Background
Fedify's FEP-ef61 support is tested only against itself and hand-written fixtures. In particular, the gateway key model from #840 was designed from the specifications (FEP-ef61, FEP-521a, FEP-ae97) and has not been checked against another implementation. Implementations differ in how they publish portable actors and their keys: tootik uses compatible identifiers as actor IDs, Mitra acts as a gateway for portable actors including ones registered by FEP-ae97 clients, and each may use a different form of key IDs. Software without portable ID support may also treat keys from secondary gateways differently from keys that are fragments of the actor ID; for instance, Mastodon appears to handle Multikey IDs whose base differs from the actor URI through a separate code path, which has not been checked.
Proposed work
Test the portable object support against other implementations, and record what works:
- collect real actor documents, activities, and signed requests from pinned versions of Mitra and tootik, and add them as fixtures;
- check that Fedify verifies their portable actors, activities, and HTTP Signatures, or record why not;
- check that they accept Fedify's portable actors, proofs, and gateway key signatures;
- check what Mastodon does with a portable actor served at a compatible identifier, including a key from a secondary gateway.
The findings should go into the FEP-ef61 section of FEDERATION.md and the manual, and any bugs into their own issues.
Scope
This issue is about testing and documenting interoperability. Fixes for the problems it finds belong in separate issues.
Tests
- fixture-based tests for each implementation's documents and signatures;
- a short manual test log for the live checks, with versions.
Background
Fedify's FEP-ef61 support is tested only against itself and hand-written fixtures. In particular, the gateway key model from #840 was designed from the specifications (FEP-ef61, FEP-521a, FEP-ae97) and has not been checked against another implementation. Implementations differ in how they publish portable actors and their keys: tootik uses compatible identifiers as actor IDs, Mitra acts as a gateway for portable actors including ones registered by FEP-ae97 clients, and each may use a different form of key IDs. Software without portable ID support may also treat keys from secondary gateways differently from keys that are fragments of the actor ID; for instance, Mastodon appears to handle
MultikeyIDs whose base differs from the actor URI through a separate code path, which has not been checked.Proposed work
Test the portable object support against other implementations, and record what works:
The findings should go into the FEP-ef61 section of FEDERATION.md and the manual, and any bugs into their own issues.
Scope
This issue is about testing and documenting interoperability. Fixes for the problems it finds belong in separate issues.
Tests