M2: every inbox answer is recorded

InboxReceiver records each answer once, in a finally, with a reason: too-large, not-json,
not-activity, missing-type-or-actor, no-signature, the signature check's own codes
(headers-unsigned, digest-mismatch, header-unreadable, date-skew, expired,
algorithm-unsupported), signature-invalid, actor-not-key-owner, key-unavailable,
id-cross-origin, undo-foreign, misattributed, unknown-recipient, and for 202s queued,
duplicate, suspended or self-delete-unknown-key. Each event carries the activity and object
type, the inbox, the signature scheme, the bytes and the time taken. A 404 for an unknown
/mouth and a rate-limited inbox (429, from OnRejected) are recorded too.

Until the signature verifies, the host is only claimed, so it is kept only if the server is
already known. A suspended server is recorded under its own name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-03 10:59:55 +02:00
1 parent 15cd034b29
commit 4fa53f63bd
7 files changed
+385 -24

No files matched your search

@@ -185,6 +185,18 @@ namespace PrivaPub.Federation.Signing
return default;
}
public static string ProblemCode(string problem) => problem switch
{
null => default,
_ when problem.StartsWith("unsupported signature algorithm", StringComparison.Ordinal) => "algorithm-unsupported",
_ when problem.EndsWith("is not signed", StringComparison.Ordinal) || problem.StartsWith("neither", StringComparison.Ordinal) => "headers-unsigned",
_ when problem.StartsWith("the digest does not match", StringComparison.Ordinal) => "digest-mismatch",
_ when problem.StartsWith("unreadable", StringComparison.Ordinal) => "header-unreadable",
_ when problem.Contains("outside the allowed window", StringComparison.Ordinal) => "date-skew",
"the signature has expired" => "expired",
_ => "signature-problem"
};
static bool IsFresh(DateTimeOffset signedAt, DateTimeOffset now) =>
signedAt >= now - MaxAge && signedAt <= now + MaxClockSkew;