Skip to content

Commit a7ffbea

Browse files
committed
Accept actorless FeatureRequest activities
Authenticate actorless FEP-7aa9 requests against the owner of the referenced collection, then use that owner as the actor passed to the listener. Preserve the signed document and carry the authenticated owner through queued processing and retries. Keep transient collection lookup failures retryable, and reject the activity on permanent failures. Add regression coverage for HTTP Signatures, Linked Data Signatures and Object Integrity Proofs, mixed signatures, forged ownership, queue retries and lookup errors. Fixes #1289 General inbox principal handling is deferred to: #1290 Codex assisted the implementation and tests and reviewed the plan with gpt-6-astra. Claude Code assisted the fixes from code review. Assisted-by: Codex:gpt-6.1-sol Assisted-by: Claude Code:claude-opus-5-5
1 parent 15508cc commit a7ffbea

8 files changed

Lines changed: 667 additions & 0 deletions

File tree

‎CHANGES.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,16 @@ Version 2.4.3
88

99
To be released.
1010

11+
### @fedify/fedify
12+
13+
- Fixed the inbox rejecting FEP-7aa9 `FeatureRequest` activities without
14+
an `actor`, allowing applications to receive collection inclusion
15+
requests from Mastodon. Requests are accepted only when authenticated
16+
as the referenced collection's owner. [[#1289], [#1291]]
17+
18+
[#1289]: https://github.com/fedify-dev/fedify/issues/1289
19+
[#1291]: https://github.com/fedify-dev/fedify/pull/1291
20+
1121

1222
Version 2.4.2
1323
-------------
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
links:
3+
'#1289': https://github.com/fedify-dev/fedify/issues/1289
4+
'#1291': https://github.com/fedify-dev/fedify/pull/1291
5+
---
6+
- Fixed the inbox rejecting FEP-7aa9 `FeatureRequest` activities without
7+
an `actor`, allowing applications to receive collection inclusion
8+
requests from Mastodon. Requests are accepted only when authenticated
9+
as the referenced collection's owner. [[#1289], [#1291]]

0 commit comments

Comments
 (0)