Lewis and Tangled
9ad70bda9e
sync: parse xrpc query params into real types
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
c3a8240154
tests: assert user_blocks matches reachable set after every write
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
1e2311f8fc
repo: keep user_blocks equal to the reachable block set
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
17905115d8
store: revalidate stored mutation sets on replay
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
6ed568dbfb
store: rebuild derived indexes when stored format version is older
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
d00d72895a
store: record-by-cid reverse index
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:40 +03:00
Lewis and Tangled
2f1e22a950
store: add record-by-cid key shapes & chunked scan helpers
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
946cb9740f
store: warn & skip instead of failing on unreadable event payloads
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
0c7cccb14c
invite: require owning account for generated codes
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
4f37ac26cd
store: typed revs thru metastore keys & requests
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
bbe9f6f3b3
db: decode sequenced event rows leniently
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
4e3b2f2af4
handle: reject handles whose tld can never resolve
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
932b0c07d4
db: make stored handle optional when it no longer parses
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
01a71ece7c
db: check column conversions when mapping rows
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
8abb6cc741
db: name column behind invalid value
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
2bfea64ffc
api: add xrpc query extractor
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
e931268f7e
types: validate on construction & normalize what gets stored
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Lewis and Tangled
14a086cb13
store: fix inline block span parsing in event sidecars
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-25 08:27:39 +03:00
Trezy and Tangled
7244551ae1
refactor: clean up property names and document stringy values
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
01d93e44e7
fix: show the user which scopes will not be granted based on delegation
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
fa50d7d54e
fix: prevent rpc scopes from escaping permission set namespace
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
19e7ec29f5
fix: prevent transient permission set publishers from causing auth refresh failures
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
311fbfcb86
feat: add handling for more scope failures
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
515c058006
refactor: use Nsid newtype instead of strings
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
aca6dd926e
chore: clean up dead code
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
9c6730579e
feat: display bundled permission-sets on consent screen
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:27 +03:00
Trezy and Tangled
348ac887fc
fix: use JWT scopes as source-of-truth for access and refresh tokens
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:26 +03:00
Trezy and Tangled
ecdda4c555
feat: cache expanded permission sets
2026-07-24 20:11:26 +03:00
Trezy and Tangled
f17adc6f88
refactor: use tranquil-scopes instead of bespoke scope handling in delegation auth
...
Signed-off-by: Trezy <tre@trezy.com >
2026-07-24 20:11:26 +03:00
Lewis and Tangled
00ca223b5f
identity: force did:web signkey check to #atproto verification
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-23 10:34:21 +03:00
nelind
9ccec274aa
chore: nix flake update
2026-07-17 02:14:30 +02:00
nelind
f2754efeb2
chore(nix): use fetcherVersion 4 of fetchPnmpDeps
2026-07-17 02:14:30 +02:00
nelind and Tangled
4416f50c87
feat(config): add more default crawlers/relays
2026-07-15 08:58:35 +03:00
Lewis
e41f34746a
db: newtype Rkey and final newtype touches for now
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
fbfa15b0b4
invite: newtype InviteCode for invite endpoints + store
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
eb1a89dc58
db: Did type for repos and handlers
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
6ca6c45605
identity: Handle type for stored handles & extract_handle
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
d238affd76
repo: newtype commit cid & rev to CidLink & Tid
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
469255f5a9
db: newtype PasswordHash for users & app passwords
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
8559764d31
auth: newtype jti claims, sessions, & store
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 08:03:14 +02:00
Lewis
a405d523ca
oauth: newtype client, token, device & request ids
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:25:08 +03:00
Lewis
3c46e5fc73
lexicon: Nsid instead of strs for collections
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-12 00:21:32 +03:00
Lewis
f330dcd366
types: did, nsid, & rkey in AtUri::from_parts
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 16:14:56 +03:00
Lewis
1411506d8c
auth: typed TokenVerifyError from es256k verifier
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 14:45:39 +03:00
Lewis
1a9dcf86ba
types: sqlx finally behind a feature -> derive Ord & Borrow on newtypes
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-07-11 08:30:22 +03:00
Alex van de Sandt and Tangled
8ae9ce9c8f
fix: enable autocomplete in totp verification
2026-07-02 20:29:22 +03:00
Lewis
6ec4484cad
sqlx: add missing file
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-29 08:31:30 +03:00
Lewis
f3af04e4ae
dns: fall back to defaults if smth bad
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-28 10:12:00 +03:00
Lewis
aab1a945c2
session: deletes scope to did, route muts by did
...
Lewis: May this revision serve well! <lu5a@proton.me >
2026-06-28 09:55:11 +03:00
ave and Tangled
9dc184ee33
bsky(auth): add grace period to legacy session refresh
...
Concurrent or retried com.atproto.server.refreshSession calls presenting the
same refresh token hit the reuse-detection path, which deleted the session and
returned "Refresh token has been revoked due to suspected compromise" —
logging users out at random. The legacy flow had no grace period, unlike OAuth.
Mirror the reference atproto PDS: every rotated refresh token gets a 2h grace
window measured from its own rotation time (used_refresh_tokens.used_at in
postgres; a rotated_at_ms field appended to the metastore used-marker, with
old-format markers decoding as outside the window). A refresh presenting a
recently-rotated token is served the session's current tokens, re-minted on
the fly with the same jti/expiry — signed JWTs are never persisted. Reuse
outside the window still revokes the session.
The grace lookup returns the session's encrypted signing key so the handler
verifies the presented token's signature before minting replacement tokens or
revoking a session; a forged token bearing a known jti gets a generic
rejection with no side effects.
Integration tests asserting the old replay-gets-401 behavior are reworked to
the new contract and now also cover forged-signature replays and
out-of-window revocation.
2026-06-27 23:54:22 +03:00