diff options
author | Alex Gleason <alex@alexgleason.me> | 2023-08-23 13:10:19 -0500 |
---|---|---|
committer | Lain Soykaf <lain@lain.com> | 2024-05-22 12:57:45 +0400 |
commit | b15f8b06425edbfc3a7cef2a55c609b12ee14377 (patch) | |
tree | 4bea5907cf9fbd0c2023f966d9d5729e580c445e /test/fixtures | |
parent | d1b053f3ba4170021c511b0d06a41405d3ab07d3 (diff) | |
download | pleroma-b15f8b06425edbfc3a7cef2a55c609b12ee14377.tar.gz pleroma-b15f8b06425edbfc3a7cef2a55c609b12ee14377.zip |
Prevent webfinger spoofing
Diffstat (limited to 'test/fixtures')
-rw-r--r-- | test/fixtures/tesla_mock/gleasonator.com_host_meta | 4 | ||||
-rw-r--r-- | test/fixtures/tesla_mock/webfinger_spoof.json | 28 |
2 files changed, 32 insertions, 0 deletions
diff --git a/test/fixtures/tesla_mock/gleasonator.com_host_meta b/test/fixtures/tesla_mock/gleasonator.com_host_meta new file mode 100644 index 000000000..c1a432519 --- /dev/null +++ b/test/fixtures/tesla_mock/gleasonator.com_host_meta @@ -0,0 +1,4 @@ +<?xml version="1.0" encoding="UTF-8"?> +<XRD xmlns="http://docs.oasis-open.org/ns/xri/xrd-1.0"> + <Link rel="lrdd" template="https://gleasonator.com/.well-known/webfinger?resource={uri}" type="application/xrd+xml" /> +</XRD>
\ No newline at end of file diff --git a/test/fixtures/tesla_mock/webfinger_spoof.json b/test/fixtures/tesla_mock/webfinger_spoof.json new file mode 100644 index 000000000..7c2a11f69 --- /dev/null +++ b/test/fixtures/tesla_mock/webfinger_spoof.json @@ -0,0 +1,28 @@ +{ + "aliases": [ + "https://gleasonator.com/users/alex", + "https://mitra.social/users/alex" + ], + "links": [ + { + "href": "https://gleasonator.com/users/alex", + "rel": "http://webfinger.net/rel/profile-page", + "type": "text/html" + }, + { + "href": "https://gleasonator.com/users/alex", + "rel": "self", + "type": "application/activity+json" + }, + { + "href": "https://gleasonator.com/users/alex", + "rel": "self", + "type": "application/ld+json; profile=\"https://www.w3.org/ns/activitystreams\"" + }, + { + "rel": "http://ostatus.org/schema/1.0/subscribe", + "template": "https://gleasonator.com/ostatus_subscribe?acct={uri}" + } + ], + "subject": "acct:trump@whitehouse.gov" +} |