Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"If you trust this link, click it to continue." breaks embeds, adds friction #30327

Closed
jernejs opened this issue May 16, 2024 · 1 comment
Closed
Labels
area/web interface Related to the Mastodon web interface status/wontfix This will not be worked on

Comments

@jernejs
Copy link

jernejs commented May 16, 2024

Steps to reproduce the problem

  1. Copy a link to post that's on another instance (eg. https://mastodon.social/@vjousse@mamot.fr/112446650777348688 )
  2. Paste the link in Discord

Expected behaviour

The post embeds in Discord, clicking the link opens the post

Actual behaviour

Post does not embed, clicking the link shows a completely useless warning

Detailed description

Clicking the above link will show the following page:
image

I don't see the point of this warning at all – it's only shown if you're not logged in in the directly linked instance, and I've only ever seen the warning shown when redirecting to other Fediverse instances. The warning probably also breaks embeds on other services, which used to work in the past.

Mastodon instance

mastodon.social, infosec.exchange, others.

Mastodon version

v4.3.0-nightly.2024-05-13, v4.3.0-alpha.3+glitch

Browser name and version

Multiple browsers (Vivaldi 6.7.3329.19, Firefox 126.0)

Operating system

Windows 11 22631.3593

Technical details

No response

@jernejs jernejs added area/web interface Related to the Mastodon web interface bug Something isn't working status/to triage This issue needs to be triaged labels May 16, 2024
@vmstan vmstan added status/wontfix This will not be worked on and removed bug Something isn't working status/to triage This issue needs to be triaged labels May 16, 2024
@ThisIsMissEm
Copy link
Contributor

These "roadblocks" are an important aspect of trust & safety, and were recently added to ensure users weren't phished or otherwise manipulated by an open redirect, which was previously the case.

You can read more about the history here: #27792

An improvement we could add is a HTTP Link rel=canonical to these redirects that automated software can parse in a standardised way to discover the canonical link instead of the redirect & then embed that link instead of the instance's cached URI for that post

@vmstan vmstan closed this as not planned Won't fix, can't repro, duplicate, stale May 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/web interface Related to the Mastodon web interface status/wontfix This will not be worked on
Projects
None yet
Development

No branches or pull requests

3 participants