Everything on, phase 3: sign-in and recovery tell nothing, recovered passwords end sessions, deleted roots are gone everywhere
Owner decision 2026-10-04: fix the account privacy findings.
- Sign-in. Every failure answers "That username and password do not match." after the same work: an unknown login
is hashed against a decoy, and the comparison is constant-time. "Banned" is told only to someone who gave the right
password. This covers /clientapi/user/login, /invitation/login and /oauth/login.
- Recovery.
- Every request answers the same sentence and queues a SendRecovery job, whether or not the account exists or has an
email. The lookup, the code and SMTP move to RecoveryJob, so neither the answer nor its timing says anything.
- Codes are kept only as a SHA-256 hash, for one hour. Migration _011 drops the plaintext ones, which never expired.
- A recovered password ends every session of the root. RootSessions sets CredentialsChangedAt, which JwtEvents
checks against the JWT's issue time, now stamped as nbf, and revokes each persona's OAuth tokens and authorizations.
- Deleting a root (RootRemoval: the admin route, or the restored self-delete at /clientapi/user/delete, which asks for
the password).
- Its sessions end.
- Each persona and each group it owns sends Delete{Actor} to its followers, its members and the accounts it follows.
- The personas' posts are emptied.
- /peasants/{name} answers 410 with a Tombstone (formerType Person or Group), as do its inbox and WebFinger, through
LocalActorService.Gone. The names stay reserved.
- The root keeps only a unique `deleted-{id}` name; the second deletion on an instance used to collide on
"Deleted user".
Also, from phase 2's pasture: GoToSocial files a circle post like a DM and shows it only to accounts it mentions. Each
member's copy, and a member's refetch, now also mentions that member silently. The GoToSocial scenario checks circle
posts in conversations, like DMs, and they pass there now, as on Mastodon.
657 tests pass.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
This commit is contained in:
1 parent
fcd35f5043
commit
8c2eba6cbb
25 files changed
+665
-248
No files matched your search
@@ -0,0 +1,119 @@
|
||||
using MongoDB.Entities;
|
||||
|
||||
using PrivaPub.Federation.Actors;
|
||||
using PrivaPub.Federation.Outbox;
|
||||
using PrivaPub.Federation.Rendering;
|
||||
using PrivaPub.Models.Federation;
|
||||
using PrivaPub.Models.Social;
|
||||
using PrivaPub.Models.User;
|
||||
using PrivaPub.StaticServices;
|
||||
|
||||
using System.Text.Json.Nodes;
|
||||
|
||||
using GroupEntity = PrivaPub.Models.Group.Group;
|
||||
using PostEntity = PrivaPub.Models.Post.Post;
|
||||
|
||||
namespace PrivaPub.Services
|
||||
{
|
||||
public interface IRootRemoval
|
||||
{
|
||||
Task<bool> Remove(string rootId, CancellationToken token);
|
||||
}
|
||||
|
||||
// Deleting a root deletes everything public it had (owner decision 2026-10-04): each persona, and each group a persona
|
||||
// owns, is announced deleted with a Delete of the actor to everyone who follows it, every member and everyone it
|
||||
// follows; their posts are emptied; their names stay reserved, and their documents answer 410 from then on. The root's
|
||||
// sessions end first, so nothing acts as it while it goes.
|
||||
public class RootRemoval : IRootRemoval
|
||||
{
|
||||
readonly DbEntities _dbEntities;
|
||||
readonly ILocalActorService _localActors;
|
||||
readonly IDeliveryService _delivery;
|
||||
readonly IRootSessions _sessions;
|
||||
|
||||
public RootRemoval(DbEntities dbEntities, ILocalActorService localActors, IDeliveryService delivery, IRootSessions sessions)
|
||||
{
|
||||
_dbEntities = dbEntities;
|
||||
_localActors = localActors;
|
||||
_delivery = delivery;
|
||||
_sessions = sessions;
|
||||
}
|
||||
|
||||
public async Task<bool> Remove(string rootId, CancellationToken token)
|
||||
{
|
||||
var root = await _dbEntities.RootUsers.MatchID(rootId).Match(u => u.DeletedAt == null).ExecuteFirstAsync(token);
|
||||
if (root == default)
