You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix add-to local delivery resolution using caller's domain instead of the instance's own (#33)
resolveLocalDelivery decided which newly-added recipients were local by
parsing the domain out of the requesting identity, not this webapi
instance's own domain. That's correct for Send (the owner is always
local to their own home server) but wrong for AddRecipients, where any
existing participant — including a federated one on a different domain
— may add recipients. When a federated participant added a recipient
who actually was local to this instance, resolveLocalDelivery treated
them as remote and skipped them, while fmsgd's outbound sender also
skips local-domain recipients assuming webapi already handled them.
Neither side resolved delivery, leaving it stuck pending indefinitely.
Adds a required FMSG_DOMAIN env var carrying this instance's own
domain, threaded through MessageHandler as LocalDomain and used at
both resolveLocalDelivery call sites instead of parsing it from the
caller's identity. fmsg-docker's compose files already pass
FMSG_DOMAIN to the fmsg-webapi service, so no deployment changes are
needed there.
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
|`FMSG_DATA_DIR`|*(required)*| Path where message data files are stored, e.g. `/var/lib/fmsgd/`|
30
+
|`FMSG_DOMAIN`|*(required)*| The fmsg domain this instance serves, e.g. `example.com`. Used to tell local recipients (resolved directly via fmsgid) from federated ones (left to fmsgd), independent of which participant's identity happens to be making the request. |
30
31
|`FMSG_JWT_JWKS_URL`|*(prod)*| JWKS endpoint for the configured identity provider (e.g. `https://idp.example.com/.well-known/jwks.json`). When set, the API verifies EdDSA (Ed25519) JWTs. Public keys are fetched and cached, refreshed and looked up by the token's `kid` header. |
31
32
|`FMSG_JWT_ISSUER`|*(prod, required with JWKS)*| Expected `iss` claim value (e.g. `https://idp.example.com/`). Tokens with a different issuer are rejected. This must exactly match the token issuer. |
32
33
|`FMSG_JWT_AUDIENCE`|*(optional)*| When set, tokens must include this value in their `aud` claim. Leave unset if your identity provider does not issue an `aud` claim. |
@@ -199,6 +200,7 @@ by default; override with `FMSG_API_PORT`.
0 commit comments