Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Author Matthias Pfefferle

    (@pfefferle)

    Hey @thommienw πŸ‘‹

    I have not tested the several plugins that allows users to disable the API in parts or completely.

    We have not changed something on ActivityPub plugin side. ActivityPub needs API endpoints for the communication with other servers (sending and receiving posts and replies), so the Plugin needs these endpoints.

    I think the best way is to ask in the forums of the specific plugin(s) if there is a way to allow-list specific subsets/namespaces!? I am happy to support, simply mention me in this/these thread(s).

    I am also happy to do this via code if the plugin you use provides a filter to do so.

    Thread Starter thommienw

    (@thommienw)

    The “Disable WP Rest API” plugin was recently recommended in an article by heise.de (C’T magazine), thus it may have some popularity among tecchies in Germany. There is a free version and also a “pro” version at https://plugin-planet.com/rest-pro-tools/ for 20 USD per year. This version has “granular control” and “Easily toggle on or off any route to disable access”. But paying 20 USD per year just for some fine grained control to enable AP endpoints and blocking anything else is a bit too much …

    Plugin Author Matthias Pfefferle

    (@pfefferle)

    @thommienw I had a look at this plugin and found that it’s possible to allowlist specific endpoints, such as those provided by ActivityPub, using a filter.

    <?php
    /**
    * Plugin Name: Allow ActivityPub through Disable WP REST API
    */
    add_filter(
    'disable_wp_rest_api_server_var',
    function ( $allowed ) {
    global $wp;
    $route = isset( $wp->query_vars['rest_route'] )
    ? '/' . ltrim( $wp->query_vars['rest_route'], '/' )
    : '';
    if (
    preg_match( '#^/activitypub/1\.0(?:/|$)#', $route )
    && isset( $_SERVER['REQUEST_URI'] )
    ) {
    $allowed = $allowed ? (array) $allowed : array();
    $allowed[] = $_SERVER['REQUEST_URI'];
    }

    return $allowed;
    }
    );

    Would that work for you?

    Thread Starter thommienw

    (@thommienw)

    hmm … Do I understand this correctly? Does this code snippet work with the basic (free) version and from CLI? As there is no UI in the basic version where I could add any “unfiltering” code.

    Or would we just add another plugin with the code in parallel to the “Disable WP REST API”

    Anyway, I have a number of sites for testing πŸ˜‰

    Plugin Author Matthias Pfefferle

    (@pfefferle)

    Thread Starter thommienw

    (@thommienw)

    Snippet is now installed at https://netzwissen.de/ and all three plugins are activated (AP, “Allow ActivityPub through Disable WP REST API”, Disable WP REST API)

Viewing 6 replies - 1 through 6 (of 6 total)

You must be logged in to reply to this topic.