Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ロックダウンされた/ログイン必須ノートは /outbox で見える #15644

Open
1 task done
eternal-flame-AD opened this issue Mar 10, 2025 · 1 comment
Open
1 task done
Labels
⚠️bug? This might be a bug 🌌Federation The Federation/ActivityPub feature packages/backend Server side specific issue/PR

Comments

@eternal-flame-AD
Copy link
Contributor

eternal-flame-AD commented Mar 10, 2025

💡 Summary

タイトル通り

(I received permission to post this in public.)

🥰 Expected Behavior

Image

From the description one would reasonably conclude:

  • This note is not visible from the home instance
  • This note is no longer federated in public view (a non follower should not be able to look this note up regardless of their respect of the _misskey vendor keys).
  • (Ideally but not mandatory behavior) Further AP get requests need a valid signature.

🤬 Actual Behavior

https://mi.yumechi.jp/users/a10sac8leyy40014/outbox?page=true

The note can still be looked up, have "public" audience and can be enumerated using /outbox?page=true

Image

📝 Steps to Reproduce

Set up lockdown

Go to the /users/<id>/outbox

💻 Frontend Environment

Not frontend problem

🛰 Backend Environment (for server admin)

* Installation Method or Hosting Service: podman
* Misskey: 2025.3.1
* Node: 22 
* PostgreSQL: 17
* Redis: official
* OS and Architecture: linux x86_64

Do you want to address this bug yourself?

  • Yes, I will patch the bug myself and send a pull request (Probably after Thurs or Friday, don't wait for me if time sensitive)
@eternal-flame-AD eternal-flame-AD added the ⚠️bug? This might be a bug label Mar 10, 2025
@eternal-flame-AD eternal-flame-AD changed the title ロックダウンされた/ログイン必需ノートは /outbox で見える ロックダウンされた/ログイン必須ノートは /outbox で見える Mar 10, 2025
@eternal-flame-AD
Copy link
Contributor Author

Related: #14802 #14473

@KisaragiEffective KisaragiEffective added packages/backend Server side specific issue/PR 🌌Federation The Federation/ActivityPub feature labels Mar 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
⚠️bug? This might be a bug 🌌Federation The Federation/ActivityPub feature packages/backend Server side specific issue/PR
Projects
Development

No branches or pull requests

2 participants