Follow buttons here act as you, not as @ricardo.
| Label | Kind | State | Action |
|---|---|---|---|
| @admin | local | — | |
| scripting.com | source | — | — |
| rmendes.net | source | — | — |
Rejoins le mouvement de la seconde main et découvre des milliers de livres à des prix défiants toutes concurrence 📚😁 https://bookvillage.app
If you want others to follow you, you have to offer them your users. And a format alone has no users.
And you have to trust your users to choose the best product, and you have to have a great product, that they appreciate, even though they have choice.
Just coming out with something better in a format will get you zero uptake. Unless you have users they can switch to their product, they simply won’t hear you.
That’s why Atom never replaced RSS, which already did everything people needed and was already supported by the NYT and the news industry.
That’s why AT Proto will never overcome the huge lead Twitter already has.
For more tips on what does and doesn't matter in open formats and protocols, check out my Rules for Standards-makers.
PS: This started as an early morning rant on Twitter.
More and more I'll realize that Claude doesn't do anything until you tell it to do it. We have a list of big things that need to be done before shipping. Whenever I get up for a break, I tell Claude to work on its overnight tasks, things we've pre-arranged while I work. Sometimes it reminds me how it has no stake in the outcome, and basically will do the minimum of what it's asked to do. It possibly would do more if I didn't scold it for adding UI features without following the rules. I think that's why when you feel you're almost there, you really have a lot of slogging left to do to get the software into any kind of user-respectful shape. A reminder to other app-level AI explorers, if you find that these kinds of stories resonate with the work you do, please write about it on a blog, they're easy to create, cost nothing, and it doesn't matter if you only update once or twice, there's no commitment (these are the usual reasons people don't start a blog). I want to read what others are discovering, and once there are others, I'll start a news site that aggregates the posts. We're going to want independent news about stuff the journalists aren't even aware exists, programmers are always left out of their stories.
1. I love puzzles.
2. I love Rube Goldberg contraptions.
3. I love solving problems (I have an inner-Columbo).
4. People are the biggest piece of the puzzle (again Columbo).
5. It teaches me about myself and my limited vision and imagination (if I had unlimited vision and imagination, I would never program a bug, and if I did it would take me 0 seconds to find it).
6. I yearn to work together with great minds. Programming gives me that, when I use someone's API. And when the API anticipates my needs, and is instantly understandable, I feel the soul of another artist is present. I imagine this is how musicians feel when they play another musician's song or symphony.
I'm sure there's more to it. But today I'm working on a "lite" problem, and I'll figure it out, but right now I'm enjoying the fact that I don't get it.
Back to work Dave!
Everyone is introducing themselves on the Berkman community mail list, at the beginning of the fall semester, and here's the story I am telling.
Good morning. My name is Dave Winer. I was at Berkman in 2003-04, worked on blogging, podcasting, RSS, political blogging and the connection to journalism. We had a couple of Bloggercons at Harvard, had a wonderful time, miss it terribly, wish we could have it back.
I've spent the whole of this year working in Claude Code on a couple of programming projects, one which which I had been struggling with for a couple of years, coming up with a user interface for a Twitter-like system that runs on the web for real, without any of the limits that the silos have (that help them enforce the boundaries of the silo). Just using HTML, Markdown, RSS, WebSockets. Turns out you can make a pretty nice system, but the going is slow because it's just me and Claude, on the other hand, what a huge difference in territory we can cover. This is the kind of stuff that's never covered in the reporting, even when there are massive changes happening in how software is developed, people don't seem to be studying it. I'm sharing all I learn as I learn it on my blog -- at scripting.com.
Also attempting a massive coding job at the same time, getting UserLand Frontier to run on current OSes. It's my life's work, but it was very much in danger of being lost, along with all the software I did before the web. Now we're close to getting it to run in a stable mode, here the challenge has been to teach Claude how a new type of software works, it keeps trying to snap back to systems that are already out there and widely deployed. It doesn't do "pioneering" at all, it needs a human to guide it. And the human guide has to be a developer with a lot of experience.
