Skip to content
Snippets Groups Projects
This project is mirrored from https://git.pleroma.social/pleroma/pleroma.git. Pull mirroring updated .
  1. Mar 01, 2025
  2. Feb 27, 2025
  3. Feb 24, 2025
  4. Feb 23, 2025
  5. Feb 22, 2025
    • Oneric's avatar
      changelog: add entries for preceding commits · 7c23793e
      Oneric authored
      7c23793e
    • Oneric's avatar
      federation: strip internal fields from incoming updates and history · 8243fc0e
      Oneric authored
      When note editing support was added, it was omitted to strip internal
      fields from edited notes and their history.
      
      This was uncovered due to Mastodon inlining the like count as a "likes"
      collection conflicting with our internal "likes" list causing validation
      failures. In a spot check with likes/like_count it was not possible to
      inject those internal fields into the local db via Update, but this
      was not extensively tested for all fields and avenues.
      
      Similarly address normalisation did not normalise addressing in the
      object history, although this was never at risk of being exploitable.
      
      The revision history of the Pleroma MR adding edit support reveals
      recusrive stripping was intentionally avoided, since it will end up
      removing e.g. emoji from outgoing activities. This appears to still
      be true. However, all current internal fields ("pleroma_interal"
      appears to be unused) contain data already publicised otherwise anyway.
      In the interest of fixing a federation bug (and at worst potential data
      injection) quickly outgoing stripping is left non-recursive for now.
      
      Of course the ultimate fix here is to not mix remote and internal data
      into the same map in the first place, but unfortunately having a single
      map of all truth is a core assumption of *oma's AP doc processing.
      Changing this is a masive undertaking and not suitable for providing
      a short-term fix.
      8243fc0e
    • Oneric's avatar
    • Oneric's avatar
      http_signatures: tweak order of route aliases · d8e40173
      Oneric authored
      We expect most requests to be made for the actual canonical ID,
      so check this one first (starting without query headers matching the
      predominant albeit spec-breaking version).
      
      Also avoid unnecessary rerewrites of the digest header on each route
      alias by just setting it once before iterating through aliases.
      d8e40173
    • Oneric's avatar
      signature: refetch key upon verification failure · 9cc5fe9a
      Oneric authored
      This matches behaviour prioir to the SigningKey migration
      and the expected semantics of the http_signatures lib.
      Additionally add a min interval paramter, to avoid
      refetch floods on bugs causing incompatible signatures
      (like e.g. currently with Bridgy)
      9cc5fe9a
    • floatingghost's avatar
      Merge pull request 'Expose Port IO stats via Prometheus' (#869) from... · 35526385
      floatingghost authored
      Merge pull request 'Expose Port IO stats via Prometheus' (#869) from Oneric/akkoma:io-telemetry into develop
      
      Reviewed-on: https://akkoma.dev/AkkomaGang/akkoma/pulls/869
      35526385
  6. Feb 15, 2025
Loading