reject activities from instance not on relay-list

This commit is contained in:
Izalia Mae 2019-05-08 02:54:57 -04:00
parent 9d1c6a3fa2
commit 1065c5ff36
1 changed files with 4 additions and 0 deletions

View File

@ -272,10 +272,14 @@ processors = {
async def inbox(request):
data = await request.json()
instance = urlsplit(data['actor']).hostname
if 'actor' not in data or not request['validated']:
raise aiohttp.web.HTTPUnauthorized(body='access denied', content_type='text/plain')
if data['type'] != 'Follow' and 'https://{}/inbox'.format(instance) not in DATABASE['relay-list']:
raise aiohttp.web.HTTPUnauthorized(body='access denied', content_type='text/plain')
actor = await fetch_actor(data["actor"])
actor_uri = 'https://{}/actor'.format(request.host)