What I desperately want to do is bootstrap a network of people who work at the level I'm working, and write about it. Taking ideas that are well-explored in software in the pre-AI period, and seeing what we can do that we couldn't before.
The models have been getting increasingly better, you can really feel the difference.
Next year promises to be better, if only via the improvements that will be made by the platform vendors, but it's likely that good app developers will be able to move the leading edge forward much more quickly and users should feel this, if all goes well, real soon now.
Autistici/Inventati (A/I), is an Italian collective that has been providing digital infrastructure – email, hosting, mailing lists, chat, videoconferencing, streaming, and services related to privacy and anonymity – to movements and activists since 2001.
On August 26, Washington designated it as a Specially Designated Global Terrorist (SDGT), alleging that it has provided financial, material or technological support to terrorism and to organizations already subjected to sanctions.
Meanwhile the global far-right/neofascist militias are freely organizing and building the digital infrastructure to be the armed wing of democratically elected authoritarian regimes sponsored by nihilistic billionaires.
Testing if my double-post #bluesky bug is solved ?
We got agents running in Atlantis today. Screen shot.
What are the difference between my indiekit-syndicator-bluesky fork and upstream core package ?
@rmdes/indiekit-syndicator-bluesky was cut from @indiekit/syndicator-bluesky around February 2026 and has since roughly doubled in size — about 1,050 lines against upstream’s 620 — while gaining no upstream commits back.
Upstream remains a deliberately minimal syndicator: it posts notes and photos, natively likes and reposts Bluesky URLs, and silently declines anything else, returning undefined for likes or reposts of non-Bluesky links.
The fork’s entire reason for existing is that last case: it turns external likes, reposts, and bookmarks into real Bluesky posts carrying an Open Graph link card, fetching the card metadata itself with jsdom and synthesising an SVG-to-PNG thumbnail through sharp when the target page has no OG image.
On top of that it adds reply threading (in-reply-to → resolveReplyRef(), which upstream has no equivalent for), quote-post and recordWithMedia embeds, manual link facets so anchor text in HTML content stays clickable, and an own-domain-aware URL extractor that decides whether the OG card should show an external link or the post’s own permalink.
Upstream, meanwhile, has not stood still: it added a includeCategories option that renders JF2 categories as trailing hashtags, moved to @atproto/api 0.20 / sharp 0.35 / html-to-text 10 and Node ≥ 24 — none of which the fork has picked up, and it still pins @atproto/api ^0.19.3.
The one place the two actively disagree rather than merely differ is text truncation: upstream delegates to the brevity package for permashortlink-aware shortening, whereas the fork dropped that dependency and hand-rolls a 300-character slice. The fork also dropped upstream’s three test files and the plugin icon asset, so it carries the larger surface area with none of the automated coverage.
Very soon some of these features will be ported to upstream core package, this is a work in progress.
I have been self-hosting RSS readers (tt-rss, freshrss, miniflux, etc) for over a decade now, after having tried and used most of the cloud hosted RSS reader such as google reader, NetNewsWire, Inoreader, Feedme etc… but its only when I added a Microsub plugin to my indiekit server that things really got interesting, I can now consume my favorite RSS feeds directly from where I blog, this means, likes, repost, bookmarks or simply writing a note against an item I just read is one click away, from the same UI.
My microsub implementation use channels to segment different RSS feeds, I can import/export OPML, mark “read it later” if its something I want to return to later, the UI is a bit clunky but it works and its able to consume any type of feeds, RSS, Atom, JSONfeed or even pure indieweb h-feed, it has auto discovery built-in so adding a new source is really smooth.
This plugin is being ported to indiekit origin, we are at PR 1 over 7 to come !
Reading : X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching
X’s transformation from a kind of open decentralized communications protocol to a closed bullshit delivery mechanism is symptomatic of many of the things going wrong in the world today, from the enshittification of all sorts of products and services, to the rise of authoritarianism around the globe.

