@helge AFAIK it was fixed in the latest Sharkey release, but not yet in Misskey.
>One would need a specification containing validation rules for that
This is the kind of stuff FEP-fe34 should cover. url doesn't point to an ActivityPub object, so in this case authorization check is not needed. Therefore, object and its url may have different origins.