From 7acc9b4471fb50e949e0bcf936e420a2711b7cf6 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Sun, 18 Jan 2026 18:02:55 -0900 Subject: [PATCH] Add client timeouts for plc lookups --- backend/internal/api/annotations.go | 5 ++++- backend/internal/api/apikey.go | 8 +++++++- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/backend/internal/api/annotations.go b/backend/internal/api/annotations.go index 948457f..7be9214 100644 --- a/backend/internal/api/annotations.go +++ b/backend/internal/api/annotations.go @@ -480,7 +480,10 @@ func (s *AnnotationService) DeleteReply(w http.ResponseWriter, r *http.Request) func resolveDIDToPDS(did string) (string, error) { if strings.HasPrefix(did, "did:plc:") { - resp, err := http.Get("https://plc.directory/" + did) + client := &http.Client{ + Timeout: 10 * time.Second, + } + resp, err := client.Get("https://plc.directory/" + did) if err != nil { return "", err } diff --git a/backend/internal/api/apikey.go b/backend/internal/api/apikey.go index 8c7daae..03d6472 100644 --- a/backend/internal/api/apikey.go +++ b/backend/internal/api/apikey.go @@ -311,7 +311,13 @@ func (h *APIKeyHandler) getSessionByDID(did string) (*SessionData, error) { return nil, fmt.Errorf("invalid session DPoP key: %w", err) } - pds, _ := resolveDIDToPDS(sessDID) + pds, err := resolveDIDToPDS(sessDID) + if err != nil { + return nil, fmt.Errorf("failed to resolve PDS: %w", err) + } + if pds == "" { + return nil, fmt.Errorf("PDS not found for DID: %s", sessDID) + } return &SessionData{ DID: sessDID, -- 2.51.2