RFC 9421 signatures are verified, not refused
WordPress's ActivityPub plugin (and Ghost and Fedify) sign with RFC 9421 first and fall back to draft-cavage only after a refusal, so each first delivery cost two requests and a 401 in our statistics. Now a request carrying Signature-Input is verified as an HTTP message signature: its covered components (the method and our own public target, the body's Content-Digest), its created and expires, with the actor's RSA key under PKCS#1 v1.5 or PSS. Deliveries and signed fetches both take it; the ledger names the scheme (rfc9421:rsa-v1_5-sha256). What PrivaPub sends stays draft-cavage, which every server reads. Ed25519 waits for FEP-521a keys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
26dac40720
commit
c5a69d240a
10 files changed
+423
-30
No files matched your search
@@ -68,6 +68,22 @@ namespace PrivaPub.Tests.Support
|
||||
return request;
|
||||
}
|
||||
|
||||
// the same delivery signed as RFC 9421 does it (WordPress, Ghost, Fedify), for `signedFor` when it is not where the
|
||||
// request goes
|
||||
public HttpRequestMessage MessageSignedPost(string path, JsonNode activity, string signedFor = default, string origin = "https://privapub.test")
|
||||
{
|
||||
var body = Encoding.UTF8.GetBytes(activity.ToJsonString());
|
||||
var request = new HttpRequestMessage(HttpMethod.Post, new Uri(origin + (signedFor ?? path))) { Content = new ByteArrayContent(body) };
|
||||
request.Content.Headers.TryAddWithoutValidation("Content-Type", "application/activity+json");
|
||||
MessageSignatures.Sign(request, KeyId, _key.ExportPkcs8PrivateKeyPem(), body);
|
||||
request.RequestUri = new Uri(origin + path);
|
||||
return request;
|
||||
}
|
||||
|
||||
public string PrivateKeyPem => _key.ExportPkcs8PrivateKeyPem();
|
||||
|
||||
public string PublicKeyPem => _key.ExportSubjectPublicKeyInfoPem();
|
||||
|
||||
string Signature(string signingString, string headers)
|
||||
{
|
||||
var signature = Convert.ToBase64String(_key.SignData(Encoding.UTF8.GetBytes(signingString), HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1));
|
||||
|
||||
Reference in new issue
Block a user