl/full/$id 404 for FSE anyway. There are enough debugging nodes to not have to worry about keeping them enabled on FSE, and that URL is only used to debug, the blocks don't propagate by reloading the entire tree, they propagate one block at a time.)