Everything on, phase 3: sign-in and recovery tell nothing, recovered passwords end sessions, deleted roots are gone everywhere
Owner decision 2026-10-04: fix the account privacy findings.
- Sign-in. Every failure answers "That username and password do not match." after the same work: an unknown login
is hashed against a decoy, and the comparison is constant-time. "Banned" is told only to someone who gave the right
password. This covers /clientapi/user/login, /invitation/login and /oauth/login.
- Recovery.
- Every request answers the same sentence and queues a SendRecovery job, whether or not the account exists or has an
email. The lookup, the code and SMTP move to RecoveryJob, so neither the answer nor its timing says anything.
- Codes are kept only as a SHA-256 hash, for one hour. Migration _011 drops the plaintext ones, which never expired.
- A recovered password ends every session of the root. RootSessions sets CredentialsChangedAt, which JwtEvents
checks against the JWT's issue time, now stamped as nbf, and revokes each persona's OAuth tokens and authorizations.
- Deleting a root (RootRemoval: the admin route, or the restored self-delete at /clientapi/user/delete, which asks for
the password).
- Its sessions end.
- Each persona and each group it owns sends Delete{Actor} to its followers, its members and the accounts it follows.
- The personas' posts are emptied.
- /peasants/{name} answers 410 with a Tombstone (formerType Person or Group), as do its inbox and WebFinger, through
LocalActorService.Gone. The names stay reserved.
- The root keeps only a unique `deleted-{id}` name; the second deletion on an instance used to collide on
"Deleted user".
Also, from phase 2's pasture: GoToSocial files a circle post like a DM and shows it only to accounts it mentions. Each
member's copy, and a member's refetch, now also mentions that member silently. The GoToSocial scenario checks circle
posts in conversations, like DMs, and they pass there now, as on Mastodon.
657 tests pass.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
This commit is contained in:
1 parent
fcd35f5043
commit
8c2eba6cbb
25 files changed
+665
-248
No files matched your search
@@ -62,6 +62,7 @@ namespace PrivaPub.Federation.Actors
|
||||
{
|
||||
string BaseAddress { get; }
|
||||
Task<LocalActor> FindByUserName(string userName, CancellationToken token);
|
||||
Task<GoneActor> Gone(string userName, CancellationToken token);
|
||||
Task<LocalActor> FindById(LocalActorKind kind, string id, CancellationToken token);
|
||||
Task<LocalActor> FindByUri(string actorUri, CancellationToken token);
|
||||
Task<LocalActor> GetInstanceActor(CancellationToken token);
|
||||
@@ -71,6 +72,9 @@ namespace PrivaPub.Federation.Actors
|
||||
LocalActor FromGroup(GroupEntity group);
|
||||
}
|
||||
|
||||
// a persona or group that was deleted: its name stays reserved, and its documents answer 410 with this
|
||||
public sealed record GoneActor(string Uri, string FormerType, DateTime DeletedAt);
|
||||
|
||||
public class LocalActorService : ILocalActorService
|
||||
{
|
||||
public const string InstanceUserName = "privapub";
|
||||
@@ -113,6 +117,18 @@ namespace PrivaPub.Federation.Actors
|
||||
return group == default ? default : FromGroup(group);
|
||||
}
|
||||
|
||||
public async Task<GoneActor> Gone(string userName, CancellationToken token)
|
||||
{
|
||||
if (string.IsNullOrEmpty(userName))
|
||||
return default;
|
||||
userName = userName.ToLowerInvariant();
|
||||
var avatar = await _dbEntities.Avatars.Match(a => a.UserName == userName && a.DeletionAt.HasValue).ExecuteFirstAsync(token);
|
||||
if (avatar != default)
|
||||
return new GoneActor($"{BaseAddress}/peasants/{avatar.UserName}", "Person", avatar.DeletionAt.Value);
|
||||
var group = await _dbEntities.Groups.Match(g => g.UserName == userName && g.DeletionAt.HasValue).ExecuteFirstAsync(token);
|
||||
return group == default ? default : new GoneActor($"{BaseAddress}/peasants/{group.UserName}", "Group", group.DeletionAt.Value);
|
||||
}
|
||||
|
||||
