Use the key cache in RequestContext.getSignedKey() #1122
Copy link
Copy link
Labels
component/federationFederation object relatedFederation object relatedcomponent/signaturesOIP or HTTP/LD Signatures relatedOIP or HTTP/LD Signatures relateddifficulty/beginnerBeginner friendlyBeginner friendly
Milestone
Description
Activity
- addedcomponent/federationFederation object relatedFederation object relatedcomponent/signaturesOIP or HTTP/LD Signatures relatedOIP or HTTP/LD Signatures relateddifficulty/beginnerBeginner friendlyBeginner friendly
on Sep 29, 2026 Hi! I’d like to work on this issue.
I’ll implement the proposed KvKeyCache integration in RequestContext.getSignedKey() and add the tests described above.
Reacted by ChanHaeng Lee@rewrite0w0 Assigned. Thanks!
- linked a pull request that will close this issueUse the key cache in `RequestContext.getSignedKey()` #1209
on Oct 4, 2026
Metadata
Metadata
Assignees
Labels
component/federationFederation object relatedFederation object relatedcomponent/signaturesOIP or HTTP/LD Signatures relatedOIP or HTTP/LD Signatures relateddifficulty/beginnerBeginner friendlyBeginner friendly
Type
Fields
Priority
None yet
Effort
None yet
Background
RequestContext.getSignedKey()callsverifyRequest()without akeyCache, so every call fetches the signer's key, and so does everygetSignedKeyOwner()call. Inbox handling passes aKvKeyCache; this path never has.The access control guide calls
getSignedKeyOwner()in authorize predicates, so every signedGETof a protected actor, object, or collection makes Fedify fetch the key again. A bogus key ID also costs one fetch per request, which inboxes avoid through the negative cache.Proposed work
Give
getSignedKey()the sameKvKeyCachethat inbox handling builds, underkvPrefixes.publicKeywithpublicKeyTtl.verifyRequest()already refetches a cached key that fails to verify, so key rotation keeps working.Open questions:
GetSignedKeyOptionslet a caller opt out, e.g., for an endpoint that wants a fresh key every time?Tests
getSignedKey()calls across requests with the same key ID fetch the key once within its TTL.