Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Current recommendation for public inboxes can lead to spam #56

Closed
elf-pavlik opened this issue Oct 8, 2022 · 2 comments · Fixed by #69
Closed

Current recommendation for public inboxes can lead to spam #56

elf-pavlik opened this issue Oct 8, 2022 · 2 comments · Fixed by #69
Assignees

Comments

@elf-pavlik
Copy link
Member

the issue for tackling the use of public inboxes more broadly: solid/specification#464

https://solid.github.io/webid-profile/#inbox

If no inbox is found a Pod Management App MAY create an inbox by creating a container. In that case, the app SHOULD also create access controls for the container that give read and write permissions to the WebID owner and append but not read or write permissions to everyone else.

I see this as a very risky suggestion. If the pod management app actually does, it can make storage vulnerable to spam. I think we should handle this issue on the spec level since in SAI we also make very minimal use of a specialized public inbox and it will require special considerations to prevent spam.

@csarven
Copy link
Member

csarven commented Oct 9, 2022

Misleading title and issue littering :(

Solid Protocol and WebID Profile do not require a public inbox. It is the specs that require a public inbox should include additional requirements and considerations to prevent spam.

It may be simpler to leave out the optional application behaviour to setting access permissions for an inbox. It does not impact interoperability given that another application (controlled by a user) can rightly set their own preferred access permissions.

@elf-pavlik
Copy link
Member Author

in SAI we also make very minimal use of a specialized public inbox and it will require special considerations to prevent spam.

I actually went ahead and proposed removing any use of public inboxes from SAI solid/data-interoperability-panel#280

Misleading title and issue littering :(

I quoted the relevant part of the spec, which part do you consider misleading?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants