P5 done: a key we cannot fetch for now gets 503, and follow/like/block ids stay private on purpose
- When a sender's key cannot be fetched because its server timed out or answered 5xx, the inbox answers 503 with Retry-After: 300 instead of 401, so Mastodon 4.7 retries rather than switching to RFC 9421 signatures we do not verify yet. The fetcher's failure cache now remembers whether a failure was temporary. - Follow, Like, Block, Accept, Reject and Undo ids are deliberately not dereferenceable: serving them would publish who follows, likes and blocks whom. They are always sent with their object embedded. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
b691c6766d
commit
81de470f64
7 files changed
+51
-9
No files matched your search
@@ -106,6 +106,21 @@ namespace PrivaPub.Tests.Federation
|
||||
Assert.NotNull(message.ConversationId);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task An_unreachable_key_asks_the_sender_to_retry_instead_of_refusing()
|
||||
{
|
||||
var (_, alice) = await _harness.Persona("alice");
|
||||
var offline = new RemoteActor(_harness.Peer, "offline", origin: "http://127.0.0.1:9");
|
||||
|
||||
var result = await _harness.Deliver(offline, "/human-centipede", new JsonObject
|
||||
{
|
||||
["id"] = NewId(offline, "follows"), ["type"] = "Follow", ["actor"] = offline.Id, ["object"] = alice.Uri
|
||||
});
|
||||
|
||||
Assert.Equal(503, result.StatusCode);
|
||||
Assert.Equal(300, result.RetryAfterSeconds);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public async Task A_join_of_a_local_post_is_answered_with_ignore()
|
||||
{
|
||||
|
||||
Reference in new issue
Block a user