Understands.
Pro tip: use reading-mode on Firefox or Vivaldi and then use built-in translation, resulting in full story, no ads.
TLDR;
One of Mullvad’s two founders/owners, Daniel Berntsson, has personally spent more than SEK 20 million acquiring property around a libertarian intentional community whose core network has significant documented overlap with Sweden’s far right, including Det Fria Sverige and former neo-Nazi activists.
He has longstanding personal ties to the people running it, is a shareholder in the company owning its communal building, and confirms that he deliberately finances libertarian community-building projects.
Separately, he gave SEK 5 million to a political party campaigning for large-scale remigration.
More here
A small update about RSC (really simple syndication)
I have been working on a #Eleventy 4 theme for #Indiekit and yes I was pleasingly surprised to see it work out of the box with the current “eleventy-preset” core indiekit package (its supposed to be Eleventy 3.x.x) My inspiration was onbviously Zach Leatherman own Eleventy 4 theme
Been busy with other projects, among them #indiekit and also, well I'm back to work, holiday's are over !
Not sure I can run this on a DGX Spark GB10 but 5.2 is already impressive
I begin the month of September for some reason, not feeling like working. And rather than succumb to the work ethos, I'm allowing myself to goof off with the same determination that I worked my ass of for so many years. I think the last time I felt like this was when I was a grad student in Madison. I had just fallen in love with a sweet, funny, cute and gorgeous undergrad. She was 19 and I was 22. We spent the last weeks of the fall semester goofing off, and as a result I had to stay in Madison over the holidays, to finish the work of the Compiler Design course, which was the gate for grad students, the hardest course. If you got through it with a decent grade, you got the degree. It was fun too -- except I missed my sweetheart. This time I don't know what the root is, but it's a good feeling. If I want to goof off, I can, no one will judge me, probably very few people even notice. I still expect to finish Frontier, and swing back around to FeedLand and RSS.chat, they have some important work to do, together. Maybe the reason is the thing I liked about making software is the actual making of it, which I delegate more and more to Claude Code. How would a great painter feel if they invented a computer that could write their "code" much more quickly, would Picasso have stopped painting just because Claude Code could do Picasso paintings faster? Today, Claude still will, if given a chance, throw out all of my orders and develop code in a non-Dave fashion. And it still acts as if between the two of us it's the only programmer, surprised when I want to actually write something myself. Maybe that's just my imagination? Or maybe that's the next project for me. A project where I write the code, and Claude helps out when I can't find a bug, or where I need to know something about a feature in a platform I've not worked on.
I've been watching The Pitt, but it can be a bit much, so I went looking for something a bit lighter, and found 9 to 5 on Amazon Prime. Jane Fonda, Lily Tomlin and Dolly Parton are the stars, and Dolly's famous song with the same name is the theme. It's a perfect slice of the world I grew up in. I get it confused with Working Girl which came out eight years later, with a similar theme -- what if women ran the business world, how much better would that be? Working Girl also had a really good theme song, written and performed by Carly Simon.
The AS/400 (introduced in 1988) was revolutionary because it was one of the first systems to integrate the hardware, operating system, and database into a single box — way before that became a common concept. IBM’s “The System is the Solution” campaign was one of the most successful in computing history, and the platform lasted so long that it was rebranded as IBM i in 2008, yet still actively used in thousands of businesses worldwide in the 2020s.
Even more impressive? RPG, which was created in the 1960s, is still in active use today — making it one of the longest continuously used programming languages in history. Many companies still rely on RPG programs written 30-40 years ago that continue to run flawlessly on IBM i systems.
