Task group 3 of federation-hardening. There was no blocklist of any kind;
the only lever against a hostile instance was an IP/host block in Caddy.
- New `federation_blocked_instances` table (domain PK, reason,
created_at). Additive → created by drizzle-kit push.
- `federation-blocklist.server.ts`: exact-host matching —
`isBlockedDomain`, `isBlockedIri` (unparseable IRI ⇒ treated as
blocked), and `filterBlockedDomains` for batch recipient filtering.
- Enforced at all three boundaries (spec: federation-operations
"Instance blocklist"):
- inbox — each of the 4 listeners silently drops a blocked actor's
activity (202, no error oracle) before dedup/side effects;
- delivery enqueue — `enqueueActivityDeliveries` filters blocked
recipients in one batch query;
- outbox poll / actor fetch — `pollRemoteActor` refuses a blocked host
up front (`skipped: "blocked instance"`), before any network.
- Operator procedure (SQL insert/list/delete) documented in the
deployment runbook's federation section.
- Tests: unit (hostOfIri) + integration against real Postgres covering
the helper and the delivery + outbox boundaries; inbox uses the same
tested isBlockedIri primitive.
Note: the inbox-drop *counter* (federation_inbox_dropped_total{reason})
lands with the other metrics in task 4.2; this commit is the enforcement.
Verified: db + journal typecheck + lint clean; drizzle-kit push creates
the table; blocklist integration tests green against real Postgres;
journal unit suite 357 passing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
14 lines
525 B
TypeScript
14 lines
525 B
TypeScript
import { describe, it, expect } from "vitest";
|
|
import { hostOfIri } from "./federation-blocklist.server.ts";
|
|
|
|
describe("hostOfIri", () => {
|
|
it("extracts the host from an actor/object IRI", () => {
|
|
expect(hostOfIri("https://mastodon.social/users/alice")).toBe("mastodon.social");
|
|
expect(hostOfIri("https://sub.example.com:8443/x")).toBe("sub.example.com:8443");
|
|
});
|
|
|
|
it("returns null for an unparseable IRI", () => {
|
|
expect(hostOfIri("not a url")).toBeNull();
|
|
expect(hostOfIri("")).toBeNull();
|
|
});
|
|
});
|