Anonymous or Pseudonymous OAuth authorization

Open
#73 12 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Quiet

Research direction

No implementation files or tests are named. Start by separating the anonymous and pseudonymous OAuth user stories and clarifying the required ActivityPub API behavior for each. Done means the project has an agreed design or specification that defines how an API client can interact without learning the user's real actor identity.

Written by the indexing model from the issue text.

Description

"As an ActivityPub social API user, I want to authorize an API client without sharing my ActivityPub ID, so that it can't identify me."

"As an ActivityPub social API user, I want to share a pseudonymous ActivityPub ID when I authorize an API client, so that it can interact with my account but not know what my real identity is."

These are two slightly different user stories with similar intent -- hiding the real actor ID from the app.

Dominant language
HTML
Stars
33
Forks
2
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from swicg/activitypub-api

All issues in swicg/activitypub-api

Similar issues

More Backend & API Design issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.