| Commit message (Collapse) | Author | ||
|---|---|---|---|
| 2026-08-10 | fix(receiver): prevent requests to non-public addresses | Dennis Fink | |
| Resolve source hostnames before fetching and reject addresses that are not globally routable to prevent SSRF against local or private services. Repeat the check for every HTTP request so redirects cannot bypass the initial source validation. Treat DNS resolution failures during verification as temporary fetch errors. | |||
| 2026-08-09 | Implement received Webmention handling | Dennis Fink | |
| Add the Flask application setup, database models and migrations, authentication, and configuration for development and testing. Implement asynchronous Webmention verification with Huey, including HTML and plain-text source validation, retries, status tracking, and size limits. Add status, login, and paginated received-Webmention views together with comprehensive tests for forms, views, and receiver tasks. | |||
