I've updated the section describing the authentication of embedded objects in FEP-fe34 (Origin-based security model):

https://codeberg.org/fediverse/fep/src/commit/9ad3767987dae7e51d647768b655e93b82881343/fep/fe34/fep-fe34.md#embedding

It now covers the case where a signed embedded object is attributed to another local actor. That happens in federated groups and conversation containers where signed activities may be wrapped in Announce or Add activities.

Previously, the recommendation was to reject such activities when submitted via C2S API. Now the FEP recommends authenticating embedded objects (e.g. by looking up their IDs).

Another important change: anonymous objects are not ownerless anymore. Such object has the same owner as its parent object. It also inherits origin from its parent object, though that follows from the definition.

#fep_fe34

Summary card of repository fediverse/fep, described as: Fediverse Enhancement ProposalsCodeberg.orgfep/fep/fe34/fep-fe34.md at 9ad3767987dae7e51d647768b655e93b82881343fep - Fediverse Enhancement Proposals
en