Add a layer of safety around required ActivityPub Actor fields (#4703)

* fix(ap): add safe constructors, getters, and validators to ActivityPub actors to address #4701

* chore: replace nil check with the new Validate() method

* chore(test): added test to verify the values extracted from actors

* fix: return the specific error type + test for it

* fix(ap): add recovery for each AP inbox worker for a worst case scenario

* fix(ap): add additional safe accessor methods to other AP entities other than actors

* chore(tests): add tests for the new safe accessors

* fix(ap): handle empty public keys in AP actors
This commit is contained in:
Gabe Kangas
2026-01-17 14:25:06 -08:00
committed by GitHub
parent 0ff73d5e1e
commit a82efb0e9a
19 changed files with 1671 additions and 177 deletions
+4 -1
View File
@@ -96,7 +96,10 @@ func Verify(request *http.Request) (bool, error) {
return false, err
}
key := publicKey.GetW3IDSecurityV1PublicKeyPem().Get()
key, err := apmodels.GetPublicKeyPem(publicKey)
if err != nil {
return false, errors.Wrap(err, "failed to get public key PEM")
}
block, _ := pem.Decode([]byte(key))
if block == nil {
log.Errorln("failed to parse PEM block containing the public key")