A private fediverse on the workstation: PrivaPub against a real GoToSocial
tools/pasture/run.sh starts PrivaPub, GoToSocial and Mongo on one podman network behind Caddy's internal CA, and interop.sh drives both through their own client APIs: follows (one to a locked account), posts, CW, replies, likes, boosts, DMs, edits, deletes and unfollow. All 25 checks pass, three fresh runs in a row. - Federation:AcceptAnyCertificate joins the two test-network switches; startup refuses all three in Production. - WebFinger falls back to http only when AllowPlainHttp is on. - A bootstrap logger, so a failure before the host is built is no longer silent. - P4 is ticked in the roadmap, with what has not been run live (Lemmy, a Mastodon circle member). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
31542a181e
commit
8f4d6cbdf9
12 files changed
+299
-12
No files matched your search
@@ -6,6 +6,7 @@ using PrivaPub.StaticServices;
|
||||
using System.Text.Json;
|
||||
|
||||
using Microsoft.Extensions.Caching.Memory;
|
||||
using Microsoft.Extensions.Options;
|
||||
|
||||
using PrivaPub.Federation.Objects;
|
||||
using PrivaPub.Federation.Signing;
|
||||
@@ -32,13 +33,16 @@ namespace PrivaPub.Federation.Actors
|
||||
readonly ILocalActorService _localActors;
|
||||
readonly IMemoryCache _cache;
|
||||
readonly DbEntities _dbEntities;
|
||||
readonly IOptionsMonitor<FederationOptions> _options;
|
||||
|
||||
public RemoteActorService(IFederationHttp http, ILocalActorService localActors, IMemoryCache cache, DbEntities dbEntities)
|
||||
public RemoteActorService(IFederationHttp http, ILocalActorService localActors, IMemoryCache cache, DbEntities dbEntities,
|
||||
IOptionsMonitor<FederationOptions> options = default)
|
||||
{
|
||||
_http = http;
|
||||
_localActors = localActors;
|
||||
_cache = cache;
|
||||
_dbEntities = dbEntities;
|
||||
_options = options;
|
||||
}
|
||||
|
||||
public async Task<FetchedJson> FetchObject(string uri, CancellationToken token)
|
||||
@@ -122,8 +126,11 @@ namespace PrivaPub.Federation.Actors
|
||||
if (parts is not { Length: 2 } || string.IsNullOrEmpty(parts[0]) || string.IsNullOrEmpty(parts[1]))
|
||||
return default;
|
||||
|
||||
var url = $"https://{parts[1]}/.well-known/webfinger?resource={Uri.EscapeDataString($"acct:{parts[0]}@{parts[1]}")}";
|
||||
using var fetched = await _http.GetJson(url, "application/jrd+json, application/json", sign: default, token);
|
||||
var query = $"/.well-known/webfinger?resource={Uri.EscapeDataString($"acct:{parts[0]}@{parts[1]}")}";
|
||||
using var fetched = await _http.GetJson($"https://{parts[1]}{query}", "application/jrd+json, application/json", sign: default, token)
|
||||
?? (_options?.CurrentValue.AllowPlainHttp == true
|
||||
? await _http.GetJson($"http://{parts[1]}{query}", "application/jrd+json, application/json", sign: default, token)
|
||||
: default);
|
||||
if (fetched == default)
|
||||
return default;
|
||||
var document = fetched.Document;
|
||||
|
||||
@@ -5,5 +5,6 @@ namespace PrivaPub.Infrastructure.Http
|
||||
public bool AllowPrivateNetworks { get; set; }
|
||||
public bool AllowPlainHttp { get; set; }
|
||||
public bool SecureMode { get; set; }
|
||||
public bool AcceptAnyCertificate { get; set; }
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,5 @@
|
||||
using System.Net;
|
||||
using System.Net.Security;
|
||||
using System.Net.Sockets;
|
||||
|
||||
namespace PrivaPub.Infrastructure.Http
|
||||
@@ -12,6 +13,9 @@ namespace PrivaPub.Infrastructure.Http
|
||||
{
|
||||
public static SocketsHttpHandler Create(FederationOptions options) => new()
|
||||
{
|
||||
SslOptions = options.AcceptAnyCertificate
|
||||
? new SslClientAuthenticationOptions { RemoteCertificateValidationCallback = (_, _, _, _) => true }
|
||||
: new SslClientAuthenticationOptions(),
|
||||
AllowAutoRedirect = false,
|
||||
UseProxy = false,
|
||||
UseCookies = false,
|
||||
|
||||
+8
-2
@@ -21,6 +21,8 @@ using PrivaPub.Models;
|
||||
using PrivaPub.Services;
|
||||
using PrivaPub.StaticServices;
|
||||
|
||||
Log.Logger = new LoggerConfiguration().WriteTo.Console().CreateBootstrapLogger();
|
||||
|
||||
try
|
||||
{
|
||||
var builder = WebApplication.CreateBuilder(args);
|
||||
@@ -71,8 +73,8 @@ try
|
||||
}
|
||||
|
||||
var federationOptions = builder.Configuration.GetSection("Federation").Get<FederationOptions>() ?? new();
|
||||
if (builder.Environment.IsProduction() && (federationOptions.AllowPrivateNetworks || federationOptions.AllowPlainHttp))
|
||||
throw new InvalidOperationException("Federation:AllowPrivateNetworks and Federation:AllowPlainHttp are for test networks and must stay off in Production.");
|
||||
if (builder.Environment.IsProduction() && (federationOptions.AllowPrivateNetworks || federationOptions.AllowPlainHttp || federationOptions.AcceptAnyCertificate))
|
||||
throw new InvalidOperationException("Federation:AllowPrivateNetworks, AllowPlainHttp and AcceptAnyCertificate are for test networks and must stay off in Production.");
|
||||
|
||||
try
|
||||
{
|
||||
@@ -189,4 +191,8 @@ catch (Exception ex)
|
||||
Log.ForContext<Program>().Fatal(ex, $"{nameof(Program)}.{nameof(Program)}()");
|
||||
Environment.ExitCode = 1;
|
||||
}
|
||||
finally
|
||||
{
|
||||
await Log.CloseAndFlushAsync();
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user