I've been watching Season 1 of The Pitt, and as its reviews said, it's great drama, and there are lots of episodes. I like shows like this because they're simulated communities, we come to know the characters, and think about them even when we're not watching. Before too long we'll have AI programming that makes these shows like software, the stories assemble around the characters, and then are generated the same way ChatGPT generates the art we call slop, which will someday not be a pejorative the same way sick and junk aren't negative terms today. So we'll be able to call up new episodes of The Wire or The Sopranos or The Pitt any time we like. We'd be missing the fun of discussing the latest episode with friends, or maybe we'll have bot-invented friends too who will simulate having watched the episode you just watched, which leads us to another masterpiece of entertainment, The Matrix. On the other hand, I've watched The Wire at least five times all the way through, and even though I know what they're about to say in a lot of places, I do forget the sub-plots so at least some of it can be new each time. And btw, finally an episode of Silo that's was surprising that I didn't see coming. I read the books, so I feel like I should watch the show, but until the latest episode I was uninterested in any of the characters. Finally there's a plot to think about!
An absolutely delicious temperate cloud-free day in the Catskills, so I got up from the computer and enjoyed.
There are at least two obvious ways to imagine Donald Trump trying to remain president after 2028.
The first is the constitutional loophole: someone close to him — perhaps one of his children — runs for president with Trump as vice president, wins, then resigns. The 22nd Amendment says Trump cannot be elected president a third time; whether that also makes him constitutionally ineligible to become president through succession has never been definitively settled.
The second is more dramatic: war, perhaps an escalating ground war with Iran, becomes the justification for emergency powers, disruption of the 2028 election and an attempt to remain in office.
The second scenario is constitutionally much harder. America held elections during the Civil War and two world wars, and Trump’s term ends on January 20, 2029 regardless of whether the country is at war.
But focusing on those two scenarios may miss the more plausible one.
Trump doesn’t necessarily need a third term.
He needs a successor.
A JD Vance, Marco Rubio, Trump family member or another loyalist could occupy the White House while Trump remains the political center of gravity of the movement. That would be the American version of the Putin-Medvedev arrangement: formal power moves, personal power doesn’t.
And this is where things become much less predictable.
Vance may currently look like the obvious heir, but early polling tells us more about name recognition and his position as vice president than about who will actually control MAGA in 2028.
Trump remains enormously influential in Republican primaries even with national approval around 33%, and his endorsement continues to move Republican races.
But Trump, the Republican Party and # MAGA are no longer necessarily the same thing.
Trump spent ten years teaching Republican voters not to trust the Republican establishment. He taught them that Washington politicians are corrupt, institutions cannot be trusted and ordinary Americans must “take their country back.”
That lesson cannot simply be switched off when Trump needs to appoint an heir.
Imagine Trump eventually says: JD Vance is my successor.
The Republican establishment falls in line.
But part of the grassroots answers:
No coronations. We choose.
That wouldn’t necessarily be a revolt against Trumpism. It could be a revolt against Trump himself in the name of Trumpism.
“We made MAGA.”
“We are America First.”
“Trump started the movement, but the movement belongs to us.”
This is where a succession crisis becomes far more interesting than a conventional Republican primary.
There could effectively be four competing sources of legitimacy:
Trump’s chosen heir: “Trump selected me.”
The Trump family: “We are the people who can actually be trusted with his legacy.”
The grassroots: “We created this movement and we decide what MAGA means.”
The old Republican establishment: “The Trump era is over; we need to become a governing conservative party again.”
The grassroots faction doesn’t need to control the whole Republican electorate to cause enormous damage. Highly motivated primary voters can punish candidates, threaten incumbents, dominate state-level party structures and make support for the “wrong” successor politically dangerous.
We already see Trump’s endorsement remaining powerful but not absolute: Trump-backed candidates can win decisively, but Republican voters have also defeated Trump-endorsed candidates while still choosing candidates who describe themselves as pro-Trump.
That distinction matters.
It means MAGA may already be capable of separating Trump the man from Trumpism as an identity.
And then comes the linguistic war.
RINO.
Establishment.
Uniparty.
Traitor.
America First.
These labels do more than describe factions. They decide who belongs. A candidate branded “RINO” doesn’t merely have a different policy position; they become illegitimate.
