mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Gate the relay admin moderation API (/api/admin/v1) behind explicit authentication configuration selected by BUZZ_ADMIN_AUTH: token (default), disabled, or nip98. In nip98 mode every request carries a signed kind-27235 NIP-98 event; the authenticated pubkey resolves to an OPERATOR or MODERATOR principal from RELAY_OPERATOR_PUBKEYS, the RELAY_OWNER_PUBKEY fallback, or the relay_operators table. Replaces the BUZZ_ADMIN_INSECURE_NO_AUTH bypass with a role model that is revocable without rotating a shared secret and fails closed at every boundary. Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
10 lines
464 B
SQL
10 lines
464 B
SQL
-- Fenced outbox delivery: add a per-claim opaque token to relay_admin_outbox.
|
|
--
|
|
-- Without this, mark_outbox_delivered and fail_outbox_row only fence on row ID,
|
|
-- which allows a stale worker (whose lease already expired) to overwrite a newer
|
|
-- worker's terminal update. The claim token is a real ownership fence: completion
|
|
-- and failure updates require the token written at claim time.
|
|
|
|
ALTER TABLE relay_admin_outbox
|
|
ADD COLUMN outbox_claim_token UUID;
|