P5 done: a key we cannot fetch for now gets 503, and follow/like/block ids stay private on purpose
- When a sender's key cannot be fetched because its server timed out or answered 5xx, the inbox answers 503 with Retry-After: 300 instead of 401, so Mastodon 4.7 retries rather than switching to RFC 9421 signatures we do not verify yet. The fetcher's failure cache now remembers whether a failure was temporary. - Follow, Like, Block, Accept, Reject and Undo ids are deliberately not dereferenceable: serving them would publish who follows, likes and blocks whom. They are always sent with their object embedded. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
b691c6766d
commit
81de470f64
7 files changed
+51
-9
No files matched your search
@@ -13,7 +13,7 @@ using static PrivaPub.Federation.Objects.ActivityJson;
|
||||
|
||||
namespace PrivaPub.Federation.Inbox
|
||||
{
|
||||
public sealed record InboxResult(int StatusCode, string Error = default);
|
||||
public sealed record InboxResult(int StatusCode, string Error = default, int? RetryAfterSeconds = default);
|
||||
|
||||
public sealed record InboxPayload(string ActorURI, string Activity, string Inbox = default, string KeyId = default, string Algorithm = default,
|
||||
string[] SignedHeaders = default, DateTime? ReceivedAt = default);
|
||||
@@ -25,6 +25,8 @@ namespace PrivaPub.Federation.Inbox
|
||||
|
||||
public class InboxReceiver : IInboxReceiver
|
||||
{
|
||||
const int KeyRetrySeconds = 300;
|
||||
|
||||
const int MaxBodyBytes = 1024 * 1024;
|
||||
|
||||
readonly ILocalActorService _localActors;
|
||||
@@ -88,6 +90,8 @@ namespace PrivaPub.Federation.Inbox
|
||||
if (keyOwner == default || !HttpSignatures.Verify(keyOwner.PublicKey, signingString, parameters.Signature))
|
||||
{
|
||||
keyOwner = await _remoteActors.GetActorByKeyId(parameters.KeyId, refresh: true, token);
|
||||
if (keyOwner == default && _remoteActors.KeyTemporarilyUnavailable(parameters.KeyId))
|
||||
return new(StatusCodes.Status503ServiceUnavailable, "the signing key could not be fetched; try again later", KeyRetrySeconds);
|
||||
if (keyOwner == default || !HttpSignatures.Verify(keyOwner.PublicKey, signingString, parameters.Signature))
|
||||
return new(StatusCodes.Status401Unauthorized, "the signature does not verify");
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user