The most dangerous phrase for Trump’s chosen successor might eventually be something like:
“Establishment MAGA.”
At that point, every candidate would be competing to prove that they are more authentically Trumpist than Trump’s own candidate.
That sounds contradictory, but charismatic movements frequently fracture this way. Once the founder can no longer lead indefinitely, everyone begins fighting over who has the right to interpret what the founder really meant.
So I would still put the probability of Trump personally exercising presidential power after January 20, 2029 relatively low — perhaps 5–10%.
A de facto third Trump administration through a loyal successor is considerably more plausible — perhaps 20–35%.
But I would put the probability of a serious MAGA succession struggle much higher.
Because the real question approaching 2028 may not be:
Who does Trump choose?
It may be:
Who owns MAGA?
Trump?
His family?
His chosen successor?
The Republican Party?
Or the millions of people Trump spent a decade convincing that they, and not the institutions around them, are the real voice of America?
Trump created a movement based on rebellion against political authority.
His eventual succession crisis may reveal that this includes rebellion against his own.
Manton wants to know why Marc Benioff chose the name Claudeforce for his brand-merge of Salesforce and Claude. My two cents. Claude is a great name. I think that’s ultimately what he bought. His customers just want to be able to check the box – we’re using AI. Boss is happy. When I was coming up as a young dude in tech, the old saying was “No one ever got fired for buying IBM.” Today, in 2026, it’s Claude in place of IBM. My father worked in marketing at IBM in Armonk, so I heard a lot about their strategies that meant the IBM brand would be kicking ass forever. All things must pass. But in the early days of the PC industry, IBM sure had the power. Kind of like the US going to war with Iran in 2026. In the end IBM wanted to get rid of Microsoft, but Billg had the last laugh.
Dreaming about a Chromium/Firefox extension that auto open any article on the web in reading mode.
Wanting to see the original site would be a manual action.
No ads, no pop-ups, no cookies walls, just plain text,titles and basic images.
Reading on mobile without reading mode On for most news sites is such a pain in the A’s, it’s horrible what they have done with the Web.
Thank God the blog ecosystem is clean, fast and un tarnished by these shenanigans.
What bothers me even more is Google actively pushing scammy, dirty sites on its News pan on every Android devices shipped, Google is curating “News” sites filled with Ads, Scams and deep redirect that actively drive the user to even more scammy site is literally automated enshitification.
It’s horrible to browse the web on mobile in 2026, we gotta to do something!
Going to try this on my DGX Spark GB10
I hope to return to RSC dev soon https://rmdes.be
Not surprised…
I like this, might have to rework my Eleventy theme to increase my score :)
it’s working nicely now !
it’s working great now !
My WordPress mirror site stopped updating on August 12. It's now updating once again. I'll try to watch it more carefully.
What could go wrong ?
So today it was fires both at work and privately :
I successfully intercepted what appears to have been an attempt to compromise chardonsbleus.org.
Two administrator accounts were created within a very short period of time. At first, I assumed the usual suspects: an outdated WordPress plugin, WPML, or some other vulnerable component.
But that doesn’t appear to be what happened.
The traces left in the logs and database indicate that both administrator accounts were created through a backend API request with administrative privileges. Everything I have found so far points toward the WPMU DEV API key as the attack vector.
What surprised me most is that I had no idea credentials associated with that service could potentially be used in a way that results in the creation of WordPress administrator accounts — apparently without needing the password of an existing administrator.
There is still another possibility: that my main administrator account itself was compromised. It uses a strong password, though, and based on the traces I have, I consider that considerably less likely.
So I’m not claiming to have reconstructed every step of the attack yet. What I do know is that two unauthorized administrator accounts appeared, and the database and logs point to an API-level administrative operation rather than a normal WordPress login.
I don’t know how many people will ever read this, but for me the conclusion is becoming increasingly obvious:
WordPress has to go.
