ActivityPub – WordPress plugin | WordPress.org
https://wordpress.org/plugins/activitypub/#developers
9.2.1 – 2026-08-03
Fixed
- Fixed duplicate entries and failed undo actions for activities received from other WordPress sites.
- Fixed posts and profiles not being found on Mastodon and other Fediverse software, which happened when a request asked for ActivityPub data but also accepted HTML as a low-priority fallback.
- Fixed remote profiles and followers not being found when their address contains unusual characters.
- Improved checks on boosted content so it is only accepted from the server that published it.
- Improve escaping of embedded link URLs in federated content.
- Improve permission checks for admin-only actions.
- Improve validation of incoming federated activities so the signing key and referenced objects are bound to the sender.
9.2.0 – 2026-07-31
Changed
- ActivityPub responses are now served only to clients that ask for ActivityPub data and nothing else, which keeps that data out of page caches meant for regular web pages.
- Only users enabled for ActivityPub can obtain and use OAuth access tokens.
Removed
- Remove support for the WP REST Cache plugin.
Fixed
- Hide the heading on the Followers and Following blocks when its text is cleared, matching the Reactions block.
- Under Authorized Fetch, ActivityPub responses are no longer stored by page caches such as LiteSpeed or Surge.
Google翻訳
9.2.1 – 2026-08-03
Fixed
- 他のWordPressサイトから受信したアクティビティにおいて、重複するエントリーや失敗していた「取り消し(undo)」アクションを修正しました。
- ActivityPubデータを要求しつつ、低優先度のフォールバックとしてHTMLも受け入れるリクエストが行われた際に、Mastodonやその他のFediverseソフトウェア上で投稿やプロフィールが見つからなくなる問題を修正しました。
- アドレスに特殊な文字が含まれるリモートのプロフィールやフォロワーが見つからない問題を修正しました。
- ブースト(再投稿)されたコンテンツのチェックを強化し、そのコンテンツを最初に公開したサーバーからのもののみを受け入れるようにしました。
- フェデレーション(連合)コンテンツ内の埋め込みリンクURLに対するエスケープ処理を改善しました。
- 管理者のみが実行可能なアクションに対する権限チェックを改善しました。
- 受信したフェデレーション・アクティビティの検証を強化し、署名キーと参照されるオブジェクトが送信者に紐付いていることを確認するようにしました。
9.2.0 – 2026-07-31
Changed
- ActivityPubのレスポンスは、ActivityPubデータを明示的に要求するクライアントに対してのみ送信されるようになりました。これにより、通常のWebページ用のページキャッシュに当該データが混入するのを防いでいます。
- ActivityPubが有効化されたユーザーのみが、OAuthアクセストークンを取得・利用できます。
Removed
- WP REST Cache プラグインのサポートを削除します。
Fixed
- 「Reactions」ブロックと同様に、「Followers」および「Following」ブロックのテキストが空になった場合は、その見出しを非表示にします。
- 「Authorized Fetch」が有効な場合、ActivityPubのレスポンスはLiteSpeedやSurgeなどのページキャッシュに保存されなくなります。

コメント