Lewis and Tangled
8c3386a3ab
caddy: on-demand TLS endpoint
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-09-01 16:31:10 +00:00
Trezy and Tangled
eba8167da8
chore: clean up supersedence shtuff
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-29 20:11:10 +00:00
Trezy and Tangled
2e92310518
fix: allow transition:generic to be used with granular scopes
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-29 20:11:10 +00:00
nelind and Tangled
0e82a38add
fix(api): dont do rotation key validation in signPlcOperation as it blocks migrations
2026-08-29 05:42:03 +00:00
Trezy and Tangled
1866d2bf0e
test: i dunno what youre talking about i would never leave prints in production code 🙃
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-28 20:28:54 +00:00
Trezy and Tangled
dc2f924130
fix: add transition: scopes to owner-level delegates
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-28 20:28:54 +00:00
Trezy and Tangled
97224551bf
test: verify taxonomy entries parse to the correct type
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-28 20:28:54 +00:00
Trezy and Tangled
68ae485a52
fix: restore rpc: scopes for delegation
...
Signed-off-by: Trezy <tre@trezy.com >
2026-08-28 20:28:54 +00:00
Johanna Larsson and Tangled
228c1bbbf5
Normalize the allow private IPs flag application
2026-08-28 12:36:47 +00:00
Johanna Larsson and Tangled
093484388f
Allow private IPs in dev
...
Running tranquil with `just run-dev` using `pds.test` seems to be broken due to a recent change that blocks requests to private ips. Inside the compose network `pds.test` resolves to the traefik container's private IP. So it can't make requests to stuff like `https://pds.test/oauth-client-metadata.json ` or the local plc.
Introduces a new flag, default off, that allows connecting to private IPs, set to true for the dev compose.
2026-08-28 12:36:47 +00:00
Johanna Larsson and Tangled
0f0c50f7d4
Loosen CORS header requirements
...
Bluesky started sending `x-bsky-is-beta-user` for some users on XRPC requests, but tranquil has a strict allowlist of CORS headers. The spec doesn't (?) specify any requirements around CORS headers, so we can avoid trouble when Bluesky make changes by just allowing all headers.
This PR replaces the allowlist with the request mirror behavior, where any headers sent on a CORS request are echoed back. This also matches the reference PDS.
2026-08-28 07:16:50 +00:00
Jack Platten and Tangled
26aa399cda
Fix name of test
2026-08-27 20:07:59 +00:00
Jack Platten and Tangled
f296bb68df
fix: allow path-empty URIs and drop authority/path charset checks
...
RFC 3986 lets hier-part be path-empty, so "urn:" alone is a valid
URI; treat it as one.
2026-08-27 20:07:59 +00:00
Jack Platten and Tangled
d979cb969a
add underscore to scheme support.
...
adds tests for mbid directly, as well as underscore scheme.
Followup:
`scheme:` is not currently passing this function, but can wait for now
2026-08-27 20:07:59 +00:00
739db41130
fix: accept RFC 3986 scheme:opaque-part URIs without //
...
is_valid_uri required a literal "://", but the atproto uri string
format follows RFC 3986's generic URI grammar, which also allows
"scheme:opaque-part" forms with no authority (e.g. urn:isbn:...).
Records using such values were rejected once production lexicons
enable strict validation.
Reported as #130 .
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com >
2026-08-27 20:07:59 +00:00
Jack Platten and Tangled
0189aa9f96
Update config commit to create new round
2026-08-21 16:16:45 +00:00
Jack Platten and Tangled
d495d7d729
Use crate::types::queuedcomms export
...
also generate example.toml
2026-08-21 16:16:45 +00:00
73cb89c9b7
resolve review feedback.
...
- eliminates panic opportunity on receiving email
- strict enum
- added unit test for ensuring that atmos headers don't leak onto
directmx
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com >
2026-08-21 16:16:45 +00:00
Jack Platten and Tangled
ecb7934a20
fix: fix missing test failure
2026-08-21 16:16:45 +00:00
Jack Platten and Tangled
9edc7dcdd8
comms: add comail.at category support
...
Adds a defaulted to off option to add the `X-Atmos-Category` headers
to emails sent via smarthost, for proper categorization by comail.
