Improvements to signature verification#9667
Merged
Gargron merged 4 commits intomastodon:masterfrom Jan 7, 2019
Merged
Conversation
93e0949 to
48d1b7d
Compare
48d1b7d to
3cabf7d
Compare
But when the account is not marked as stale, avoid fetching collections and media, and avoid webfinger round-trip.
3cabf7d to
9be1988
Compare
Gargron
approved these changes
Jan 7, 2019
hiyuki2578
pushed a commit
to ProjectMyosotis/mastodon
that referenced
this pull request
Oct 2, 2019
* Refactor signature verification a bit * Rescue signature verification if recorded public key is invalid Fixes mastodon#8822 * Always re-fetch AP signing key when HTTP Signature verification fails But when the account is not marked as stale, avoid fetching collections and media, and avoid webfinger round-trip. * Apply stoplight to key/account update as well as initial key retrieval
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This part of the code is a bit hairy, this should be thoroughly reviewed, and tests should probably be added.