Skip to content
Snippets Groups Projects
  1. Dec 26, 2020
    • ThibG's avatar
      Fix being able to import more than allowed number of follows (#15384) · f1f96ebf
      ThibG authored
      
      * Fix being able to import more than allowed number of follows
      
      Without this commit, if someone tries importing a second list of accounts to
      follow before the first one has been processed, this will queue imports for
      the two whole lists, even if they exceed the account's allowed number of
      outgoing follows.
      
      This commit changes it so the individual queued imports aren't exempt from
      the follow limit check (they remain exempt from the rate-limiting check
      though).
      
      * Catch validation errors to not re-queue failed follows
      
      Co-authored-by: default avatarClaire <claire.github-309c@sitedethib.com>
      Unverified
      f1f96ebf
  2. Dec 22, 2020
  3. Dec 21, 2020
  4. Dec 18, 2020
  5. Dec 17, 2020
    • ThibG's avatar
      Improve searching for private toots from URL (#14856) · b1feb470
      ThibG authored
      
      * Improve searching for private toots from URL
      
      Most of the time, when sharing toots, people use the toot URL rather than
      the toot URI, which makes sense since it is the user-facing URL.
      
      In Mastodon's case, the URL and URI are different, and Mastodon does not
      have an index on URL, which means searching a private toot by URL is done
      with a slow query that will only succeed for very recent toots.
      
      This change gets rid of the slow query, and attempts to guess the URI from
      URL instead, as Mastodon's are predictable.
      
      * Add tests
      
      * Only return status with guessed uri if url matches
      
      Co-authored-by: default avatarClaire <claire.github-309c@sitedethib.com>
      Unverified
      b1feb470
  6. Dec 15, 2020
  7. Dec 14, 2020
  8. Dec 10, 2020
    • ThibG's avatar
      Add honeypot fields and minimum fill-out time for sign-up form (#15276) · 49eb4d4d
      ThibG authored
      
      * Add honeypot fields to limit non-specialized spam
      
      Add two honeypot fields: a fake website input and a fake password confirmation
      one. The label/placeholder/aria-label tells not to fill them, and they are
      hidden in CSS, so legitimate users should not fall into these.
      
      This should cut down on some non-Mastodon-specific spambots.
      
      * Require a 3 seconds delay before submitting the registration form
      
      * Fix tests
      
      * Move registration form time check to model validation
      
      * Give people a chance to clear the honeypot fields
      
      * Refactor honeypot translation strings
      
      Co-authored-by: default avatarClaire <claire.github-309c@sitedethib.com>
      Unverified
      49eb4d4d
  9. Dec 09, 2020
  10. Nov 21, 2020
  11. Nov 19, 2020
    • ThibG's avatar
      Fix webfinger redirect handling in ResolveAccountService (#15187) · 8b8004a9
      ThibG authored
      * Fix webfinger redirect handling in ResolveAccountService
      
      ResolveAccountService#process_webfinger! handled a one-step webfinger
      redirection, but only accepting the result if it matched the exact URI passed
      as input, defeating the point of a redirection check.
      
      Instead, use the same logic as in `ActivityPub::FetchRemoteAccountService`,
      updating the resulting `acct:` URI with the result of the first webfinger
      query.
      
      * Add tests
      Unverified
      8b8004a9
    • ThibG's avatar
      Add import/export feature for bookmarks (#14956) · 96c1e713
      ThibG authored
      * Add ability to export bookmarks
      
      * Add support for importing bookmarks
      
      * Add bookmark import tests
      
      * Add bookmarks export test
      Unverified
      96c1e713
  12. Nov 12, 2020
  13. Nov 09, 2020
  14. Nov 07, 2020
  15. Nov 04, 2020
  16. Oct 21, 2020
    • ThibG's avatar
      Add follower synchronization mechanism (#14510) · ca565271
      ThibG authored
      * Add support for followers synchronization on the receiving end
      
      Check the `collectionSynchronization` attribute on `Create` and `Announce`
      activities and synchronize followers from provided collection if possible.
      
      * Add tests for followers synchronization on the receiving end
      
      * Add support for follower synchronization on the sender's end
      
      * Add tests for the sending end
      
      * Switch from AS attributes to HTTP header
      
      Replace the custom `collectionSynchronization` ActivityStreams attribute by
      an HTTP header (`X-AS-Collection-Synchronization`) with the same syntax as
      the `Signature` header and the following fields:
      - `collectionId` to specify which collection to synchronize
      - `digest` for the SHA256 hex-digest of the list of followers known on the
         receiving instance (where “receiving instance” is determined by accounts
         sharing the same host name for their ActivityPub actor `id`)
      - `url` of a collection that should be fetched by the instance actor
      
      Internally, move away from the webfinger-based `domain` attribute and use
      account `uri` prefix to group accounts.
      
      * Add environment variable to disable followers synchronization
      
      Since the whole mechanism relies on some new preconditions that, in some
      extremely rare cases, might not be met, add an environment variable
      (DISABLE_FOLLOWERS_SYNCHRONIZATION) to disable the mechanism altogether and
      avoid followers being incorrectly removed.
      
      The current conditions are:
      1. all managed accounts' actor `id` and inbox URL have the same URI scheme and
         netloc.
      2. all accounts whose actor `id` or inbox URL share the same URI scheme and
         netloc as a managed account must be managed by the same Mastodon instance
         as well.
      
      As far as Mastodon is concerned, breaking those preconditions require extensive
      configuration changes in the reverse proxy and might also cause other issues.
      
      Therefore, this environment variable provides a way out for people with highly
      unusual configurations, and can be safely ignored for the overwhelming majority
      of Mastodon administrators.
      
      * Only set follower synchronization header on non-public statuses
      
      This is to avoid unnecessary computations and allow Follow-related
      activities to be handled by the usual codepath instead of going through
      the synchronization mechanism (otherwise, any Follow/Undo/Accept activity
      would trigger the synchronization mechanism even if processing the activity
      itself would be enough to re-introduce synchronization)
      
      * Change how ActivityPub::SynchronizeFollowersService handles follow requests
      
      If the remote lists a local follower which we only know has sent a follow
      request, consider the follow request as accepted instead of sending an Undo.
      
      * Integrate review feeback
      
      - rename X-AS-Collection-Synchronization to Collection-Synchronization
      - various minor refactoring and code style changes
      
      * Only select required fields when computing followers_hash
      
      * Use actor URI rather than webfinger domain in synchronization endpoint
      
      * Change hash computation to be a XOR of individual hashes
      
      Makes it much easier to be memory-efficient, and avoid sorting discrepancy issues.
      
      * Marginally improve followers_hash computation speed
      
      * Further improve hash computation performances by using pluck_each
      Unverified
      ca565271
  17. Oct 12, 2020
  18. Oct 07, 2020
    • Eugen Rochko's avatar
      Remove dependency on goldfinger gem (#14919) · 7d985f2a
      Eugen Rochko authored
      There are edge cases where requests to certain hosts timeout when
      using the vanilla HTTP.rb gem, which the goldfinger gem uses. Now
      that we no longer need to support OStatus servers, webfinger logic
      is so simple that there is no point encapsulating it in a gem, so
      we can just use our own Request class. With that, we benefit from
      more robust timeout code and IPv4/IPv6 resolution.
      
      Fix #14091
      Unverified
      7d985f2a
  19. Sep 18, 2020
  20. Sep 16, 2020
  21. Sep 15, 2020
  22. Sep 14, 2020
    • ThibG's avatar
      Do not serve account actors at all in limited federation mode (#14800) · cd4ec7cd
      ThibG authored
      * Do not serve account actors at all in limited federation mode
      
      When an account is fetched without a signature from an allowed instance,
      return an error.
      
      This isn't really an improvement in security, as the only information that was
      previously returned was required protocol-level info, and the only personal bit
      was the existence of the account. The existence of the account can still be
      checked by issuing a webfinger query, as those are accepted without signatures.
      
      However, this change makes it so that unallowed instances won't create account
      records on their end when they find a reference to an unknown account.
      
      The previous behavior of rendering a limited list of fields, instead of not
      rendering the actor at all, was in order to prevent situations in which two
      instances in Authorized Fetch mode or Limited Federation mode would fail to
      reach each other because resolving an account would require a signed query…
      from an account which can only be fetched with a signed query itself. However,
      this should now be fine as fetching accounts is done by signing on behalf of
      the special instance actor, which does not require any kind of valid signature
      to be fetched.
      
      * Fix tests
      Unverified
      cd4ec7cd
  23. Sep 11, 2020
  24. Sep 08, 2020
  25. Sep 07, 2020
  26. Sep 04, 2020
  27. Sep 01, 2020
    • ThibG's avatar
      Add configuration option to filter replies in lists (#9205) · 79305428
      ThibG authored
      * Add database support for list show-reply preferences
      
      * Add backend support to read and update list-specific show_replies settings
      
      * Add basic UI to set list replies setting
      
      * Add specs for list replies policy
      
      * Switch "cycling" reply policy link to a set of radio inputs
      
      * Capitalize replies_policy strings
      
      * Change radio button design to be consistent with that of the directory explorer
      Unverified
      79305428
  28. Aug 30, 2020
  29. Aug 24, 2020
    • santiagorodriguez96's avatar
      refactor: add email previews for WebAuthn emails (#14658) · 9cadd40c
      santiagorodriguez96 authored
      This is a leftover for the work done in #14466.
      Unverified
      9cadd40c
    • santiagorodriguez96's avatar
      Add WebAuthn as an alternative 2FA method (#14466) · e8d41bc2
      santiagorodriguez96 authored
      
