http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/restricting-unauthenticated-access-to-mastodons-public-feeds.html
Of course, the more widely adopted the ruleset, the more likely that bot authors will include this simple circumvention. Active Checks Whilst it's dissapointing the Mastodon doesn't reject invalid tokens, there is still a path forwards: Rather than simply requiring the presence of a token , we should instead require the presence of a valid token .