• JRaccoon@discuss.tchncs.de
    link
    fedilink
    arrow-up
    5
    ·
    13 hours ago

    That’s reassuring to know. What I don’t understand is why you have the /api/v3/post/like/list route. You say you don’t want votes to be snooped on, but then you add an endpoint that makes it very easy for instance admins to do exactly that if they choose to? Also worth pointing out that the tool linked here wouldn’t work in its current form if this route didn’t exist.

    • Dessalines@lemmy.ml
      link
      fedilink
      arrow-up
      4
      ·
      3 hours ago

      Read the issue above for why. Vote manipulation is a real problem, but making all votes public is not the solution anyone wants. Limiting vote viewing to admins and mods is decided on as the best of both worlds.

      Also that tool can only be used by specifically malicious instances whose goal it is to snoop and expose all votes. Those instances can and should be blocked.

    • Rooki@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      11 hours ago

      This is for admins to see easier vote manipulation. I think mods can see that on their communities too.

      For admins its like… they could literally just look into the database, so it doesnt make any difference. Mods in the other hand should rather not snoop around i guess.

      This tool just simplifies the process instead of creating an open federated instance yourself and see the votes.