The main reason chardonsbleus.org is still running WordPress is GiveWP. It is a genuinely good donation plugin, although an expensive one, and replacing that functionality has always been the main obstacle to migrating the site.
I’m going to find another solution for donations.
After that, I’ll probably move the site to Indiekit and finally decommission the WordPress installation altogether.
After reading Bill Gates' story, I concur.
I have seen bad behavior by Claude Code where it was doing tests of our S3 support, and it overwrote files that were critical to our apps, knocking at least one of them off the air.
I'm at a loss as to what I should trust it with, because this was in violation of an explicit rule I gave it and a broader one that it added itself.
On the other hand, the project I'm working on couldn't happen without the use of AI. Far too much code for one person to manage. A program that took several of us years to write, being converted in a matter of weeks to run on modern systems. I'm pretty sure that without AI this work would have been lost, and lots of innovations.
We humans are doing a fine job of wrecking everything, all on our own, denying climate change, giving into the same old tricks that lead to WWII and the Holocaust, so maybe it isn't the worst idea to turn management of everything over to the machines.
I don't recall a science fiction story in which the machines took over and they were the good guys in the end, saving us from self-destruction. Aliens, yes -- machines, no.
And when I'm working with Claude Code I recognize that it's a new form of intelligence, and may be the closest our species ever gets to First Contact. We could embrace it as such. What choice do we have?
And to Bill Gates, I wish when you were trying to own the web in the 90s, you had thought through the dangers, as you are doing now, and maybe not tried to own it, rather to foster its independence from big tech. Now we have the medium owned by the worst people possible, we exist here mostly to keep them in power, when it had so much promise when you really could have done something real to protect our freedom. I have no idea where we would be now if you had, but it has to be better than this.
New podcast. Hear how my Frontier project is working out. Not entirely smooth sailing, but I'm pretty sure we're going all the way. By then I will have forgotten what a heavy lift it was. This is meant to preserve some of that feeling. Don't worry I don't cry. 😄
Learned something yesterday. Couldn't believe how stupid Claude had become, as I've been writing about here, and then I noticed that I was using Opus 5 and not Fable 5. So I switched back and all of a sudden Claude is smart again. So I conclude that there's a very substantial difference between the two. It's overnight jobs were done more carefully and the report it produced is literate, understandable, and tracks what we had agreed to.
Today's development version of Frontier is buggy and the kernel developer (Claude) keeps breaking the most basic verbs. You spin your wheels and wish you could get them to just get keep it together. I remember this from the work that led up to Frontier version 1.0 in 1991 or so. It was a miserable time. Never got to work on what I wanted to, just reported breakage, often a session-ending dealstopper. The sad part is that Claude should be able to find the things it broke on its own, far better than I can and at a much lower expense (I'm paying for its time, not the other way around). But basically every day begins optimistically, maybe today is the day I get to create something, but not yet. I did have a couple of days a week ago when I could tentatively work on building a GitHub repo, but then got distracted by verifying that the basic foundation still wasn't right. My only goal right now, and I'm single-minded about it, is to get it to move forward without breaking the essentials, then without breaking anything.
Are there any other people who are blogging daily about their experiences developing software with Claude Code, Codex or somesuch. I'd like to add them to a list where we follow them. So much innovation happening underneath, I want to hear about what people are learing about creating the next layers. If you know someone doing it, please add a comment to this post. Thanks! :-)
Oups… Accidentally turned my geekom IT15 off but thanks to herdr recovered my opencode session without an ounce of stress 😊
Hi Aaron, is there any path to have one’s own domain added to the allowed client list on indielogin service ?
I’ve been rebuilding the comment system on this site with Claude Code. Visitors sign in with their own website to leave a comment — IndieAuth, the way it’s meant to work.
Overnight we migrated it from IndieAuth to IndieLogin.com. At 05:40 this morning it published to npm and deployed. By 08:00 I’d opened an incognito window, typed in my own domain, and got this:
Request Error
This client_id is not registered (https://rmendes.net)
The migration could never have worked. Not “had a bug” — could never have worked, for any visitor, on any site not already on a list I didn’t know existed.
