Skip to content

feat(storage): guard the profile card of registered WebIDs - #147

Open
bourgeoa wants to merge 1 commit into
mainfrom
webid-guard
Open

bourgeoa wants to merge 1 commit into
mainfrom
webid-guard

Conversation

@bourgeoa

Copy link
Copy Markdown
Member

Adds a pivot-side profile-card guard so the protection no longer depends on an upstream Community Solid Server change:

  • GuardedWebIdStore extends the CSS BaseWebIdStore with hasWebId, an exact indexed lookup on the account storage;
  • ProfileCardGuard extends the CSS PassthroughStore and, for the card of a registered WebID, requires every write (PUT/POST or the result of a PATCH) to remain valid RDF that still contains the <webId> solid:oidcIssuer <baseUrl/> triple, and forbids deleting the card while its WebID is registered;
  • a new pivot config module wires the guard between the RDF patching store and the converting store, and routes the account/WebID key-value storage past it to avoid a dependency cycle;
  • the guard is enabled in the prod, suffix and dev server configs.

Both classes extend types already present in the published @solid/community-server, so no CSS fork or patch is required. Adds unit and integration tests covering the full WebID lifecycle.

Adds a pivot-side profile-card guard so the protection no longer depends
on an upstream Community Solid Server change:

- GuardedWebIdStore extends the CSS BaseWebIdStore with hasWebId, an exact
  indexed lookup on the account storage;
- ProfileCardGuard extends the CSS PassthroughStore and, for the card of a
  registered WebID, requires every write (PUT/POST or the result of a
  PATCH) to remain valid RDF that still contains the
  `<webId> solid:oidcIssuer <baseUrl/>` triple, and forbids deleting the
  card while its WebID is registered;
- a new pivot config module wires the guard between the RDF patching store
  and the converting store, and routes the account/WebID key-value storage
  past it to avoid a dependency cycle;
- the guard is enabled in the prod, suffix and dev server configs.

Both classes extend types already present in the published
@solid/community-server, so no CSS fork or patch is required. Adds unit
and integration tests covering the full WebID lifecycle.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant