From 490f43ec8c1fecf7ab142450f48c3ef5e25bcee2 Mon Sep 17 00:00:00 2001 From: Bretton Date: Wed, 26 Aug 2026 23:36:41 -0700 Subject: [PATCH 1/2] chore(pds): bump PDS 0.4.193 -> 0.4.5027 (@atproto/pds 0.5.27) Image tag 0.4.5027 encodes upstream @atproto/pds 0.5.27 (distro keeps the 0.4 line: 0.4.). Digest verified via docker buildx imagetools inspect; :latest resolves to the same index. Why now: the 0.4.193 image ships Node 20.19.5, EOL since 2026-04-30 and excluded from the June 2026 Node security release (incl. CVE-2026-48618 TLS wildcard auth bypass, CVE-2026-48933 WebCrypto DoS). 0.4.5027 is on Node 24.18.1. Reviewed for this range: zero DB migrations (DDL byte-identical across all 9 migration sets; rollback to 0.4.193 boot-tested on an upgraded data dir), firehose/subscribeRepos wire format unchanged, blob layout unchanged, no required env changes (10 removed vars are OAuth-screen colours we never set; 6 added are optional). Operator impact: @atproto/oauth-provider now enforces session lifetimes (previously dead code). The AppView is a confidential client (private_key_jwt, /oauth-client-metadata.json), so it gets the extended limits: 2-year session (already capped at 18 months by our SealedTokenTTL) and a 3-month refresh-inactivity window. Only sessions idle >90 days are rejected on their next refresh; active devices are unaffected. The legacy public /client-metadata.json document is unused since Nov 2025. Rollback: re-pin 0.4.193@sha256:50e60af2... and up -d --no-deps pds. Co-Authored-By: Claude Fable 5 --- docker-compose.prod.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 6ed57dd..61286b5 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -213,7 +213,7 @@ services: # Bump: `docker buildx imagetools inspect ghcr.io/bluesky-social/pds:`. # Same depends_on caveat as postgres above: a changed pin is applied by # the next `up -d caddy` unless --no-deps is used. - image: ghcr.io/bluesky-social/pds:0.4.193@sha256:50e60af25fa7b580ddae8fc18ae97b1d7cdeb1a3068a3d345f9161cc7796417b + image: ghcr.io/bluesky-social/pds:0.4.5027@sha256:d95725b24dbe53af9d91dc69750556931ebed6c396f2cfa42b221434db642f12 container_name: coves-prod-pds restart: unless-stopped ports: -- 2.51.2 From 8a79c1525649d75d4a9bb0ffc509f98ea2d19ce4 Mon Sep 17 00:00:00 2001 From: Bretton Date: Thu, 27 Aug 2026 00:01:41 -0700 Subject: [PATCH 2/2] chore(oauth): remove legacy public client-metadata.json The AppView has registered as a confidential client at /oauth-client-metadata.json (private_key_jwt, served by HandleClientMetadata) since Jan 2026; the static public document at /client-metadata.json (token_endpoint_auth_method: none) was last used by two sessions in Nov 2025 and is referenced by no code or client. Drop the file, its Caddy route, and the unused OAUTH_CLIENT_ID env passthrough so the only advertised OAuth client is the confidential one. Co-Authored-By: Claude Fable 5 --- Caddyfile | 6 ------ docker-compose.prod.yml | 3 +-- static/client-metadata.json | 18 ------------------ 3 files changed, 1 insertion(+), 26 deletions(-) delete mode 100644 static/client-metadata.json diff --git a/Caddyfile b/Caddyfile index 05081ac..ffd1726 100644 --- a/Caddyfile +++ b/Caddyfile @@ -107,12 +107,6 @@ coves.social { file_server } - # Serve OAuth client metadata - handle /client-metadata.json { - root * /srv - file_server - } - # /img/* belongs to the media hostname, and only to the media hostname. # # The AppView registers the image-proxy route on its router with no Host diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 61286b5..2bbb38f 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -96,7 +96,6 @@ services: SKIP_DID_WEB_VERIFICATION: "false" # OAuth (for community account provisioning) - OAUTH_CLIENT_ID: ${OAUTH_CLIENT_ID} OAUTH_REDIRECT_URI: ${OAUTH_REDIRECT_URI} OAUTH_SEAL_SECRET: ${OAUTH_SEAL_SECRET} @@ -322,7 +321,7 @@ services: - ./Caddyfile:/etc/caddy/Caddyfile:ro - caddy-data:/data - caddy-config:/config - # Static files (.well-known, client-metadata.json, oauth callback) + # Static files (.well-known DID docs, images) - ./static:/srv:ro networks: - coves-internal diff --git a/static/client-metadata.json b/static/client-metadata.json deleted file mode 100644 index 00ea85d..0000000 --- a/static/client-metadata.json +++ /dev/null @@ -1,18 +0,0 @@ -{ - "client_id": "https://coves.social/client-metadata.json", - "client_name": "Coves", - "client_uri": "https://coves.social", - "logo_uri": "https://coves.social/logo.png", - "tos_uri": "https://coves.social/terms", - "policy_uri": "https://coves.social/privacy", - "redirect_uris": [ - "https://coves.social/oauth/callback", - "social.coves:/oauth/callback" - ], - "scope": "atproto", - "grant_types": ["authorization_code", "refresh_token"], - "response_types": ["code"], - "application_type": "native", - "token_endpoint_auth_method": "none", - "dpop_bound_access_tokens": true -} -- 2.51.2