gotosocial/internal
kim d8c4d9fc5a [feature] proof of work scraper deterrence (#4043)
This adds a proof-of-work based scraper deterrence to GoToSocial's middleware stack on profile and status web pages. Heavily inspired by https://github.com/TecharoHQ/anubis, but massively stripped back for our own usecase.

Todo:
- ~~add configuration option so this is disabled by default~~
- ~~fix whatever weirdness is preventing this working with CSP (even in debug)~~
- ~~use our standard templating mechanism going through apiutil helper func~~
- ~~probably some absurdly small performance improvements to be made in pooling re-used hex encode / hash encode buffers~~ the web endpoints aren't as hot a path as API / ActivityPub, will leave as-is for now as it is already very minimal and well optimized
- ~~verify the cryptographic assumptions re: using a portion of token as challenge data~~ this isn't a serious application of cryptography, if it turns out to be a problem we'll fix it, but it definitely should not be easily possible to guess a SHA256 hash from the first 1/4 of it even if mathematically it might make it a bit easier
- ~~theme / make look nice??~~
- ~~add a spinner~~
- ~~add entry in example configuration~~
- ~~add documentation~~

Verification page originally based on https://github.com/LucienV1/powtect

Co-authored-by: tobi <tobi.smethurst@protonmail.com>
Reviewed-on: https://codeberg.org/superseriousbusiness/gotosocial/pulls/4043
Reviewed-by: tobi <tsmethurst@noreply.codeberg.org>
Co-authored-by: kim <grufwub@gmail.com>
Co-committed-by: kim <grufwub@gmail.com>
2025-04-28 20:12:27 +00:00
..
admin [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
ap [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
api [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
cache [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
cleaner [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
config [feature] proof of work scraper deterrence (#4043) 2025-04-28 20:12:27 +00:00
db [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
email [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
federation [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
filter [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
gtscontext [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
gtserror [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
gtsmodel [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
headerfilter [feature] request blocking by http headers (#2409) 2023-12-18 14:18:25 +00:00
httpclient [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
id [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
iotools [performance] update storage backend and make use of seek syscall when available (#2924) 2024-05-22 11:46:24 +02:00
language [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
log [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
media [chore] add woodpecker ci/cd pipelines (#4061) 2025-04-27 11:22:35 +00:00
messages [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
middleware [feature] proof of work scraper deterrence (#4043) 2025-04-28 20:12:27 +00:00
oauth [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
observability [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
oidc [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
paging [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
processing [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
queue [performance] update go-structr and go-mutexes with memory usage improvements (#2909) 2024-05-13 08:05:46 +00:00
regexes feat: Relax URL matching (#3925) 2025-03-24 14:13:32 +01:00
router [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
scheduler [feature] add support for polls + receiving federated status edits (#2330) 2023-11-08 14:32:17 +00:00
state [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
storage [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
stream [feature] Conversations API (#3013) 2024-07-23 20:44:31 +01:00
subscriptions [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
text [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
trans [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
transport [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
typeutils [chore] Rewrite all remaining Github links 2025-04-27 13:40:22 +02:00
uris [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
util [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
validate [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
web [feature] proof of work scraper deterrence (#4043) 2025-04-28 20:12:27 +00:00
webpush [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00
workers [feature] Move to code.superseriousbusiness.org 2025-04-26 15:38:43 +02:00