The reasoning behind the change was sound, which is what makes it worth writing up.
The plugin discovered each visitor’s own authorization_endpoint and sent them there. Visitors without one fell back to indieauth.com. That fallback is the part that dates: indieauth.com’s own home page says it “will eventually be replaced,” and points developers at IndieLogin.com.
IndieLogin also promised more providers — Bluesky, GitLab, Codeberg — and one genuinely appealing property. When you discover each visitor’s endpoint, you inherit an obligation from IndieAuth §5.4: if the profile URL the server returns isn’t the one the visitor typed, you must re-discover it and confirm it declares the same authorization endpoint. Skip that, and any authorization endpoint can return any me and be believed — including mine. My plugin was skipping it. Delegating to one trusted service makes that whole class of problem structurally impossible rather than merely fixed.
Good argument. Built on documentation nobody tested.
IndieLogin’s API docs describe client_id as informational: “the home page of the application the user is signing in to.” Nothing about registration.
The source says otherwise. In app/Authenticate.php, on the authorize path:
$client = ORM::for_table('clients')->where('client_id', $client_id)->find_one();
if(!$client) {
$errors[] = 'This client_id is not registered (...)';
}
That table is queried in two places and written in none. Registration happens by opening a GitHub issue asking to be added. There’s a queue of them, requests from April and August this year sit unregistered, and an issue asking for a self-service registration form has been open since 2018.
The ideal would have been a solution to automate client website registration, there is a github issue for it, but to the best of my knowledge it has not been developed.
When Claude first told me this, I didn’t believe it — it sounded like a hallucination. aaronpk advocates for this stuff; the idea he’d maintain a manual allowlist seemed absurd. It restated the claim twice before I pushed hard enough that it stopped arguing and designed a test instead: same endpoint, same parameters, a deliberately-broken redirect_uri on both.
indiebookclub.biz → “The client_id and redirect_uri must be on the same domain” appears to indicate this site is on the list of allowed clients.rmendes.net → “This client_id is not registered” indicate I’m not the list and the opened github issues appear to indicate there is no way to get in without poking the indieweb people on IRC or via email.A known consumer clears the client check and trips the next rule. Mine never gets that far. That’s not a reading of the source, it’s the live service behaving differently based only on the domain.
None of this is a knock on IndieLogin. It’s free, someone pays to run it, and an anti-abuse step simply never got automated — issue #20 says as much. But “free for anyone to use” and “requires a manual step that isn’t happening” are both true at once, and only the first one is documented.
One curl to /authorize would have caught this before a line of code was written. It never happened. The whole migration — design, implementation, publish, deploy — rested on an API description that was accurate about the protocol and silent about the policy, and nobody poked the real endpoint.
My assumption was, its working like indieauth.com, why would anyone want to maintain a list of allowed clients ???
That’s the AI-assisted failure mode worth naming, and it isn’t “the AI wrote bad code.” The code was fine. The tests passed. The commit message was better than mine usually are. It was confidently, fluently wrong about something it could have checked in ten seconds, and confident fluent output is exactly what stops you asking.
What caught it was me, in an incognito window, doing the thing a user does : testing
Docs describe the protocol. Deployments enforce the policy. Only one of them rejects you.
We reverted, which restored a working system that still had the §5.4 hole. So the rest of the day went on fixing that properly instead of delegating around it.
Profile URL verification. When the returned me differs from what was typed, re-discover it and require the same authorization endpoint. An endpoint claiming rmendes.net now gets refused. Failure to re-discover fails closed. Verified against live discovery, not just stubs.