public async Task<LocalActor> FindById(LocalActorKind kind, string id, CancellationToken token)
|
||||
{
|
||||
switch (kind)
|
||||
|
||||
@@ -53,6 +53,20 @@ namespace PrivaPub.Federation.Controllers
|
||||
public async Task<IActionResult> GetActor(string actor, CancellationToken token)
|
||||
{
|
||||
var local = await _localActors.FindByUserName(actor, token);
|
||||
if (local == default && await _localActors.Gone(actor, token) is { } gone)
|
||||
return new ContentResult
|
||||
{
|
||||
Content = new JsonObject
|
||||
{
|
||||
["@context"] = ActivityPubRenderer.ActivityStreams,
|
||||
["id"] = gone.Uri,
|
||||
["type"] = "Tombstone",
|
||||
["formerType"] = gone.FormerType,
|
||||
["deleted"] = ActivityPubRenderer.Timestamp(gone.DeletedAt)
|
||||
}.ToJsonString(),
|
||||
ContentType = ActivityContentType,
|
||||
StatusCode = StatusCodes.Status410Gone
|
||||
};
|
||||
if (local is not { IsFederated: true })
|
||||
return NotFound();
|
||||
if (WantsHtml() && local.Kind != LocalActorKind.Application)
|
||||
@@ -282,6 +296,8 @@ namespace PrivaPub.Federation.Controllers
|
||||
public async Task<IActionResult> Inbox(string actor, CancellationToken token)
|
||||
{
|
||||
var local = await _localActors.FindByUserName(actor, token);
|
||||
if (local == default && await _localActors.Gone(actor, token) != default)
|
||||
return StatusCode(StatusCodes.Status410Gone);
|
||||
if (local is not { IsFederated: true })
|
||||
return Answer(_inbox.NoSuchRecipient(Request));
|
||||
return Answer(await _inbox.Receive(Request, local, token));
|
||||
@@ -328,7 +344,9 @@ namespace PrivaPub.Federation.Controllers
|
||||
{
|
||||
var circle = await _dbEntities.Groups.MatchID(post.GroupId).ExecuteFirstAsync(token);
|
||||
var note = ActivityPubRenderer.Note(post, local, _localActors.FromGroup(circle), post.InReplyToURI);
|
||||
return (local, post, OutboxPublisher.Naming(note, SignedFetchAuthorizer.CircleReaders(circle, requester)));
|
||||
var readers = SignedFetchAuthorizer.CircleReaders(circle, requester);
|
||||
var named = readers.Count == 0 ? new List<Models.User.ForeignAvatar>() : await _dbEntities.ForeignAvatars.Match(a => readers.Contains(a.ActorURI)).ExecuteAsync(token);
|
||||
return (local, post, OutboxPublisher.Naming(note, named));
|
||||
}
|
||||
var rendered = post.Visibility == PostVisibility.Direct
|
||||
? ActivityPubRenderer.DirectNote(post, local, Array.Empty<(string, string)>(), post.ContextURI)
|
||||
|
||||
@@ -49,6 +49,8 @@ namespace PrivaPub.Federation.Controllers
|
||||
if (parts.Length != 2 || !parts[1].Equals(domain, StringComparison.OrdinalIgnoreCase))
|
||||
return NotFound();
|
||||
actor = await _localActors.FindByUserName(parts[0], token);
|
||||
if (actor == default && await _localActors.Gone(parts[0], token) != default)
|
||||
return StatusCode(StatusCodes.Status410Gone);
|
||||
}
|
||||
else
|
||||
actor = await _localActors.FindByUri(resource, token);
|
||||
|
||||
@@ -2,6 +2,7 @@ using PrivaPub.Federation.Actors;
|
||||
using PrivaPub.Federation.Rendering;
|
||||
using PrivaPub.Models.Federation;
|
||||
using PrivaPub.Models.Post;
|
||||
using PrivaPub.Models.User;
|
||||
using PrivaPub.StaticServices;
|
||||
|
||||
using System.Text.Json.Nodes;
|
||||
@@ -75,19 +76,18 @@ namespace PrivaPub.Federation.Outbox
|
||||
}
|
||||
|
||||
async Task<IReadOnlyList<string>> CircleMembers(string groupId, CancellationToken token) =>
|
||||
(await CircleRecipients(groupId, token)).Select(r => r.Inbox).Distinct(StringComparer.Ordinal).ToList();
|
||||
(await CircleRecipients(groupId, token)).Select(r => r.InboxURL).Distinct(StringComparer.Ordinal).ToList();
|
||||
|
||||
async Task<IReadOnlyList<(string Member, string Inbox)>> CircleRecipients(string groupId, CancellationToken token)
|
||||
async Task<IReadOnlyList<ForeignAvatar>> CircleRecipients(string groupId, CancellationToken token)
|
||||
{
|
||||
var circle = string.IsNullOrEmpty(groupId) ? default : await _dbEntities.Groups.MatchID(groupId).ExecuteFirstAsync(token);
|
||||
if (circle == default)