|
||||
return false;
|
||||
await _sessions.Revoke(root.ID, token);
|
||||
var now = DateTime.UtcNow;
|
||||
|
||||
var avatarIds = (await _dbEntities.RootToAvatars.Match(ra => ra.RootId == root.ID).ExecuteAsync(token)).Select(ra => ra.AvatarId).ToList();
|
||||
var avatars = await _dbEntities.Avatars.Match(a => avatarIds.Contains(a.ID) && !a.DeletionAt.HasValue).ExecuteAsync(token);
|
||||
foreach (var avatar in avatars)
|
||||
{
|
||||
foreach (var group in await _dbEntities.Groups.Match(g => g.OwnerAvatarId == avatar.ID && !g.DeletionAt.HasValue).ExecuteAsync(token))
|
||||
{
|
||||
await Announce(_localActors.FromGroup(group), group.Members.Where(m => m.IsForeign).Select(m => m.AvatarId), token);
|
||||
await DB.Default.Update<GroupEntity>().MatchID(group.ID).Modify(g => g.DeletionAt, now).ExecuteAsync(token);
|
||||
}
|
||||
var persona = _localActors.FromAvatar(avatar);
|
||||
var followed = (await _dbEntities.Followings.Match(f => f.AvatarId == avatar.ID && !f.TargetIsLocal).ExecuteAsync(token))
|
||||
.Select(f => f.TargetActorURI);
|
||||
await Announce(persona, followed, token);
|
||||
await DB.Default.Update<Avatar>().MatchID(avatar.ID).Modify(a => a.DeletionAt, now).ExecuteAsync(token);
|
||||
await Empty(avatar.ID, now, token);
|
||||
}
|
||||
|
||||
await DB.Default.Update<RootUser>().MatchID(root.ID)
|
||||
.Modify(u => u.UserName, $"deleted-{root.ID}")//unique, so a second deletion never collides with the first
|
||||
.Modify(u => u.Email, null)
|
||||
.Modify(u => u.HashedPassword, null)
|
||||
.Modify(u => u.Policies, new List<string>())
|
||||
.Modify(u => u.IsBanned, false)
|
||||
.Modify(u => u.IsEmailValidated, false)
|
||||
.Modify(u => u.DeletedAt, now)
|
||||
.ExecuteAsync(token);
|
||||
await DB.Default.DeleteAsync<EmailRecovery>(r => r.RootUserId == root.ID);
|
||||
return true;
|
||||
}
|
||||
|
||||
// Delete{Actor}: to its followers' (shared) inboxes, and to the inboxes of the other accounts named
|
||||
async Task Announce(LocalActor actor, IEnumerable<string> others, CancellationToken token)
|
||||
{
|
||||
var inboxes = (await _delivery.FollowerInboxes(actor, token)).ToList();
|
||||
var named = others.Where(uri => !string.IsNullOrEmpty(uri)).Distinct().ToList();
|
||||
if (named.Count > 0)
|
||||
inboxes.AddRange((await _dbEntities.ForeignAvatars.Match(a => named.Contains(a.ActorURI)).ExecuteAsync(token))
|
||||
.Select(a => string.IsNullOrEmpty(a.SharedInboxURL) ? a.InboxURL : a.SharedInboxURL));
|
||||
await _delivery.Enqueue(actor, inboxes.Where(i => !string.IsNullOrEmpty(i)).Distinct(), new JsonObject
|
||||
{
|
||||
["@context"] = ActivityPubRenderer.Context(),
|
||||
["id"] = actor.ActivityUri("delete-actor"),
|
||||
["type"] = "Delete",
|
||||
["actor"] = actor.Uri,
|
||||
["object"] = actor.Uri,
|
||||
["to"] = new JsonArray(ActivityPubRenderer.Public),
|
||||
["cc"] = new JsonArray(actor.Followers)
|
||||
}, token);
|
||||
}
|
||||
|
||||
// a persona's posts keep their ids and lose their content, like a single deleted post; a group writes none of its own
|
||||
static async Task Empty(string avatarId, DateTime now, CancellationToken token)
|
||||
{
|
||||
var postIds = (await DB.Default.Find<PostEntity>().Match(p => p.GroupUserId == avatarId && !p.IsFederatedCopy && !p.DeletedAt.HasValue)
|
||||
.Project(p => p.Include(x => x.ID)).ExecuteAsync(token)).Select(p => p.ID).ToList();
|
||||
if (postIds.Count == 0)
|
||||
return;
|
||||
await DB.Default.Update<PostEntity>().Match(p => postIds.Contains(p.ID))
|
||||
.Modify(p => p.DeletedAt, now)
|
||||
.Modify(p => p.Text, null)
|
||||
.Modify(p => p.ContentHtml, null)
|
||||
.Modify(p => p.Title, null)
|
||||
.Modify(p => p.SpoilerText, null)
|
||||
.Modify(p => p.Media, new List<Models.Post.PostMedia>())
|
||||
.Modify(p => p.Revisions, new List<Models.Post.PostRevision>())
|
||||
.ExecuteAsync(token);
|
||||
await DB.Default.DeleteAsync<TimelineEntry>(e => postIds.Contains(e.PostId) || postIds.Contains(e.ReblogOfPostId));
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user