ActivityPub – WordPress plugin | WordPress.org
https://wordpress.org/plugins/activitypub/#developers
9.1.0 – 2026-07-22
Security
- Ensure apps you connect can only act within the access you granted them, and not make wider changes to your site.
- Ensure remote profiles and content are served from the address they claim before storing them.
- Fix a security issue where a remote actor’s profile link could run scripts in the admin area.
- Ignore an incoming follow request whose actor resolves to a different account than the one that sent it.
Added
- Add a filter that allows federating with servers on private or internal networks.
- Add an actor autocomplete endpoint so Fediverse apps can offer typeahead search when mentioning people.
- Federate the episode summary for Podlove Podcast Publisher episodes.
Changed
- Improve reliability of the Social Web admin screen loading.
- Improve the internal handling of the Application actor used for server-to-server requests.
Fixed
- Ensure a follow can only be declined by the account you followed.
- Fixed using the correct cache representation in Surge config
- Fix follow requests from some fediverse services staying pending after they are accepted.
- Fix likes from some accounts being recorded as multiple duplicate comments.
- Fix posts being removed from the Fediverse when edited while scheduled for a future publish date.
- Fix repeated deliveries of a like or repost creating new comments after the original was marked as spam or moved to the trash.
- Fix Starter Kit imports failing on Fediverse servers that require signed requests.
- Fix the scheduled refresh of remote profiles so it actually re-fetches from the remote server. Previously, stale avatars and bios for commenters never updated until they sent a new activity to your site.
- Fix URLs with multiple query parameters (such as avatars, images, profile links, and podcast media) being corrupted in content sent to the Fediverse.
- Prevent caching non-actor objects (such as notes) as remote profiles.
- Refresh cached remote profiles in place during scheduled updates to avoid creating duplicate copies.
- Show the Fediverse Preview for scheduled posts instead of the regular post preview.
- Stop storing responses from remote servers in the database when they were requested uncached.
Google翻訳
9.1.0 – 2026-07-22
Security
- 連携するアプリが、許可された範囲内でのみ動作し、サイトに対してそれ以上の変更を行えないようにします。
- リモートのプロフィールやコンテンツを保存する前に、それらが申告されたアドレスから配信されていることを確認します。
- リモートのアクターのプロフィールリンクが管理画面でスクリプトを実行できてしまうセキュリティ上の問題を修正します。
- フォローリクエストの送信元アクターが、リクエストを送信したアカウントとは別のアカウントに解決される場合、そのリクエストを無視します。
Added
- プライベートネットワークや内部ネットワーク上のサーバーとの連携(フェデレーション)を可能にするフィルターを追加します。
- Fediverseアプリがメンション時にタイプアヘッド検索(入力中の候補表示)機能を提供できるよう、アクターのオートコンプリート用エンドポイントを追加します。
- Podlove Podcast Publisherのエピソードについて、その概要を連携(フェデレーション)対象に含めます。
Changed
- ソーシャルウェブ管理画面の読み込みの信頼性を向上させます。
- サーバー間リクエストに使用されるアプリケーションアクターの内部処理を改善します。
Fixed
- フォローの拒否は、フォローされたアカウントからのみ行えるようにしました。
- Surge設定において正しいキャッシュ表現を使用するように修正しました。
- 一部のFediverseサービスからのフォローリクエストが、承認後も「保留中」のままになる問題を修正しました。
- 一部のアカウントからの「いいね」が、複数の重複したコメントとして記録される問題を修正しました。
- 将来の日時に公開するよう予約された投稿を編集した際、その投稿がFediverseから削除されてしまう問題を修正しました。
- 「いいね」や「リポスト」が繰り返し送信された際、元のデータがスパム指定やゴミ箱への移動済みであっても新しいコメントが作成されてしまう問題を修正しました。
- 署名付きリクエストを必須とするFediverseサーバーで、スターターキットのインポートに失敗する問題を修正しました。
- リモートプロフィールの定期更新が、実際にはリモートサーバーから再取得を行っていなかった問題を修正しました。以前は、コメント投稿者の古いアバターや自己紹介文が、そのユーザーが新しいアクティビティを送信するまで更新されませんでした。
- Fediverseに送信されるコンテンツ内で、複数のクエリパラメータを含むURL(アバター、画像、プロフィールリンク、ポッドキャストのメディアなど)が破損する問題を修正しました。
- 「ノート(投稿)」などのアクター(主体)ではないオブジェクトが、リモートプロフィールとしてキャッシュされないようにしました。
- 定期更新時にキャッシュされたリモートプロフィールをその場で更新し、重複コピーが作成されないようにしました。
- 予約投稿については、通常の投稿プレビューではなくFediverse用プレビューを表示するようにしました。
- キャッシュを使用しないリクエストで取得したリモートサーバーからのレスポンスを、データベースに保存しないようにしました。

コメント