Background
A gateway that receives an activity in an FEP-ef61 portable inbox forwards it to the actor's other gateways (#1092). FEP-ef61 forbids forwarding an activity from an inbox more than once, and Fedify enforces that per gateway, but it cannot tell which gateway a delivery came from, so it forwards the activity back to the sending gateway too. That gateway drops it, as it has already forwarded the activity, but the echo costs one request per activity and gateway.
Once forwarded requests are signed with gateway keys (#1100), the signature could tell the receiver which gateway sent a delivery. Fedify does not check it today: when an activity is authenticated by its Object Integrity Proof, the inbox does not verify HTTP Signatures at all.
Proposed work
For deliveries to a portable inbox, verify the HTTP Signature even when the activity's proof has verified. If the key is a gateway key of the recipient actor on a gateway in its gateways, skip that gateway when forwarding.
Design questions:
- Verifying the signature means fetching the key's actor document from the sending gateway and checking its proof, once per delivery unless cached. Is the saved echo worth that request?
- If the signature is invalid or the key cannot be fetched, should the delivery still be accepted based on its proof, without identifying the sending gateway?
- Should the key's actor be required to be the recipient actor, or is any portable actor listing the gateway enough?
What Mitra and Streams send when forwarding (#1097) should inform the answers.
Scope
Activities are still authenticated by their Object Integrity Proofs; this issue does not change that.
Tests
- a delivery signed with a gateway key of the recipient actor is not forwarded back to that gateway;
- deliveries with an invalid signature, an unknown key, or a gateway not in
gateways are handled as decided above;
- unsigned deliveries are forwarded as before.
Background
A gateway that receives an activity in an FEP-ef61 portable inbox forwards it to the actor's other gateways (#1092). FEP-ef61 forbids forwarding an activity from an inbox more than once, and Fedify enforces that per gateway, but it cannot tell which gateway a delivery came from, so it forwards the activity back to the sending gateway too. That gateway drops it, as it has already forwarded the activity, but the echo costs one request per activity and gateway.
Once forwarded requests are signed with gateway keys (#1100), the signature could tell the receiver which gateway sent a delivery. Fedify does not check it today: when an activity is authenticated by its Object Integrity Proof, the inbox does not verify HTTP Signatures at all.
Proposed work
For deliveries to a portable inbox, verify the HTTP Signature even when the activity's proof has verified. If the key is a gateway key of the recipient actor on a gateway in its
gateways, skip that gateway when forwarding.Design questions:
What Mitra and Streams send when forwarding (#1097) should inform the answers.
Scope
Activities are still authenticated by their Object Integrity Proofs; this issue does not change that.
Tests
gatewaysare handled as decided above;