Personas prove what goes to relays; the server says what it reads
FEP-521a and FEP-8b32. Every persona has an Ed25519 key of its own (Avatar.SigningKey; migration 014 gives the earlier ones theirs), named in its actor's assertionMethod as a Multikey, the terms defined in the actor's own context. A persona's activity going to a relay carries an eddsa-jcs-2022 proof (JSON canonicalised by RFC 8785, Jcs), so what Activity-Relay forwards reaches Mastodon, which verifies it with its own code. Nothing else carries one: Mitra takes a proof over the HTTP signature and refuses one by a key it has not read, without reading the actor again. Received: an actor's own Multikeys are kept, and a forwarded activity whose proof one of them verifies is taken as it came instead of being read again from its origin. Discovery: WebFinger for the server's origin links its instance actor (FEP-d556), NodeInfo links it as the application actor (FEP-2677), and actors name RFC 9421 under implements (FEP-844e). Checked live: relay 16 (Activity-Relay's forward of alice's post reaches Mastodon), Mitra, GoToSocial and Mastodon unchanged (165 in all). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
c47b6e5533
commit
9ab87b2779
22 files changed
+702
-30
No files matched your search
@@ -36,6 +36,19 @@ namespace PrivaPub.Federation.Controllers
|
||||
{
|
||||
if (string.IsNullOrEmpty(resource))
|
||||
return BadRequest();
|
||||
// the server itself (FEP-d556): its instance actor
|
||||
if (resource.TrimEnd('/') == _localActors.BaseAddress)
|
||||
{
|
||||
var instance = await _localActors.GetInstanceActor(token);
|
||||
return Content(new JsonObject
|
||||
{
|
||||
["subject"] = resource,
|
||||
["links"] = new JsonArray(new JsonObject
|
||||
{
|
||||
["rel"] = "https://www.w3.org/ns/activitystreams#Service", ["type"] = "application/activity+json", ["href"] = instance.Uri
|
||||
})
|
||||
}.ToJsonString(), "application/jrd+json; charset=utf-8");
|
||||
}
|
||||
|
||||
LocalActor actor;
|
||||
// Mastodon, GoToSocial and Pleroma also take a bare user@domain or @user@domain, so we do too.
|
||||
@@ -72,7 +85,7 @@ namespace PrivaPub.Federation.Controllers
|
||||
}
|
||||
|
||||
[HttpGet, Route("/.well-known/nodeinfo")]
|
||||
public IActionResult NodeInfoLinks()
|
||||
public async Task<IActionResult> NodeInfoLinks(CancellationToken token)
|
||||
{
|
||||
var document = new JsonObject
|
||||
{
|
||||
@@ -86,6 +99,12 @@ namespace PrivaPub.Federation.Controllers
|
||||
{
|
||||
["rel"] = "http://nodeinfo.diaspora.software/ns/schema/2.0",
|
||||
["href"] = $"{_localActors.BaseAddress}/nodeinfo/2.0"
|
||||
},
|
||||
// the application actor (FEP-2677)
|
||||
new JsonObject
|
||||
{
|
||||
["rel"] = "https://www.w3.org/ns/activitystreams#Application",
|
||||
["href"] = (await _localActors.GetInstanceActor(token)).Uri
|
||||
})
|
||||
};
|
||||
return Content(document.ToJsonString(), "application/json; charset=utf-8");
|
||||
|
||||
Reference in new issue
Block a user