Persona separation is tested, the API is smoke-checked on deploy, OAuth rows are pruned
- PersonaSeparationTests: two personas of one login follow the same account and post; nothing the API maps for one contains the other's id, username or the root id. - tools/smoke/mastodon-api.sh checks what a client meets first (instance v1/v2, discovery, app registration, client credentials, an app token refused by a user endpoint, the public timeline, revocation) and, given a persona token, verify_credentials, home and notifications. deploy.yml runs it after every deploy. - OAuthPruner removes invalid tokens and authorizations older than two weeks, every six hours. - The consent page no longer sets form-action, which browsers apply to the redirect back to the client after the form is posted. CLAUDE.md gains the Mastodon API layout and invariants. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
70b4c45eb0
commit
d8f163b5ce
7 files changed
+157
-3
No files matched your search
@@ -147,7 +147,7 @@ namespace PrivaPub.Web.Pages.OAuth
|
||||
.Where(p => p.Key is not ("avatarId" or "decision" or "signed_in"))
|
||||
.Select(p => new KeyValuePair<string, string>(p.Key, (string)p.Value))
|
||||
.ToList();
|
||||
Response.Headers["Content-Security-Policy"] = "default-src 'none'; style-src 'unsafe-inline'; form-action 'self'; frame-ancestors 'none'";
|
||||
Response.Headers["Content-Security-Policy"] = "default-src 'none'; style-src 'unsafe-inline'; frame-ancestors 'none'";
|
||||
Response.Headers["Cache-Control"] = "no-store";
|
||||
return Page();
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user