authorized fetch #217

the implementation is copied from the other places we already check
HTTP signatures, and cross-checked with Firefish's implementation
This commit is contained in:
dakkar 2023-12-20 12:17:59 +00:00
parent 6526968f2d
commit e5ea882ed7
4 changed files with 136 additions and 0 deletions

View file

@ -194,6 +194,8 @@ id: "aidx"
# Sign to ActivityPub GET request (default: true)
signToActivityPubGet: true
# check that inbound ActivityPub GET requests are signed ("authorized fetch")
checkActivityPubGetSignature: false
#allowedPrivateNetworks: [
# '127.0.0.1/32'