
- Set the right keyID and use the right signing keys for outgoing requests. - Verify the HTTP signature of all incoming requests, except for the server actor. - Caches keys of incoming requests for users and servers actors. Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/7035 Reviewed-by: Gusted <gusted@noreply.codeberg.org> Co-authored-by: famfo <famfo@famfo.xyz> Co-committed-by: famfo <famfo@famfo.xyz>
29 lines
632 B
Go
29 lines
632 B
Go
// Copyright 2025 The Forgejo Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package forgejo_migrations //nolint:revive
|
|
|
|
import (
|
|
"database/sql"
|
|
|
|
"xorm.io/xorm"
|
|
)
|
|
|
|
func AddPublicKeyInformationForFederation(x *xorm.Engine) error {
|
|
type FederationHost struct {
|
|
KeyID sql.NullString `xorm:"key_id UNIQUE"`
|
|
PublicKey sql.Null[sql.RawBytes] `xorm:"BLOB"`
|
|
}
|
|
|
|
err := x.Sync(&FederationHost{})
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
type FederatedUser struct {
|
|
KeyID sql.NullString `xorm:"key_id UNIQUE"`
|
|
PublicKey sql.Null[sql.RawBytes] `xorm:"BLOB"`
|
|
}
|
|
|
|
return x.Sync(&FederatedUser{})
|
|
}
|