* Sanitize AP name possible XSS * Pull out sanitizing method + remove rendering markdown for AP chat messages * Add tests around AP message rendering and usernames * Add sanitization tests to AP integration test
ActivityPub Federation Test
This test verifies Owncast's ActivityPub federation by having snac2 users follow the Owncast instance and confirming message delivery.
All test infrastructure (snac2, Caddy, mkcert, Go) runs inside a Docker container so you don't need to install anything on the host besides Docker.
Prerequisites
- Docker installed and running
Running the Tests
# Run the federation test with default 100 users
./run.sh
# Run with fewer users for quick testing
USER_COUNT=10 ./run.sh
# Run the follower validation test
./run.sh test-follower-validation.sh
# Keep servers running after test for debugging
KEEP_RUNNING=true ./run.sh
# Adjust follow request throttling (default 0.1s)
FOLLOW_DELAY=0.2 ./run.sh
Configuration Options
| Variable | Default | Description |
|---|---|---|
USER_COUNT |
100 | Number of test users to create |
FOLLOW_DELAY |
0.1 | Delay in seconds between follow requests |
KEEP_RUNNING |
false | Keep servers running after test for debugging |
CI |
false | Always true inside the container |
PROXY_PORT |
8443 | HTTPS proxy port |
SNAC_PORT |
9080 | snac2 HTTP port |
OWNCAST_PORT |
8080 | Owncast HTTP port |
What the Test Does
- Creates a temporary snac2 instance with test users
- Starts an HTTPS reverse proxy for TLS termination
- Starts Owncast configured for federation
- Has all snac2 users follow Owncast
- Sends a message from Owncast
- Verifies all followers received the message
Test Results
The test reports:
- Followers Registered: Number of successful follow requests
- Messages Delivered: Number of users who received the message
- Delivery Time: Time to deliver to all followers
- Follow Success Rate: Percentage of follow requests that succeeded
- Delivery Rate: Percentage of registered followers who received the message
Docker Image Details
The Docker image (owncast-ap-test) bundles all dependencies:
- Go (for building Owncast)
- snac2 (built from source)
- Caddy (HTTPS reverse proxy)
- mkcert (TLS certificates trusted by the container)
- sqlite3, jq, curl
Go module and build caches are stored in named Docker volumes (owncast-ap-test-gomod, owncast-ap-test-gobuild) so repeated runs are faster.
Troubleshooting
Docker build fails
Make sure Docker is running. On macOS, Docker Desktop or a compatible runtime (colima, OrbStack, etc.) is required.
Port already in use
If a previous container didn't shut down cleanly:
docker ps -a | grep owncast-ap-test
docker rm -f <container_id>
Cleaning up Docker resources
# Remove the image
docker rmi owncast-ap-test
# Remove Go caches
docker volume rm owncast-ap-test-gomod owncast-ap-test-gobuild