Domain blocks: suspend, silence, reject media
DomainBlock (domain, severity, reject-media, public and private comment)
covers the domain and its subdomains. Admins manage them under
/clientapi/admin/domainblocks/{list,insert,delete}; the set is kept in
memory, reloaded on every change and at most five minutes stale.
A suspended domain is refused by FederationHttp.IsAllowed, so nothing is
fetched from it and no job delivers to it, and the inbox drops its
activities with a 202 before fetching any key. Reject-media strips the
attachments of posts from that domain. Silence is recorded for the
timelines and notifications that arrive in P1.2.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
9ec1f9930b
commit
e6a362c0b8
13 files changed
+318
-13
No files matched your search
@@ -1,6 +1,8 @@
|
||||
using Microsoft.Extensions.Caching.Memory;
|
||||
using Microsoft.Extensions.Options;
|
||||
|
||||
using PrivaPub.Federation.Moderation;
|
||||
|
||||
using System.Net;
|
||||
using System.Text.Json;
|
||||
|
||||
@@ -41,14 +43,16 @@ namespace PrivaPub.Infrastructure.Http
|
||||
readonly IHttpClientFactory _httpClientFactory;
|
||||
readonly IMemoryCache _cache;
|
||||
readonly IOptionsMonitor<FederationOptions> _options;
|
||||
readonly IDomainBlocks _domainBlocks;
|
||||
readonly ILogger<FederationHttp> _logger;
|
||||
|
||||
public FederationHttp(IHttpClientFactory httpClientFactory, IMemoryCache cache, IOptionsMonitor<FederationOptions> options,
|
||||
ILogger<FederationHttp> logger)
|
||||
IDomainBlocks domainBlocks, ILogger<FederationHttp> logger)
|
||||
{
|
||||
_httpClientFactory = httpClientFactory;
|
||||
_cache = cache;
|
||||
_options = options;
|
||||
_domainBlocks = domainBlocks;
|
||||
_logger = logger;
|
||||
}
|
||||
|
||||
@@ -56,6 +60,8 @@ namespace PrivaPub.Infrastructure.Http
|
||||
{
|
||||
if (target is not { IsAbsoluteUri: true } || !string.IsNullOrEmpty(target.UserInfo))
|
||||
return false;
|
||||
if (_domainBlocks?.IsSuspended(target.Host) == true)
|
||||
return false;
|
||||
var options = _options.CurrentValue;
|
||||
if (target.Scheme != Uri.UriSchemeHttps && !(options.AllowPlainHttp && target.Scheme == Uri.UriSchemeHttp))
|
||||
return false;
|
||||
|
||||
Reference in new issue
Block a user