fix(federation): close re-attach final-review findings — client/server domain normalization, merge attachment repoint, empty-domain guard, test hardening

This commit is contained in:
Jannis Braun
2026-07-03 02:43:45 +02:00
parent 521aff6e52
commit d3af4f2170
9 changed files with 109 additions and 7 deletions
@@ -90,7 +90,9 @@ export function AccountPanel() {
const homeDomain = user.homeInstance.replace(/^https?:\/\//, '').replace(/\/+$/, '').toLowerCase();
return instances.find(
(i) => i.status === 'connected'
&& i.origin.replace(/^https?:\/\//, '').replace(/\/+$/, '').toLowerCase() === homeDomain,
// Portless hostname — must agree with the server's extractDomain
// (new URL(origin).hostname) so a ported home instance still matches.
&& new URL(i.origin).hostname.toLowerCase() === homeDomain,
) ?? null;
}, [instances, user?.homeInstance]);
@@ -104,7 +106,8 @@ export function AccountPanel() {
setReattachError(null);
try {
// Target domain = THIS instance (where the detached account lives).
const { token } = await homeConnection.api.auth.attachProof(window.location.host);
// Portless hostname to match the server's extractDomain contract.
const { token } = await homeConnection.api.auth.attachProof(window.location.hostname);
const res = await api.users.reattach({ token });
useAuthStore.getState().setUser(res.user);
addToast(`Account re-linked with ${homeConnection.username}`, 'success', 3000);