<feed xmlns='http://www.w3.org/2005/Atom'>
<title>webmentions-ssg/webmentions_ssg/tasks/receiver.py, branch main</title>
<subtitle>A web service that implements webmentions receiver/sender for static site generators.</subtitle>
<id>https://git.dennisfink.me/webmentions-ssg/atom/webmentions_ssg/tasks/receiver.py?h=main</id>
<link rel='self' href='https://git.dennisfink.me/webmentions-ssg/atom/webmentions_ssg/tasks/receiver.py?h=main'/>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/'/>
<updated>2026-08-20T20:22:15Z</updated>
<entry>
<title>chore(core): standardize SPDX copyright headers</title>
<updated>2026-08-20T20:22:15Z</updated>
<author>
<name>Dennis Fink</name>
</author>
<published>2026-08-20T20:22:15Z</published>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/commit/?id=12b8c4b7f1d14556cc459f672b501e901da2d216'/>
<id>urn:sha1:12b8c4b7f1d14556cc459f672b501e901da2d216</id>
<content type='text'>
Add SPDX copyright and license headers to source, test, migration,
template, and static files throughout the project.

Include the maintainer email in copyright notices and fill in the BSD
license copyright holder.
</content>
</entry>
<entry>
<title>refactor(core): improve typing and test coverage</title>
<updated>2026-08-19T17:49:55Z</updated>
<author>
<name>Dennis Fink</name>
</author>
<published>2026-08-19T17:49:55Z</published>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/commit/?id=d0e245d63e014d268310976fc45429f08d2cbbe9'/>
<id>urn:sha1:d0e245d63e014d268310976fc45429f08d2cbbe9</id>
<content type='text'>
Restructure database and user CLI commands, make passwords write-only
model properties, and use the UTC datetime constant throughout the
application.

Add PEP 287-style documentation and expand receiver, scanner, sender,
and URL security tests to cover error paths and edge cases.
</content>
</entry>
<entry>
<title>feat(sender): add outgoing Webmention pipeline</title>
<updated>2026-08-15T18:54:53Z</updated>
<author>
<name>Dennis Fink</name>
</author>
<published>2026-08-15T18:54:53Z</published>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/commit/?id=e0f65d7ff582b32f1c7b5508bba8cda807aaae5f'/>
<id>urn:sha1:e0f65d7ff582b32f1c7b5508bba8cda807aaae5f</id>
<content type='text'>
Scan generated h-entry documents for Webmention targets and track source
revisions and delivery state in the database.

Discover target endpoints, send Webmentions asynchronously, and reconcile
updated, removed, restored, and deleted sources across scans.

Add authenticated views for inspecting sent Webmentions and make the scanner
schedule configurable.
</content>
</entry>
<entry>
<title>fix(receiver): prevent requests to non-public addresses</title>
<updated>2026-08-10T17:36:49Z</updated>
<author>
<name>Dennis Fink</name>
</author>
<published>2026-08-10T17:36:49Z</published>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/commit/?id=8350bef3e3baea6042ed3780a054cc65707e9f8d'/>
<id>urn:sha1:8350bef3e3baea6042ed3780a054cc65707e9f8d</id>
<content type='text'>
Resolve source hostnames before fetching and reject addresses that are
not globally routable to prevent SSRF against local or private services.

Repeat the check for every HTTP request so redirects cannot bypass the
initial source validation. Treat DNS resolution failures during
verification as temporary fetch errors.
</content>
</entry>
<entry>
<title>Implement received Webmention handling</title>
<updated>2026-08-09T12:22:00Z</updated>
<author>
<name>Dennis Fink</name>
</author>
<published>2026-08-09T12:15:29Z</published>
<link rel='alternate' type='text/html' href='https://git.dennisfink.me/webmentions-ssg/commit/?id=67eff0a854da010cb6ecd119d84238ec3e119272'/>
<id>urn:sha1:67eff0a854da010cb6ecd119d84238ec3e119272</id>
<content type='text'>
Add the Flask application setup, database models and migrations,
authentication, and configuration for development and testing.

Implement asynchronous Webmention verification with Huey, including HTML
and plain-text source validation, retries, status tracking, and size
limits.

Add status, login, and paginated received-Webmention views together with
comprehensive tests for forms, views, and receiver tasks.
</content>
</entry>
</feed>
