洪 民憙 (Hong Minhee) 
@hongminhee@hollo.social · Reply to 洪 民憙 (Hong Minhee) :nonbinary:'s post
The problem is that Fedify's Activity Vocabulary API supports property hydration. Fedify intentionally hides the following three states of properties of Activity Vocabulary objects, which seems to hinder the application of an origin-based security model:
- When a complete object is embedded within a property of a JSON-LD object.
- When a property of a JSON-LD object references an object by URI.
- When it was initially #2, but the property has since been hydrated.