RFC 9421 signatures are verified, not refused
WordPress's ActivityPub plugin (and Ghost and Fedify) sign with RFC 9421 first and fall back to draft-cavage only after a refusal, so each first delivery cost two requests and a 401 in our statistics. Now a request carrying Signature-Input is verified as an HTTP message signature: its covered components (the method and our own public target, the body's Content-Digest), its created and expires, with the actor's RSA key under PKCS#1 v1.5 or PSS. Deliveries and signed fetches both take it; the ledger names the scheme (rfc9421:rsa-v1_5-sha256). What PrivaPub sends stays draft-cavage, which every server reads. Ed25519 waits for FEP-521a keys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
26dac40720
commit
c5a69d240a
10 files changed
+423
-30
No files matched your search
@@ -83,7 +83,8 @@ PrivaPub/ ASP.NET Core Web API, net10.0
|
||||
(authoritative fetch, key verification, WebFinger), ActorDocument (parser)
|
||||
Objects/ Origin, ActivityJson, NoteParser, Addressing, ContentSanitizer
|
||||
Moderation/ DomainBlocks (suspend / silence / reject media)
|
||||
Signing/ HttpSignatures (draft-cavage sign/verify)
|
||||
Signing/ HttpSignatures (draft-cavage sign/verify), MessageSignatures (RFC 9421 verify),
|
||||
RequestSignature (whichever a request carries)
|
||||
Inbox/ InboxReceiver (verify, queue, 202) → InboxProcessor (job) → Handlers/{Follow,Accept,Reject,
|
||||
Undo,Create,Update,Delete,Like,Announce}; RemotePosts (build, fetch parents, FetchAncestors);
|
||||
RemoteReplies (FetchReplies: a thread's `context`, else `replies` two levels down)
|
||||
@@ -159,7 +160,8 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
`HttpClient` for federation. The only other outbound traffic is SMTP and `GeoUpdater`'s monthly DB-IP Lite download
|
||||
(its own `geo` client, a fixed HTTPS host, size-capped, the file checked before it is swapped in).
|
||||
2. **Every fetch is signed by the instance actor** (`privapub`), never by a persona; deliveries are signed by the acting
|
||||
avatar or group. Both are draft-cavage rsa-sha256 over `(request-target) host date` (+ `digest` on bodies).
|
||||
avatar or group. Both are draft-cavage rsa-sha256 over `(request-target) host date` (+ `digest` on bodies). Inbound,
|
||||
an RFC 9421 signature (`Signature-Input`) is verified too, its target against our public address.
|
||||
3. **A remote document is believed only from its own address.** `RemoteActorService.FetchObject` requires the
|
||||
document's `id` to be the URL it was served from (a same-origin alias is followed once). A key is accepted only if
|
||||
the actor lists it, its `owner` is the actor and it shares the actor's origin.
|
||||
|
||||
Reference in new issue
Block a user