Remove inbound request signature verification (closes #279)
All checks were successful
check / check (push) Successful in 3m10s
All checks were successful
check / check (push) Successful in 3m10s
The receiver verified an optional per-entrypoint HMAC or shared token
before accepting a request. That is removed outright: the entrypoint
UUID in the URL is the authentication secret, and possession of it
authorises submission. This reverses the feature added in fcead5d.
Deletes the internal/signature package, the signature_scheme and
signature_secret columns from Entrypoint along with their accessors,
the per-entrypoint secret form and its POST route, and the scheme
labelling in EntrypointView. Pre-1.0 with no installed base, so the
columns simply stop being written; there is no migration and no
compatibility path.
Header sanitisation goes with it. SanitizeHeaders existed to strip a
scheme's own credential header before the header map was stored and
forwarded; with no configured credential there is nothing to strip, so
the receiver marshals the headers as received.
The receiver's other protections are untouched: the 1 MB body cap, the
per-IP rate limiter, the 410 for a deactivated entrypoint and the 404
for an unknown UUID.
This commit is contained in:
@@ -84,10 +84,6 @@ const resubmitColumns = "id, entrypoint_id, method, headers, " +
|
||||
// is the stored EVENT. The response bodies and headers the original
|
||||
// deliveries received stay where they are.
|
||||
//
|
||||
// Inbound signature verification is deliberately not re-run. There is
|
||||
// no inbound signature to check on a copy the operator submits; the
|
||||
// route is authenticated and CSRF-protected as an operator action.
|
||||
//
|
||||
// Resubmitting the same event repeatedly is supported and is the point
|
||||
// of the feature, so replay's in-flight refusal is deliberately not
|
||||
// applied here. The route's rate limit is what bounds a held-down
|
||||
|
||||
Reference in New Issue
Block a user