Category breakdown is as follows:
verification: EmailVerification, ChannelVerification, ChannelVerified,
MigrationVerification, LegacyLoginAlert, EmailUpdate, PlcOperation,
AccountDeletion
password-reset: PasswordReset, PasskeyRecovery
mfa-otp: TwoFactorCode
bulk: Welcome
untagged: AdminEmail
2026-08-21 16:16:45 +00:00
Matan Kushner and Tangled
479fa3ed22
fix: require DPoP for loopback clients
2026-08-21 11:41:29 +00:00
Louis Escher and Tangled
aa815931e0
Update lib.rs
2026-08-20 08:21:53 +00:00
Louis Escher and Tangled
0ce725174d
fix: DID length test, service test, cloning, dead code (should be it!)
2026-08-20 08:21:53 +00:00
Louis Escher and Tangled
dae3cc7e08
fix: aud fragment matching
2026-08-20 08:21:53 +00:00
Louis Escher and Tangled
b9e7955606
fix: pass exp to token creation
2026-08-20 08:21:53 +00:00
Louis Escher and Tangled
32c58b1d0b
fix: make thingy allow list
2026-08-20 08:21:53 +00:00
Louis Escher and Tangled
1b5a2b319c
fix: getServiceAuth aud parsing
2026-08-20 08:21:53 +00:00
Lewis and Tangled
8d0b6f8322
cache: DID, SSO, & OAuth client metadata caches onto shared cache
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis and Tangled
0fc577316e
lexicon: schema docs & negative results via cluster cache
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis and Tangled
52d5236e89
plc: dedup fetch paths, cache TTL from config
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis and Tangled
0274f19d75
auth: EmailTokenPurpose from tranquil-types, shared cache key fns, MemoryCache in tests
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis and Tangled
135912194d
types: HttpUrl newtypes, shared cache key/JSON helpers
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis and Tangled
0b8787d1de
pds: compile bsky-specific proxy, CORS, & validation out under bsky features
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 17:15:23 +00:00
Lewis
18455f54f2
api: moorfc compliance endpoint toggle
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-08-16 19:58:24 +03:00
Louis Escher and Tangled
ce2f05b9d4
fix: make coverage triple state instead of boolean
2026-08-13 16:09:03 +00:00
Louis Escher and Tangled
c88f69f31d
fix: Address PR review
2026-08-13 16:09:03 +00:00
Louis Escher and Tangled
b3c314ce66
fix: Address review comments
2026-08-13 16:09:03 +00:00
Louis Escher and Tangled
434079a732
feat: compress large token scopes with brotli
2026-08-13 16:09:03 +00:00
Louis Escher and Tangled
a5a2f30bbe
fix: Collapse action parameters for repo scopes
...
TODO: Still missing tests!
2026-08-13 16:09:03 +00:00
Johanna Larsson and Tangled
bc751b0ee2
Bring back thing that made yubikey work
2026-08-08 15:41:29 +00:00
Johanna Larsson and Tangled
9e78206cf4
Switch back to SecurityKey, remove hint
2026-08-08 15:41:29 +00:00
Johanna Larsson and Tangled
779dc1b985
Replace SecurityKey with Passkey
2026-08-08 15:41:29 +00:00
Edmund Edgar and Tangled
1dc0c40206
fix: don't require a server-custodied rotation key
...
Remove the requirement that the user's did can be controlled by the
server rotation key and signing key. This was preventing users who
didn't want to trust the PDS with their rotation keys from activating
their accounts. Errors are removed but we issue debug messages.
2026-07-26 11:45:09 +03:00
nelind and Tangled
59934cc184
feat: add bsky and bsky-support cargo features to manage bsky specific code
2026-07-25 18:31:06 +03:00
nelind and Tangled
34a47e6e5a
chore: clean up Cargo.toml files with cargo-shear and remove default feature on lib crates
2026-07-25 18:31:06 +03:00
Lewis and Tangled
aca78bb8d3
scopes: tweak tests, add translations
...
Lewis: May this revision serve well! <did:plc:3fwecdnvtcscjnrx2p4n7alz>
2026-07-25 11:08:27 +03:00
Lewis and Tangled
25d7d24d4e
types: drop unchecked construction from validated newtypes
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
b6274bb3c4
api: validated newtypes from their checked constructors
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
2a96a8f420
server: report absent repo rev instead of an empty one
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
9ad70bda9e
sync: parse xrpc query params into real types
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00