nelind
cd7e01100e
chore(auth): also mention that atproto spec requiers typ be "JWT" for inter-service tokens
2026-06-05 12:49:25 +02:00
ave and Tangled
7c248be153
fix(auth): emit uppercase "JWT" typ in service-auth header
...
RFC 7519 §5.1 recommends the uppercase "JWT" typ for compatibility with
legacy implementations, and it matches the reference @atproto/pds. Parsing
already lowercases, so existing lowercase "jwt" tokens still verify.
2026-06-05 13:34:43 +03:00
ave and Tangled
91999819c6
fix(proxy): limit audience of getFeed service-auth to the feed generator
2026-06-04 22:39:14 +03:00
Tyler and Tangled
8e6ace2fe2
fix: derive lexicon DNS authority from all-but-last NSID segment
...
Permission-set expansion resolved the lexicon's DNS authority using a
fixed `parts[..2]`, which only works for three-segment NSIDs. For a
four-segment NSID such as community.lexicon.bookmarks.authManageBookmarks
this dropped a segment and queried _lexicon.lexicon.community instead of
_lexicon.bookmarks.lexicon.community, failing with "DNS resolution
failed: ... no record found".
The authority is every NSID segment except the last (the name),
reversed. Use parts[..parts.len() - 1] to match the spec and the
existing extract_namespace_authority helper, and update the DNS
authority test with three/four-segment and bookmarks regression cases.
2026-06-04 01:28:13 +03:00
Lewis and Tangled
3018a20843
fix(plc): allow arbitrary services to sign
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-03 11:23:51 +03:00
Lewis and Tangled
37fc06fb39
fix(store): unblock eventlog sync&freeze when writer dies
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis and Tangled
728a8c4d3b
test(store): cross-store, firehose, read-validation coverage w/ faults
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis and Tangled
3d49e99cc3
test(store): generic consistency checker, gauntlet fault/read
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis and Tangled
7e823673ca
test(store): untested metastore, eventlog, & archival stuff
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-02 17:29:21 +03:00
Lewis
320933598c
fix(auth): error num 401 for oauth
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:38:45 +03:00
Lewis
500dc2e0e6
test(store): gauntlet sweep configs for time-travel & fsync repro
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis
a220611a8b
test(store): D gauntlet faults, crash-loss oracley, recoverable scenarios
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis
ca7a4b4b73
fix(store): recover eventlog lastseq from tail not sidecar
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis
8ff02610e4
feat(store): inline-commit mode, committed-extent recovery, failsafe verify&rollback
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-01 19:01:04 +03:00
Lewis and Tangled
22f82489d5
test(pds): e2e & durability coverage for MST self-heal
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
cee483e358
feat(pds): selfhealing repo writing by detecting corruption & retrying
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
7f8e858137
test(store): gauntlet MST-repairable & misdirected-write scenario
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
44d73dac58
feat(store): rebuild & rewrite missing/corrupt MST blocks
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
b8cae15c12
feat(store): detect foreign&corrupt blocks on read & preserve blocks thru recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 21:11:36 +03:00
Lewis and Tangled
9b58961bba
feat(repo): missing $type? invent one
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 13:02:11 +03:00
Lewis
31ee12ecd3
fix(store): torn hint-file tail should be recoverable on reopen
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-31 11:37:21 +03:00
Lewis
4015217a2e
feat(store): Clock trait for DST
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-30 23:46:22 +03:00
Lewis and Tangled
e9dc57d6f4
fix(firehose): lost events if seq commits out of order
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-30 21:10:38 +03:00
Lewis
7a54ccf6a3
fix(tranquil-config): reject unknown keys in TlsConfig, bump rust 1.96
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-29 09:39:14 +03:00
isabel and Tangled
28aa7ab7fc
feat!(tranquil-config): error on unknown keys
...
an attempt to make it so that fixes like
fc6063dba8 never have to occur again
2026-05-27 20:13:58 +03:00
Lewis and Tangled
a7052e878c
feat: tranquil's own TLS handling
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-27 13:54:33 +03:00
Lewis
96c8375706
fix(test): oauth token eviction should be agnostic
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-25 16:17:10 +03:00
Lewis
86c5995568
fix(config): signal gate is useless since needs admin work to activate anyway
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-24 22:50:14 +03:00
Lewis and Tangled
036c317fd6
fix(migrate): oauth refreshing, embedded db first invite code
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-24 19:28:57 +03:00
Lewis and Tangled
4d2c7d4723
feat(auth): verification-gate override, inbound-migration bypass, store deleter improvement
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-23 23:02:43 +03:00
karitham.dev and Tangled
a3bd7c59ad
feat(locales): add french locale, fix missing error keys, remove dead keys
...
Adds french locale registration and translation file. Fixes 4 missing error keys that were referenced in code but absent from all locale files. Removes 2 unreferenced keys from `register.validation` that duplicated `registerPasskey.errors`.
I *think* that's all that's needed for french locale? Couldn't find anything else required to make it work!
2026-05-20 22:20:20 +03:00
Trezy and Tangled
76f22b801b
chore: allow native certs during local dev
...
Allows Traefik certs to be trusted by Tranquil.
Signed-off-by: Trezy <tre@trezy.com >
2026-05-19 19:46:58 +03:00
Lewis
bdaf510898
build: bump workspace to 0.6.2
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 12:32:05 +03:00
Lewis
deb2502112
feat(pds): phantom-file self-heal goes in scheduled compaction + reachability walk
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 12:32:05 +03:00
Lewis
1815ddba9f
feat(gauntlet): index-backed/hint-backed/readable invariants, ExternalCorruption scenario
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 12:32:05 +03:00
Lewis
a7517ed5c9
feat(store): consistency check & repair for orphan hints etc
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 11:50:32 +03:00
Lewis
d07d702dd4
feat(store): try to self-heal phantom index entries on compaction
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-17 11:50:19 +03:00
Lewis and Tangled
a13343e1de
fix(oauth): gc tokens in pg in the right order, more exposure of dpop err
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-14 16:51:53 +03:00
Lewis and Tangled
fac9520a16
feat(tranquil-server): email config, tests, fmt
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis and Tangled
eee6fb9ff4
feat(comms): EmailSender, permanent/transient routing
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis and Tangled
2462d0ab3b
feat(tranquil-comms): smtp and dkim signing
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis and Tangled
85f87f7b28
feat(tranquil-comms): message construction and mx resolution
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis and Tangled
b1d86caa78
feat(tranquil-comms): prework for email
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-05-02 22:28:59 +03:00
Lewis
9b2cfb3a7e
fix(tranquil-store): durable-tail recovery + sync semantics
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-30 11:11:28 +03:00
Lewis
efd499bb26
fix(tranquil-store): barrier durability + torn-header recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-29 15:35:42 +03:00
Lewis and Tangled
af3821514f
test(tranquil-pds): same-rkey batch coverage and inductive inverse for in-batch dups
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-28 22:05:03 +03:00
Lewis and Tangled
8f7aad3756
fix(tranquil-pds): same-rkey batch semantics and firehose lag recovery
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-28 22:05:03 +03:00
Lewis and Tangled
75b9e3165f
refactor(deploy): container-first cleanup, drop debian malware-style install
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-27 00:13:27 +03:00
Lewis and Tangled
ccc9916109
test(tranquil-pds): websocket firehose end-to-end mst verification
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-26 20:11:27 +03:00
Lewis and Tangled
bc8fd66a45
test(tranquil-pds): mst fuzz + repo integrity properties
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-04-26 20:11:27 +03:00