Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
a7ffbea
Accept actorless FeatureRequest activities
dahlia Oct 10, 2026
0f477c5
Recheck collection owner after HTTP fallback
dahlia Oct 10, 2026
a5b2a6d
Keep transient collection failures retryable
dahlia Oct 10, 2026
9b84dda
Bind queued owners to authenticated instruments
dahlia Oct 10, 2026
ebb78d5
Authenticate before resolving collection owners
dahlia Oct 10, 2026
8730d0e
Dereference collections without account discovery
dahlia Oct 10, 2026
09f7f29
Check collection origin after redirects
dahlia Oct 10, 2026
be7774b
Freeze authenticated FeatureRequest queue views
dahlia Oct 10, 2026
2eb01c2
Reject malformed FeatureRequest collections
dahlia Oct 10, 2026
929e6f7
Use the owner's proof-verified activity view
dahlia Oct 10, 2026
d0ed260
Reject malformed collection dates and contexts
dahlia Oct 10, 2026
4765d02
Scope owner proofs to their parsed activity
dahlia Oct 10, 2026
3d5cff1
Reject oversized FeatureRequest collections
dahlia Oct 10, 2026
3040f52
Reject unusable successful collection responses
dahlia Oct 10, 2026
ff38ae4
Require one complete FeatureRequest instrument
dahlia Oct 10, 2026
2adad42
Reject credentials in FeatureRequest instruments
dahlia Oct 10, 2026
675c6d2
Test credential rejection through the inbox
dahlia Oct 10, 2026
ad64ad5
Validate every collection attribution
dahlia Oct 10, 2026
f9ec7d4
Reject unusable collection redirects
dahlia Oct 10, 2026
3f5ca6f
Reject cyclic and excessive collection redirects
dahlia Oct 10, 2026
3e0b5f3
Require absent actors before owner inference
dahlia Oct 10, 2026
25ebc02
Keep document scheme checks with private access
dahlia Oct 10, 2026
dc6c318
Count list-wrapped collection attributions
dahlia Oct 10, 2026
356d03f
Reject malformed collection language tags
dahlia Oct 10, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,28 @@ Version 2.4.3

To be released.

### @fedify/fedify

- Fixed `getAuthenticatedDocumentLoader()` skipping URL scheme validation
when `allowPrivateAddress` was enabled. Unsupported schemes are now
rejected before fetching, including redirect and alternate document
targets. [[#1291], [#1292]]
- Fixed the inbox rejecting FEP-7aa9 `FeatureRequest` activities without
an `actor`, allowing applications to receive collection inclusion
requests from Mastodon. Requests are accepted only when authenticated
as the referenced collection's owner. [[#1289], [#1291]]

[#1289]: https://github.com/fedify-dev/fedify/issues/1289
[#1291]: https://github.com/fedify-dev/fedify/pull/1291
[#1292]: https://github.com/fedify-dev/fedify/issues/1292

### @fedify/vocab-runtime

- Fixed `getDocumentLoader()` skipping URL scheme validation when
`allowPrivateAddress` was enabled. Unsupported schemes are now rejected
before fetching, including redirect and alternate document targets.
[[#1291], [#1292]]


Version 2.4.2
-------------
Expand Down
9 changes: 9 additions & 0 deletions changes.d/fedify/actorless-feature-requests.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
links:
'#1289': https://github.com/fedify-dev/fedify/issues/1289
'#1291': https://github.com/fedify-dev/fedify/pull/1291
---
- Fixed the inbox rejecting FEP-7aa9 `FeatureRequest` activities without
an `actor`, allowing applications to receive collection inclusion
requests from Mastodon. Requests are accepted only when authenticated
as the referenced collection's owner. [[#1289], [#1291]]
4 changes: 4 additions & 0 deletions changes.d/fedify/document-url-schemes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
- Fixed `getAuthenticatedDocumentLoader()` skipping URL scheme validation
when `allowPrivateAddress` was enabled. Unsupported schemes are now
rejected before fetching, including redirect and alternate document
targets. [[#1291], [#1292]]
4 changes: 4 additions & 0 deletions changes.d/vocab-runtime/document-url-schemes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
- Fixed `getDocumentLoader()` skipping URL scheme validation when
`allowPrivateAddress` was enabled. Unsupported schemes are now rejected
before fetching, including redirect and alternate document targets.
[[#1291], [#1292]]
Loading
Loading