Lewis and Tangled
2bfea64ffc
api: add xrpc query extractor
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
e931268f7e
types: validate on construction & normalize what gets stored
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
14a086cb13
store: fix inline block span parsing in event sidecars
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Trezy and Tangled
7244551ae1
refactor: clean up property names and document stringy values
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
01d93e44e7
fix: show the user which scopes will not be granted based on delegation
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
fa50d7d54e
fix: prevent rpc scopes from escaping permission set namespace
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
19e7ec29f5
fix: prevent transient permission set publishers from causing auth refresh failures
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
311fbfcb86
feat: add handling for more scope failures
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
515c058006
refactor: use Nsid newtype instead of strings
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
aca6dd926e
chore: clean up dead code
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
9c6730579e
feat: display bundled permission-sets on consent screen
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
348ac887fc
fix: use JWT scopes as source-of-truth for access and refresh tokens
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:26 +03:00
Trezy and Tangled
ecdda4c555
feat: cache expanded permission sets
2026-07-24 20:11:26 +03:00
Trezy and Tangled
f17adc6f88
refactor: use tranquil-scopes instead of bespoke scope handling in delegation auth
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:26 +03:00
Lewis and Tangled
00ca223b5f
identity: force did:web signkey check to #atproto verification
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-23 10:34:21 +03:00
nelind
9ccec274aa
chore: nix flake update
2026-07-17 02:14:30 +02:00
nelind
f2754efeb2
chore(nix): use fetcherVersion 4 of fetchPnmpDeps
2026-07-17 02:14:30 +02:00
nelind and Tangled
4416f50c87
feat(config): add more default crawlers/relays
2026-07-15 08:58:35 +03:00
Lewis
e41f34746a
db: newtype Rkey and final newtype touches for now
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
fbfa15b0b4
invite: newtype InviteCode for invite endpoints + store
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
eb1a89dc58
db: Did type for repos and handlers
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
6ca6c45605
identity: Handle type for stored handles & extract_handle
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
d238affd76
repo: newtype commit cid & rev to CidLink & Tid
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
469255f5a9
db: newtype PasswordHash for users & app passwords
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
8559764d31
auth: newtype jti claims, sessions, & store
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
a405d523ca
oauth: newtype client, token, device & request ids
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:25:08 +03:00
Lewis
3c46e5fc73
lexicon: Nsid instead of strs for collections
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:21:32 +03:00
Lewis
f330dcd366
types: did, nsid, & rkey in AtUri::from_parts
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 16:14:56 +03:00
Lewis
1411506d8c
auth: typed TokenVerifyError from es256k verifier
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 14:45:39 +03:00
Lewis
1a9dcf86ba
types: sqlx finally behind a feature -> derive Ord & Borrow on newtypes
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 08:30:22 +03:00
Alex van de Sandt and Tangled
8ae9ce9c8f
fix: enable autocomplete in totp verification
2026-07-02 20:29:22 +03:00
Lewis
6ec4484cad
sqlx: add missing file
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-29 08:31:30 +03:00
Lewis
f3af04e4ae
dns: fall back to defaults if smth bad
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-28 10:12:00 +03:00
Lewis
aab1a945c2
session: deletes scope to did, route muts by did
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-28 09:55:11 +03:00
ave and Tangled
9dc184ee33
bsky(auth): add grace period to legacy session refresh
...
Concurrent or retried com.atproto.server.refreshSession calls presenting the
same refresh token hit the reuse-detection path, which deleted the session and
returned "Refresh token has been revoked due to suspected compromise" —
logging users out at random. The legacy flow had no grace period, unlike OAuth.
Mirror the reference atproto PDS: every rotated refresh token gets a 2h grace
window measured from its own rotation time (used_refresh_tokens.used_at in
postgres; a rotated_at_ms field appended to the metastore used-marker, with
old-format markers decoding as outside the window). A refresh presenting a
recently-rotated token is served the session's current tokens, re-minted on
the fly with the same jti/expiry — signed JWTs are never persisted. Reuse
outside the window still revokes the session.
The grace lookup returns the session's encrypted signing key so the handler
verifies the presented token's signature before minting replacement tokens or
revoking a session; a forged token bearing a known jti gets a generic
rejection with no side effects.
Integration tests asserting the old replay-gets-401 behavior are reworked to
the new contract and now also cover forged-signature replays and
out-of-window revocation.
2026-06-27 23:54:22 +03:00
Lewis
ab4eba6dc4
delegation: preset scopes grant identity & account
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-27 23:11:24 +03:00
Lewis
a171518290
tranquil-store/repo: repair tolerates corrupt/missing blocks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-26 20:50:30 +03:00
Lewis and Tangled
28f2e04019
plc: always keep signing key in rotationKeys
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-26 18:52:12 +03:00
Lewis and Tangled
39a2e40b35
invite codes: dedup consumption, iron out kinks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-26 13:28:49 +03:00
isabel and Tangled
05ab0b7423
nix: use systemd-nspawn tests
...
this speeds tests up like 10 fold; had to swap from sudo to runuser
since sudo wanted passwords
2026-06-22 20:31:06 +03:00
Lewis and Tangled
221b32d66f
build: smaller faster prod container
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-19 09:16:30 +03:00
Lewis
1b489776c5
server healthcheck in-bin
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-18 09:34:36 +03:00
nelind
2ca15fe7a0
fix(nix): disable the nixpkgs tranquil module when the repo module is used
2026-06-17 11:53:58 +02:00
ave and Tangled
48ae1e8b7b
Move Dockerfile(s) from musl to glibc
...
Musl is tier 2 on rust support, and glibc is tier 1.
https://doc.rust-lang.org/nightly/rustc/platform-support.html
Generally, glibc rust is reported to be more performant. Could vary due
to any other reason, but in my testing, builds were up to 50% faster
(for docker cross-compilation amd64->arm64 at least).
2026-06-16 14:31:32 +03:00
ave and Tangled
6838976969
fix(cors): Allow User-Agent header in CORS
2026-06-15 13:27:31 +03:00
Jim Severino and Tangled
3045ee25c0
Fix(docs): Add correctly TOML-formatted values for first string and array examples
2026-06-15 11:04:59 +03:00
Jim Severino and Tangled
04a90b1563
Fix(docs): Change symlinks to SSL cert files from absolute to relative
2026-06-15 11:04:59 +03:00
Lewis and Tangled
e13ba7f4c7
ripple: anti-entropy gossip sync
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-14 18:46:41 +03:00
Lewis and Tangled
a3f729c3cd
ripple: fail-closed startup, bind policy
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-14 18:46:41 +03:00
Lewis and Tangled
637b817a33
ripple: cluster-key oomf authentication
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-14 18:46:41 +03:00