2026-5-22 - Posting @tesaguri@fedibird.com -

19:09:25

LD-Signature Bypass via JSON-LD Named-Graph Restructuring · Advisory · mastodon/mastodon · GitHub
github.com/mastodon/mastodon/s

というかこれ、“Named-Graph”とあるけど、本当に*named* graphだったらカノニカルなN-Quadsにも影響するわけだから、問題になるのはデフォルトグラフに対する明示的な`@graph`の場合だけでは。そしてデフォルトグラフの判定は“plain JSON”の処理としても比較的容易なのだから[^1]、一律の拒否でなくデフォルトグラフの場合だけ検出して弾くとかで良くないだろうか

LD-Signature Bypass via JSON-LD Named-Graph Restructuring
19:09:39

[^1]: <w3.org/TR/2020/REC-json-ld11-2>のこのケースのみのはず:“When a JSON-LD document's top-level structure is a map that contains no other keys than `@graph` and optionally `@context` (properties that are not mapped to an IRI or a keyword are ignored), `@graph` is considered to express the otherwise implicit default graph.”

19:19:34

Claire氏が`@graph`は使われていないと述べたときにさっと`proof`の例を出せれば良かったのだろうけど、失敗したな

19:27:00

いや、Mastodonの場合はcompaction contextに`security`コンテクストを含んでいるから、問題にはならないか。あくまでMastodonに限った話ではあるけど

19:42:17

ここはやはり`"@container": "@graph"`を使う拡張をぶち上げて混乱を招くしか……(?):

github.com/w3c/activitypub/iss
(2024-04-06)

Semantics of embedded `object`s of `Update` activities in collections of activities · Issue #408 · w3c/activitypub
20:01:14

実際、オブジェクトの版の表現として名前付きグラフはありだと思いません?(こいつまた変なこと言っているよ):

```jsonc
{
"id": "/note/42/version/1",
"@graph": {
"id": "/note/42",
"type": "Note",
/* … */
}
}
```

21:40:16

正月飾りなどで日の丸国旗をお持ちの皆さん、今のうちに処分しておかないと将来犯罪になるかも!? 日本国国章断捨離ラストチャンス!