
2·
6 months agoAs long as there is a bypass for /inbox it should be fine. I used to run my instance behind a WAF and I had to add that path to the allowlist so that federation requests would bypass it.

As long as there is a bypass for /inbox it should be fine. I used to run my instance behind a WAF and I had to add that path to the allowlist so that federation requests would bypass it.
Honestly, it makes sense that Lemmy refuses to use SVG as profile picture, as they can be used for XSS.