aboutsummaryrefslogtreecommitdiff
path: root/webmentions_ssg/forms/__init__.py (follow)
Commit message (Collapse)AuthorAge
* docs(core): add docstrings and type annotationsDennis Fink2026-08-20
| | | | | | | | Document forms, validators, models, and views with PEP 287-style docstrings and complete missing type annotations. Add developer-readable representations for Webmention models and mark the user password property as write-only in its return type.
* chore(core): standardize SPDX copyright headersDennis Fink2026-08-20
| | | | | | | | Add SPDX copyright and license headers to source, test, migration, template, and static files throughout the project. Include the maintainer email in copyright notices and fill in the BSD license copyright holder.
* feat(core): add received webmention admin actionsDennis Fink2026-08-10
| | | | | | | | Add authenticated delete and reverify actions to the received webmentions admin view and protect them with CSRF validation. Enable CSRF protection globally while exempting the public Webmention endpoint.
* fix(receiver): prevent requests to non-public addressesDennis Fink2026-08-10
| | | | | | | | | Resolve source hostnames before fetching and reject addresses that are not globally routable to prevent SSRF against local or private services. Repeat the check for every HTTP request so redirects cannot bypass the initial source validation. Treat DNS resolution failures during verification as temporary fetch errors.
* Implement received Webmention handlingDennis Fink2026-08-09
Add the Flask application setup, database models and migrations, authentication, and configuration for development and testing. Implement asynchronous Webmention verification with Huey, including HTML and plain-text source validation, retries, status tracking, and size limits. Add status, login, and paginated received-Webmention views together with comprehensive tests for forms, views, and receiver tasks.