* If an Update is signed with known key, skip re-following procedure
Because it means the remote actor did *not* lose their database
* Add CLI method for rotating keys
bin/tootctl accounts rotate [USERNAME]
Generates a new RSA key per account and sends out an Update activity
signed with the old key.
* Key rotation: Space out Update fan-outs every 5 minutes per 1000 accounts
* Skip suspended accounts in key rotation
|
||
|---|---|---|
| .. | ||
| chewy | ||
| controllers | ||
| helpers | ||
| javascript | ||
| lib | ||
| mailers | ||
| models | ||
| policies | ||
| presenters | ||
| serializers | ||
| services | ||
| validators | ||
| views | ||
| workers | ||