@thisismissem @quintessence @PaulaToThePeople @MastodonEngineering It could be implemented differently.https://docs.gotosocial.org/en/latest/federation/access_control/Next, GoToSocial will check for the existence of a block (in either direction) between the owner of the public key making the http request, and the owner of the resource that the request is targeting. If the GoToSocial user blocks the remote account making the request, then the request will be aborted with http code 403 Forbidden.