Add a layer of safety around required ActivityPub Actor fields (#4703)
* fix(ap): add safe constructors, getters, and validators to ActivityPub actors to address #4701 * chore: replace nil check with the new Validate() method * chore(test): added test to verify the values extracted from actors * fix: return the specific error type + test for it * fix(ap): add recovery for each AP inbox worker for a worst case scenario * fix(ap): add additional safe accessor methods to other AP entities other than actors * chore(tests): add tests for the new safe accessors * fix(ap): handle empty public keys in AP actors
This commit is contained in:
@@ -96,7 +96,10 @@ func Verify(request *http.Request) (bool, error) {
|
||||
return false, err
|
||||
}
|
||||
|
||||
key := publicKey.GetW3IDSecurityV1PublicKeyPem().Get()
|
||||
key, err := apmodels.GetPublicKeyPem(publicKey)
|
||||
if err != nil {
|
||||
return false, errors.Wrap(err, "failed to get public key PEM")
|
||||
}
|
||||
block, _ := pem.Decode([]byte(key))
|
||||
if block == nil {
|
||||
log.Errorln("failed to parse PEM block containing the public key")
|
||||
|
||||
Reference in New Issue
Block a user