diff --git a/docs/configuration.md b/docs/configuration.md index 007347f..be885c6 100644 --- a/docs/configuration.md +++ b/docs/configuration.md @@ -60,7 +60,7 @@ hydrant is configured via environment variables, all prefixed with `HYDRANT_` (e | `BACKFILL_STRATEGY` | `auto` | backfill strategy: `full` keeps the existing `getRepo` path, `sparse-filter` attempts authenticated sparse collection backfill before falling back to full, `auto` probes filtered repos and falls back to full for tiny MST roots | | `REPO_FETCH_TIMEOUT` | `5min` | timeout for fetching a repository | | `VERIFY_SIGNATURES` | `full` | signature verification level: `full`, `backfill-only`, or `none` | -| `VERIFY_CIDS` | `true` | reject firehose and backfill CAR blocks whose content does not hash to their claimed CID. without this, signature verification does not cover record content | +| `VERIFY_CIDS` | `true` | reject firehose and backfill CAR blocks whose content does not hash to their claimed CID. without this, signature verification does not cover the MST: a PDS or relay can forge nodes that map a key to a different record. record bodies are hashed before they are stored either way | | `PLC_URL` | `https://plc.wtf`, `https://plc.directory` (full network) | base URL(s) of the PLC directory, comma-separated | | `IDENTITY_CACHE_SIZE` | `1000000` | number of identity entries to cache in memory | diff --git a/src/config.rs b/src/config.rs index 45001a2..ee0e80b 100644 --- a/src/config.rs +++ b/src/config.rs @@ -197,9 +197,10 @@ pub struct Config { /// set via `HYDRANT_GET_REPO_CONCURRENCY_LIMIT`; defaults to 2. pub get_repo_concurrency_limit: usize, - /// if `true`, rejects CAR blocks whose content does not hash to their claimed CID. - /// CAR readers do not check this, so without it signature verification does not cover - /// record content. set via `HYDRANT_VERIFY_CIDS`. default: true. + /// if `true`, rejects CAR blocks whose content does not hash to their claimed CID. without + /// it, signature verification does not cover the MST: a PDS or relay can forge nodes that + /// map a key to a different record. record bodies are hashed before they are stored either + /// way. set via `HYDRANT_VERIFY_CIDS`. default: true. pub verify_cids: bool, /// if `true`, record blocks are not stored; only the index (records, counts, events) is kept.