|
||||
return Array.Empty<(string, string)>();
|
||||
return Array.Empty<ForeignAvatar>();
|
||||
var remote = circle.Members.Where(m => m.IsForeign).Select(m => m.AvatarId).ToList();
|
||||
if (remote.Count == 0)
|
||||
return Array.Empty<(string, string)>();
|
||||
return Array.Empty<ForeignAvatar>();
|
||||
return (await _dbEntities.ForeignAvatars.Match(a => remote.Contains(a.ActorURI)).ExecuteAsync(token))
|
||||
.Where(a => !string.IsNullOrEmpty(a.InboxURL))
|
||||
.Select(a => (a.ActorURI, a.InboxURL))
|
||||
.ToList();
|
||||
}
|
||||
|
||||
@@ -95,8 +95,8 @@ namespace PrivaPub.Federation.Outbox
|
||||
{
|
||||
if (post.Visibility == PostVisibility.Circle)
|
||||
{
|
||||
foreach (var (member, inbox) in await CircleRecipients(post.GroupId, token))
|
||||
await _delivery.Enqueue(author, new[] { inbox }, Naming(activity, new[] { member }), token);
|
||||
foreach (var member in await CircleRecipients(post.GroupId, token))
|
||||
await _delivery.Enqueue(author, new[] { member.InboxURL }, Naming(activity, new[] { member }), token);
|
||||
return;
|
||||
}
|
||||
var inboxes = await Audience(author, post, token);
|
||||
@@ -110,27 +110,44 @@ namespace PrivaPub.Federation.Outbox
|
||||
await Publish(author, post, ActivityPubRenderer.UpdateOf(post, author, group, reason), token);
|
||||
}
|
||||
|
||||
// Mastodon and GoToSocial keep a post only when it names one of their own accounts, and a circle post names only the
|
||||
// circle. So each member's copy, or a member's refetch, also names that member in cc (owner decision 2026-10-04):
|
||||
// it tells each member nothing but that they are in the circle.
|
||||
public static JsonObject Naming(JsonObject activityOrObject, IEnumerable<string> members)
|
||||
// Mastodon keeps a post only when it names one of its own accounts, and GoToSocial shows a post that is neither
|
||||
// public nor for followers only to the accounts it mentions; a circle post names only the circle. So each member's
|
||||
// copy, or a member's refetch, also names that member in cc and mentions them, silently, in its tags (owner decision
|
||||
// 2026-10-04): it tells each member nothing but that they are in the circle.
|
||||
public static JsonObject Naming(JsonObject activityOrObject, IEnumerable<ForeignAvatar> members)
|
||||
{
|
||||
var named = members.ToList();
|
||||
var copy = (JsonObject)activityOrObject.DeepClone();
|
||||
Name(copy, members);
|
||||
if (copy["object"] is JsonObject inner && inner.ContainsKey("to"))
|
||||
Name(inner, members);
|
||||
if (copy["object"] is JsonObject inner)
|
||||
{
|
||||
Name(copy, named, mention: false);
|
||||
if (inner.ContainsKey("to"))
|
||||
Name(inner, named, mention: true);
|
||||
}
|
||||
else
|
||||
Name(copy, named, mention: copy.ContainsKey("attributedTo"));
|
||||
return copy;
|
||||
}
|
||||
|
||||
static void Name(JsonObject node, IEnumerable<string> members)
|
||||
static void Name(JsonObject node, IReadOnlyList<ForeignAvatar> members, bool mention)
|
||||
{
|
||||
var cc = node["cc"] as JsonArray ?? new JsonArray();
|
||||
var tags = node["tag"] as JsonArray ?? new JsonArray();
|
||||
foreach (var member in members)
|
||||
if (!cc.Any(c => c?.GetValue<string>() == member))
|
||||
cc.Add(member);
|
||||
{
|
||||
if (!cc.Any(c => c?.GetValue<string>() == member.ActorURI))
|
||||
cc.Add(member.ActorURI);
|
||||
if (mention && !tags.Any(t => t?["href"]?.GetValue<string>() == member.ActorURI))
|
||||
tags.Add(new JsonObject { ["type"] = "Mention", ["href"] = member.ActorURI, ["name"] = Handle(member) });
|
||||
}
|
||||
node["cc"] = cc;
|
||||
if (mention)
|
||||
node["tag"] = tags;
|
||||
}
|
||||
|
||||
static string Handle(ForeignAvatar member) =>
|
||||
string.IsNullOrEmpty(member.UserName) ? member.ActorURI : $"@{member.UserName}@{new Uri(member.ActorURI).Authority}";
|
||||
|
||||
public async Task PublishProfile(LocalActor actor, CancellationToken token)
|
||||
{
|
||||
var document = ActivityPubRenderer.Actor(actor);
|
||||
|
||||
Reference in new issue
Block a user