diff --git a/fep/ef61/fep-ef61.md b/fep/ef61/fep-ef61.md index 99e0a32..67c75ee 100644 --- a/fep/ef61/fep-ef61.md +++ b/fep/ef61/fep-ef61.md @@ -1,6 +1,6 @@ --- slug: "ef61" -authors: silverpill +authors: silverpill <@silverpill@mitra.social> status: DRAFT dateReceived: 2023-12-06 discussionsTo: https://codeberg.org/fediverse/fep/issues/209 @@ -23,6 +23,12 @@ The proposed solution should satisfy the following constraints: - The solution should be compatible with existing and emerging decentralized identity and storage systems. - The solution should be transport-agnostic. +## History + +[Streams](https://codeberg.org/streams/streams) implements [Nomadic Identity](https://codeberg.org/streams/streams/src/commit/11f5174fdd3dfcd8714974f93d8b8fc50378a193/FEDERATION.md?display=source#L54-L59) mechanism, that makes identity independent from a server. Nomadic accounts are currently not supported by ActivityPub but are available via the [Nomad protocol](https://codeberg.org/streams/streams/src/commit/11f5174fdd3dfcd8714974f93d8b8fc50378a193/spec/Nomad/Home.md). + +[Decentralized Identifiers (DIDs) v1.0][DID] specification suggests that DIDs might be assigned to web resources in section [B.8 Assigning DIDs to existing web resources](https://www.w3.org/TR/did-core/#assigning-dids-to-existing-web-resources). + ## Requirements The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC-2119][RFC-2119]. @@ -51,19 +57,19 @@ GET https://social.example/.well-known/apresolver/did:ap:key:z6MkrJVnaZkeFzdQyMZ ActivityPub objects identified by `did:ap:key` URLs can be stored on multiple servers simultaneously. -If object identified by `did:ap:key` URL is stored on the server, it MUST return a response with status `200 OK` containing the requested object. The response MUST have a `Link` header with `rel` parameter set to `canonical` and containing an HTTP(S) URL corresponding to a requested DID URL. +If object identified by `did:ap:key` URL is stored on the server, it MUST return a response with status `200 OK` containing the requested object. The response MUST have a `Link` header with `rel` parameter set to `alternate` and containing an HTTP(S) URL corresponding to a requested DID URL. Example: ``` -Link: ; rel="canonical" +Link: ; rel="alternate" ``` If object identified by `did:ap:key` URL is not stored on a server, it MUST return `404 Not Found`. If object is not public, `/.well-known/apresolver` MUST return `404 Not Found` unless the request has a HTTP signature and the signer is allowed to view the object. -After retrieving an object, the client MUST verify its [FEP-8b32][FEP-8b32] integrity proof. +After retrieving an object, the client MUST verify its [FEP-8b32][FEP-8b32] integrity proof. The value of `verificationMethod` property of the proof MUST match the DID component of the DID URL. ## Portable actors @@ -127,6 +133,16 @@ ActivityPub clients MUST follow [FEP-ae97][FEP-ae97] to publish activities. A cl Upon receiving an activity in actor's inbox, server SHOULD forward it to inboxes located on other servers where actor's data is stored. +### Discovering locations + +(This section is non-normative.) + +This proposal makes use of the `aliases` property, but the following alternatives are being considered: + +- `sameAs` +- `alsoKnownAs` (used for account migrations, so the usage of this property may cause issues) +- `url` (with `alternate` [relation type](https://html.spec.whatwg.org/multipage/links.html#linkTypes)) + ## Portable objects Objects identified by `did:ap:key` URLs MUST contain [FEP-8b32][FEP-8b32] integrity proof. @@ -166,6 +182,16 @@ Example: } ``` +## Compatibility + +(This section is non-normative.) + +DID URLs are not compatible with existing [ActivityPub][ActivityPub] implementations. The following workarounds are being considered: + +1. Use HTTP URL of a resolver query instead of an actual DID URL. Implementations that support DID URLs should be able to extract the DID URL from the HTTP URL and process the object accordingly. +2. Use regular HTTP URLs but include a link to a DID URL in the `url` (with `canonical` relation type, as proposed in [FEP-fffd][FEP-fffd]). For pointers to other objects such as `inReplyTo` property, an embedded object with `url` property can be used instead of a plain URL. +3. Alter object ID depending on the capabilities of the peer which can be reported by [NodeInfo][NodeInfo] or some other mechanism. + ## References - Christine Lemmer Webber, Jessica Tallon, [ActivityPub][ActivityPub], 2018 @@ -174,6 +200,8 @@ Example: - Manu Sporny, Dave Longley, Markus Sabadello, Drummond Reed, Orie Steele, Christopher Allen, [Decentralized Identifiers (DIDs) v1.0][DID], 2022 - silverpill, [FEP-8b32: Object Integrity Proofs][FEP-8b32], 2022 - silverpill, [FEP-ae97: Client-side activity signing][FEP-ae97], 2023 +- Adam R. Nelson, [FEP-fffd: Proxy Objects][FEP-fffd], 2023 +- Jonne Haß, [NodeInfo][NodeInfo], 2014 [ActivityPub]: https://www.w3.org/TR/activitypub/ [RFC-2119]: https://tools.ietf.org/html/rfc2119.html @@ -182,6 +210,8 @@ Example: [DID URLs]: https://www.w3.org/TR/did-core/#did-url-syntax [FEP-8b32]: https://codeberg.org/fediverse/fep/src/branch/main/fep/8b32/fep-8b32.md [FEP-ae97]: https://codeberg.org/fediverse/fep/src/branch/main/fep/ae97/fep-ae97.md +[FEP-fffd]: https://codeberg.org/fediverse/fep/src/branch/main/fep/fffd/fep-fffd.md +[NodeInfo]: https://nodeinfo.diaspora.software/ ## Copyright