Skip to content

0.4.1 — Webmention endpoint hardening

Choose a tag to compare

@vgururao vgururao released this 28 Sep 18:47
· 181 commits to main since this release

Security release. Recommended for every live node.

POST {mount}/webmention is the only unauthenticated public endpoint in this program, and the origins that advertise it are now published in a public directory — so the defaults shipped here are the ones strangers find. Protocol 0.3, unchanged. Level 1, unchanged.

  • The rate limit now also counts the registrable domain, at 120/hour, alongside the existing per-host cap of 60/hour. Per-host counting was defeated by wildcard DNS: a.spam.example and b.spam.example are different hosts, so a flooder paid one DNS label per 60 accepted claims. The domain cap is the looser of the two on purpose — the grouping is a documented heuristic, and a hosting suffix it does not know about would otherwise cap every site behind that suffix collectively.
  • A global cap of 300 accepted claims/hour on the endpoint as a whole. No per-source limit bounds a total: fifty domains sending 119 each sat inside every previous cap while spending up to ~11,900 outbound fetches at URLs strangers chose, on the deployer's Cloudflare account. Once this cap binds, further new claims in that window are refused, so the 429 now carries Retry-After.
  • failed inbound claims are deleted after 30 days, on the existing cron. They previously accumulated forever, which made an endpoint anyone can POST to into an unbounded write surface. verified, gone and pending rows are untouched.

Migrations: none. Every cap counts columns that already exist, so upgrading is a redeploy with no database step.

Upgrading

git pull                      # see the note below if your copy came from blygger-spec
npm ci --legacy-peer-deps
npm run deploy

If your copy came from blygger-spec/worker/ — i.e. you stood your node up before 2026-09-28 — git pull will not bring you here: the client left that repo by git subtree split, so this history is the same content with different commit ids, and worker/ no longer exists there. Clone this repo fresh and carry over your wrangler.jsonc (D1 database_id, R2 bucket, routes, vars). Your secrets, database and bucket are untouched by an upgrade.

Full reasoning in CHANGELOG.md, and in self-host-plan.md §9.1.

A note on how you heard about this

You probably didn't — there is no notification channel yet. Watching this repo's releases is currently the only mechanism, which is a gap we are fixing from the directory side (roadmap item 3.1). If you run a blyg, blygger.com now takes an optional contact when you submit, used for exactly this and never published.