Anyone could mint signed proxy URLs (a remote account changes its icon, an anonymous lookup returns the URL), and each anonymous request held up to 40 MB in memory; the cache grew without bound between hourly trims; two clients asking for the same new file downloaded it twice and wrote over each other in place, so a reader could get half a file with a 7-day cache header; a file over the limit was downloaded twice on every request; a failed fetch, a 404, was cached by browsers for a week; cached media of a server suspended later were still served, and RejectMedia skipped avatars, emoji, covers, video variants, link cards and remote edits; /clientapi/group/members returned remote pictures raw. Now a download is shared by everyone asking at once, streamed into a .part file and renamed into place (FederationHttp.DownloadMedia copies bounded, never into memory), at most eight at a time; a file too big to cache is remembered for an hour and only streamed, a failure for five minutes; the cache's size is counted as it grows and trimmed as soon as it passes the cap; a cached file is opened before it is answered; browsers may cache only a success; nothing of a suspended server, or of one whose media are rejected, is proxied (everything remote a client sees goes through the proxy, so that covers every kind), and blocking one purges its cache; the proxy has its own rate limit per client address; group members' pictures are proxied; the proxy's key is loaded once, the oldest if two were made. This changes what PrivaPub serves its clients, not what it sends to other servers. Tests: clients asking at once share one download, a failure isn't cached by browsers, an over-limit file is fetched three times for two requests instead of four, a blocked server's media are refused and its cache purged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
80 lines
2.8 KiB
C#
80 lines
2.8 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.Extensions.Localization;
|
|
|
|
using MongoDB.Entities;
|
|
|
|
using PrivaPub.ClientModels;
|
|
using PrivaPub.ClientModels.Admin;
|
|
using PrivaPub.Federation.Moderation;
|
|
using PrivaPub.Models.Federation;
|
|
using PrivaPub.Resources;
|
|
|
|
namespace PrivaPub.Controllers.ClientToServer
|
|
{
|
|
[ApiController,
|
|
Route("clientapi/admin/domainblocks"),
|
|
Authorize(Policy = Policies.IsAdmin)]
|
|
public class DomainBlockController : ControllerBase
|
|
{
|
|
readonly IDomainBlocks _domainBlocks;
|
|
readonly IStringLocalizer _localizer;
|
|
readonly Domain.Media.IMediaProxy _proxy;
|
|
|
|
public DomainBlockController(IDomainBlocks domainBlocks, IStringLocalizer<GenericRes> localizer, Domain.Media.IMediaProxy proxy)
|
|
{
|
|
_domainBlocks = domainBlocks;
|
|
_localizer = localizer;
|
|
_proxy = proxy;
|
|
}
|
|
|
|
[HttpGet, Route("/clientapi/admin/domainblocks/list")]
|
|
public async Task<IActionResult> List(CancellationToken token) =>
|
|
Ok((await DB.Default.Find<DomainBlock>().Sort(b => b.Domain, Order.Ascending).ExecuteAsync(token)).Select(ToView).ToList());
|
|
|
|
[HttpPost, Route("/clientapi/admin/domainblocks/insert")]
|
|
public async Task<IActionResult> Insert(DomainBlockForm form, CancellationToken token)
|
|
{
|
|
var domain = DomainBlocks.Normalise(form.Domain);
|
|
if (!ModelState.IsValid || Uri.CheckHostName(domain) != UriHostNameType.Dns)
|
|
return BadRequest(new WebResult().Invalidate(_localizer["Invalid model."]));
|
|
|
|
var block = await DB.Default.UpdateAndGet<DomainBlock>()
|
|
.Match(b => b.Domain == domain)
|
|
.Modify(b => b.Domain, domain)
|
|
.Modify(b => b.Severity, form.Suspend ? DomainBlockSeverity.Suspend : DomainBlockSeverity.Silence)
|
|
.Modify(b => b.RejectMedia, form.RejectMedia)
|
|
.Modify(b => b.PublicComment, form.PublicComment)
|
|
.Modify(b => b.PrivateComment, form.PrivateComment)
|
|
.Modify(b => b.SetOnInsert(x => x.CreatedAt, DateTime.UtcNow))
|
|
.Option(o => o.IsUpsert = true)
|
|
.ExecuteAsync(token);
|
|
await _domainBlocks.Reload(token);
|
|
// what the media proxy holds of it goes with the block
|
|
if (block.Severity == DomainBlockSeverity.Suspend || block.RejectMedia)
|
|
_proxy.Purge(domain);
|
|
return Ok(ToView(block));
|
|
}
|
|
|
|
[HttpPost, Route("/clientapi/admin/domainblocks/delete")]
|
|
public async Task<IActionResult> Delete([FromQuery] string domain, CancellationToken token)
|
|
{
|
|
domain = DomainBlocks.Normalise(domain);
|
|
await DB.Default.DeleteAsync<DomainBlock>(b => b.Domain == domain);
|
|
await _domainBlocks.Reload(token);
|
|
return Ok();
|
|
}
|
|
|
|
static ViewDomainBlock ToView(DomainBlock block) => new()
|
|
{
|
|
Id = block.ID,
|
|
Domain = block.Domain,
|
|
Severity = block.Severity.ToString(),
|
|
RejectMedia = block.RejectMedia,
|
|
PublicComment = block.PublicComment,
|
|
PrivateComment = block.PrivateComment,
|
|
CreatedAt = block.CreatedAt
|
|
};
|
|
}
|
|
}
|