-
-
Notifications
You must be signed in to change notification settings - Fork 143
Use the key cache in RequestContext.getSignedKey() #1122
Copy link
Copy link
Labels
component/federationFederation object relatedFederation object relatedcomponent/signaturesOIP or HTTP/LD Signatures relatedOIP or HTTP/LD Signatures relateddifficulty/beginnerBeginner friendlyBeginner friendly
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
component/federationFederation object relatedFederation object relatedcomponent/signaturesOIP or HTTP/LD Signatures relatedOIP or HTTP/LD Signatures relateddifficulty/beginnerBeginner friendlyBeginner friendly
Type
Fields
Priority
None yet
Effort
None yet
Background
RequestContext.getSignedKey()callsverifyRequest()without akeyCache, so every call fetches the signer's key, and so does everygetSignedKeyOwner()call. Inbox handling passes aKvKeyCache; this path never has.The access control guide calls
getSignedKeyOwner()in authorize predicates, so every signedGETof a protected actor, object, or collection makes Fedify fetch the key again. A bogus key ID also costs one fetch per request, which inboxes avoid through the negative cache.Proposed work
Give
getSignedKey()the sameKvKeyCachethat inbox handling builds, underkvPrefixes.publicKeywithpublicKeyTtl.verifyRequest()already refetches a cached key that fails to verify, so key rotation keeps working.Open questions:
GetSignedKeyOptionslet a caller opt out, e.g., for an endpoint that wants a fresh key every time?Tests
getSignedKey()calls across requests with the same key ID fetch the key once within its TTL.