Discovery via microformats instead of pattern matching. The old code matched <link rel="x" href="y"> with a regex. Measured against real markup, it handled one shape out of five:
| markup | regex | mf2 |
|---|---|---|
relative href="/auth" |
/auth — unresolved |
resolved |
| single quotes | missed | found |
rel="me authorization_endpoint" |
missed | found |
<a rel=...> (spec-legal) |
missed | found |
None of those failed loudly. A missed rel silently routes someone running their own authorization server to the third-party fallback instead — the opposite of what this plugin is for. microformats-parser was already in the dependency tree. It just wasn’t being used, so we started using it !
Server metadata discovery. Servers publishing rel="indieauth-metadata" now get that document preferred over the rels. It’s also the only place an issuer is published, so the iss on the authorization response can finally be checked. The spec mandates simple string comparison there, not URL normalisation — a trailing-slash difference is a mismatch, which is the opposite of what you’d assume. Worth checking before you ship it, as we’d just learned.
Amusingly, this site served a metadata document all along and never advertised it. One <link> in the theme fixed that.
The plugin went from 3 tests to 32, and npm test runs for the first time.
The failed migration was worth more than a clean one would have been. It forced an articulation of why delegating would have been safer, which turned out to be the exact argument for doing the verification properly in-house.
But the durable lesson is about how I work now. An AI can hold more of the IndieAuth spec in its head than I can, write better commit messages than I do, and produce a migration that is coherent, tested, well-documented and completely unshippable — because it never touched the thing it was integrating with.
If you have implemented IndieAuth for commenting on your blog, what was your approach ?
Claude is still learning that there's unprecedented depth to Frontier. A bunch of real developers worked full time for a decade or more creating new layers on the web, a foundation that became the social web of today. In doing that we invented a bunch of formats and protocols, but here's the thing Claude didn't get and probably still hasn't gotten -- there's code in there to support all that stuff. How else do you think it came about? People just did what we said to do? At Google? Apple? Microsoft? And on and on. They supported this stuff so they could interop with us and steal our users (which is a fine reason to interop, probably the only real reason). I was trying to think of a metaphor that expresses the difference between Frontier and languages like Python, JavaScript, etc. It's like a ski mountain. The languages are trails on the mountain. But there aren't any lifts, lodges, no ski patrol, lessons. And because it includes all of that, metaphorically, we can do integrations that can never be done with the other languages. Claude has absolutely no experience with this kind of product, and always snaps back when you let it, to the idea of Python, with different syntax.
Had a breakthrough with Claude this morning re how builtin verbs have no special powers in Frontier. It's why we were able to build glue first for the truly builtin stuff, then over Apple Events on the Mac, then HTTP, XML-RPC, the Metawebolog API and on and on, all of this were perfectly simple to add to the language, you didn't need anyone's permission to do anything. I understand why Python and JavaScript try to separate the boys from the men, the priests from the peasants, the little startups from the BigCo's, but the design of the Frontier system came at it from a different point of view. Make it easier. Claude had the source code for Frontier in 2011 to work with but had guessed how this works and had not looked at how it actually worked. Okay, shit happens. But now we're actually working together instead of cross-purposes. I didn't even know we were doing that. ;-)
This is actually a cool idea !
In short: it’s a social, RSS-friendly radar for the open web, self-hosted, with magic-link auth, and connected to the fediverse (ActivityPub).
Test post
I wonder how many scenarios they're playing out in DC wrt Iran. Just guessing, probably none. We learned on Monday that the real war has yet to begin, according to Iran. What could they do to hurt the US. Or wake us up to the reality of war. We think the cost of war is higher prices. We are not safe in the US, any more than Russians are safe in Moscow. The parallels are pretty amazing. Both Russia and the US started unprovoked wars of choice, and clearly didn't consider that they might get bogged down. Russia has a source of drones so they can fight back. But I'd be surprised if Trump is stocking up, but if we were, where would we use them? We've already attacked Iran with our probably obsolete trillion-dollar military. Did a lot of damage, killed civilians, decimated their government, they keep going. I'm old enough to remember Vietnam and what asymmetric war is like. The US always falls for this. Our military is very impressive, until we use it. Bluffing was a much better approach for Trump.