activitypub: also check incoming activity host for block

This commit is contained in:
Johann150 2023-04-16 19:34:15 +02:00
parent 5f4aab6d46
commit 4fbbfff145
Signed by untrusted user: Johann150
GPG key ID: 9EE6577A2A06F8F1

View file

@ -107,9 +107,14 @@ export default async (job: Bull.Job<InboxJobData>): Promise<string> => {
}
}
// Verify that the actor's host is not blocked
const signerHost = extractDbHost(authUser.user.uri!);
if (await shouldBlockInstance(signerHost)) {
return `Blocked request: ${signerHost}`;
}
if (typeof activity.id === 'string') {
// Verify that activity and actor are from the same host.
const signerHost = extractDbHost(authUser.user.uri!);
const activityIdHost = extractDbHost(activity.id);
if (signerHost !== activityIdHost) {
return `skip: signerHost(${signerHost}) !== activity.id host(${activityIdHost}`;