mirror of https://github.com/pixelfed/pixelfed
staging
l10n_crowdin_translations
dev
feature/configurable-min-registration-age
configcache-clean-rebased
dockerfile-compile-ffmpeg-x264-x265
fix/media-storage-optimized-charge
fix/dm-remote-delete-media-leak
feat/emoji-cloud-storage-v2
feat/story-cloud-storage-v2
fix/hashtags-outside-bmp
copilot/review-old-issues
groups
vue3
v0.1.9
v0.10.0
v0.10.1
v0.10.10
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.11.10
v0.11.11
v0.11.12
v0.11.13
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.11.7
v0.11.8
v0.11.9
v0.12.0
v0.12.1
v0.12.10
v0.12.11
v0.12.12
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9
v0.13.0
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.5.9
v0.6.0
v0.6.1
v0.7.6
v0.8.0
v0.8.5
v0.8.6
v0.9.0
v0.9.4
v0.9.5
v0.9.6
${ noResults }
1 Commits (0fc121b6856901fa3e4107b568cab1be1783535c)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
2ad6e28318 |
Add timeout, retry and error handling to remote auth HTTP calls
RemoteAuthService::getVerifyCredentials, getFollowing and getToken made outbound HTTP requests to a user-controlled remote instance during the Mastodon login flow with no timeout, no retry and no exception handling. A slow or hostile instance could hang the request or surface an uncaught exception. Wrap all three in timeout(20)->retry(3, 750) with try/catch that returns false on failure, matching the existing pattern in isDomainCompatible(). Callers already treat a falsy return as a failure; add the missing guard at the one verify_credentials call site that accessed the result array without checking it first. Adds RemoteAuthServiceTest covering connection failure, server error and success paths. |
3 weeks ago |