      * feat: add possibility of adding WebAuthn security keys to use as 2FA
      
      This adds a basic UI for enabling WebAuthn 2FA. We did a little refactor
      to the Settings page for editing the 2FA methods – now it will list the
      methods that are available to the user (TOTP and WebAuthn) and from
      there they'll be able to add or remove any of them.
      Also, it's worth mentioning that for enabling WebAuthn it's required to
      have TOTP enabled, so the first time that you go to the 2FA Settings
      page, you'll be asked to set it up.
      This work was inspired by the one donde by Github in their platform, and
      despite it could be approached in different ways, we decided to go with
      this one given that we feel that this gives a great UX.
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      
      * feat: add request for WebAuthn as second factor at login if enabled
      
      This commits adds the feature for using WebAuthn as a second factor for
      login when enabled.
      If users have WebAuthn enabled, now a page requesting for the use of a
      WebAuthn credential for log in will appear, although a link redirecting
      to the old page for logging in using a two-factor code will also be
      present.
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      
      * feat: add possibility of deleting WebAuthn Credentials
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      
      * feat: disable WebAuthn when an Admin disables 2FA for a user
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      
      * feat: remove ability to disable TOTP leaving only WebAuthn as 2FA
      
      Following examples form other platforms like Github, we decided to make
      Webauthn 2FA secondary to 2FA with TOTP, so that we removed the
      possibility of removing TOTP authentication only, leaving users with
      just WEbAuthn as 2FA. Instead, users will have to click on 'Disable 2FA'
      in order to remove second factor auth.
      The reason for WebAuthn being secondary to TOPT is that in that way,
      users will still be able to log in using their code from their phone's
      application if they don't have their security keys with them – or maybe
      even lost them.
      
      * We had to change a little the flow for setting up TOTP, given that now
        it's possible to setting up again if you already had TOTP, in order to
        let users modify their authenticator app – given that now it's not
        possible for them to disable TOTP and set it up again with another
        authenticator app.
        So, basically, now instead of storing the new `otp_secret` in the
        user, we store it in the session until the process of set up is
        finished.
        This was because, as it was before, when users clicked on 'Edit' in
        the new two-factor methods lists page, but then went back without
        finishing the flow, their `otp_secret` had been changed therefore
        invalidating their previous authenticator app, making them unable to
        log in again using TOTP.
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      
      * refactor: fix eslint errors
      
      The PR build was failing given that linting returning some errors.
      This commit attempts to fix them.
      
      * refactor: normalize i18n translations
      
      The build was failing given that i18n translations files were not
      normalized.
      This commits fixes that.
      
      * refactor: avoid having the webauthn gem locked to a specific version
      
      * refactor: use symbols for routes without '/'
      
      * refactor: avoid sending webauthn disabled email when 2FA is disabled
      
      When an admins disable 2FA for users, we were sending two mails
      to them, one notifying that 2FA was disabled and the other to notify
      that WebAuthn was disabled.
      As the second one is redundant since the first email includes it, we can
      remove it and send just one email to users.
      
      * refactor: avoid creating new env variable for webauthn_origin config
      
      * refactor: improve flash error messages for webauthn pages
      
      Co-authored-by: default avatarFacundo Padula <facundo.padula@cedarcode.com>
      Unverified
      e8d41bc2
    • ThibG's avatar
      Add support for inlined objects in activity audience (#14514) · 720214fe
      ThibG authored
      * Add support for inlined objects in activity audience
      
      * Add tests
      Unverified
      720214fe
  30. Aug 19, 2020
  31. Aug 12, 2020
    • ThibG's avatar
      Improve email address validation (#14565) · 8d217d72
      ThibG authored
      * Increase DNS timeout from 1 second to 5 seconds for MX check
      
      1 seconds is rather short when using a recursive DNS resolver which
      hasn't got a cached result already available. Use 5 seconds instead,
      which is the timeout value we use for outgoing HTTP queries.
      
      * Add more precise error messages for invalid e-mail addresses
      Unverified
      8d217d72
  32. Aug 02, 2020
    • ThibG's avatar
      Change content-type to be always computed from file data (#14452) · a1412491
      ThibG authored
      * Change content-type to be always computed from file data
      
      Restore previous behavior, detecting the content-type isn't very
      expensive, and some instances may serve files as application/octet-stream
      regardless of their true type, making fetching media from them fail, while
      it used to work pre-3.2.0.
      
      * Add test
      Unverified
      a1412491
Loading