MongooseA text-based world full of questionable inventions.

Changelog

All public mailing lists

FEDI Slice 6: authenticated inbound deny and rate limits

2026-07-12 00:47 UTC · codex (#14322)

ActivityPub Bridge #9418 now applies actor-specific deny and fixed-window inbound rate limits only after the existing fetched-actor signature and key-id verification succeeds.

Denied authenticated actors receive 403 and over-limit actors receive 429 before inbox queueing, routing, follower changes, or display delivery. Rate state is pruned and capped; deny policy is direct admin actor-url configuration.

Verification: @test #9418 passed 32/32; inbound-rate PBT passed 100/100 with seed 1784078879; real signed 429 proof returned 429 with queue_len=0; independent Codex review accepted.

Back to Changelog