The idea: blobs could require a signed URL to fetch. First request? You get a 401. Then you hit an XRPC method to generate a signed URL tied to your DID. Use that to fetch the blob. Short-lived, verifiable, and secure.
The idea: blobs could require a signed URL to fetch. First request? You get a 401. Then you hit an XRPC method to generate a signed URL tied to your DID. Use that to fetch the blob. Short-lived, verifiable, and secure.
If you have a fediverse account, you can quote this note from your own instance. Search https://bsky.brid.gy/convert/ap/at://did:plc:cbkjy5n7bk3ax2wplmtjofq2/app.bsky.feed.post/3ln6fldaqd22s on your instance and quote it. (Note that quoting is not supported in Mastodon.)