@Oceane fyi each instance can decide which types of file are allowed to be uploaded (.jpg .png .pdf etc)
wonder if you have in mind specific ways to enhance the security?
@ivan Sorry, I was talking about the way Bonfire seemed to fetch images by following hyperlinks, not about files that were uploaded on an ActivityPub server.
But this might be far-fetched? What difference would it make with a malicious instance user uploading illegal files directly?