You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/ipips/ipip-0337.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -70,7 +70,7 @@ To understand the design rationale, it is important to consider the concrete Ref
70
70
So this API proposal makes the following changes:
71
71
72
72
- The Delegated Content Routing API is defined using HTTP semantics, and can be implemented without introducing Reframe concepts nor IPLD
73
-
- There is a clear distinction between the RPC protocol (HTTP) and the API (Delegated Content Routing)
73
+
- There is a clear distinction between the [Kubo RPC](https://docs.ipfs.tech/reference/kubo/rpc/)and the vendor-agnostic Routing V1 HTTP API (introduced in :cite[ipip-0377]).
74
74
- "Method names" and cache-relevant parameters are pushed into the URL path
75
75
- Streaming support is removed, and default response size limits are added.
76
76
- We will add streaming support in a subsequent IPIP, but we are trying to minimize the scope of this IPIP to what is immediately useful
Copy file name to clipboardExpand all lines: src/ipips/ipip-0379.md
+12-29Lines changed: 12 additions & 29 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,13 +12,12 @@ relatedIssues:
12
12
- https://github.com/ipfs/specs/issues/343
13
13
- https://github.com/ipfs/specs/pull/337
14
14
- https://github.com/ipfs/specs/pull/377
15
+
xref:
16
+
- ipns-record
15
17
order: 379
16
18
tags: ['ipips']
17
19
---
18
20
19
-
- Start Date: 2023-02-13
20
-
- Related Issues:
21
-
22
21
## Summary
23
22
24
23
This IPIP specifies a set of HTTP APIs to offload naming system onto another process or server.
@@ -28,21 +27,17 @@ This IPIP specifies a set of HTTP APIs to offload naming system onto another pro
28
27
Expanding on the motivations of :cite[ipip-0337], the work here concentrates on delegation of _naming system_ over HTTP APIs. Naming is part of the core IPFS DHT functionality.
29
28
The performance of naming system over the IPFS DHT can suffer from long delays due to churn of records and quorum requirements.
30
29
31
-
## HTTP API Specification
30
+
## Detailed design
32
31
33
-
See :cite[http-ipns-routing] specification.
32
+
See :cite[http-routing-v1] specification.
34
33
35
34
## Design rationale
36
35
37
36
The rationale for delegated IPNS over HTTP APIs closely follows the reasoning listed in :cite[ipip-0337].
38
37
39
38
The document proposes the following:
40
39
- Use of HTTP semantics for publication and resolution of naming records.
41
-
- Preference for human-readable request and response encoding, such as JSON format
42
-
- Optional backward compatibility support for the existing ProtocolBuffer format using `Content-Type: application/vnd.ipfs.ipns-record`
43
-
- Use of extra headers in `OPTIONS` response to communicate the supported capabilities and limitations, namely:
44
-
-`X-Ipns-Allow-Max-Size` -- to signal maximum supported IPNS record size
45
-
-`X-Ipns-Allow-Protobuf` -- to signal whether the server supports ProtocolBuffer formatted records.
40
+
- Use of existing :ref[IPNS Record] serialization format through `Content-Type: application/vnd.ipfs.ipns-record`.
46
41
- Streaming interaction is not supported.
47
42
48
43
### User benefit
@@ -51,44 +46,32 @@ The ability of offload naming onto another process or server via an idiomatic an
This format is widely in use in IPNS over PubSub and DHT routing systems.
60
55
One of the motivations of this document is to introduce simple to use HTTP APIs and ultimately reduce barrier for interaction across alternative systems.
61
56
Further, interoperability across the existing and HTTP APIs is also desirable in order to reduce the barrier for adoption of the delegated HTTP APIs.
62
57
63
-
The specification here maintains backwards compatibility in terms of record serialisation, with preference for human-readable formats such as JSON.
64
58
To maximize interoperability with existing ecosystem, the canonical IPNS record serialization format :cite[ipns-record] (`0x0300`) can be requested with content type `application/vnd.ipfs.ipns-record`.
65
59
66
-
##### Reframe
67
-
68
-
See "Backwards Compatibility" section of :cite[ipip-0337].
69
-
70
-
#### Forwards Compatibility
71
-
72
-
See "Forwards Compatibility" section of :cite[ipip-0337].
73
-
74
60
### Security
75
61
76
62
All interaction over the APIs should use TLS to protect against third-party observation and tampering.
77
-
Additionally, the IPNS records are signed by the publisher's identity and contain sequence number to avoid replay attacks.
78
-
79
-
To avoid Denial of Service attack, maximum IPNS record size of `10 KiB` applies.
80
-
Implements are permitted to set a lower limit. If lower than the default maximum, the limit should be discoverable via `OPTIONS` request with header key `X-Ipns-Allow-Max-Size` with value specified as the number of bytes.
63
+
Additionally, the IPNS records must be validated according to the rules stated in :cite[ipns-record] before further processing.
81
64
82
-
Similarly, a client may check if a server supports ProtocolBuffer formatted records by checking the `X-Ipns-Allow-Protobuf` header key in response to `OPTIONS` request. If present the header value must be either `true` or `false` the absence of the header indicates that ProtocolBuffer formatted records are not supported.
65
+
To avoid Denial of Service attack, maximum IPNS record size defined in :cite[ipns-record] applies.
83
66
84
67
Privacy in delegated IPNS is out of scope for this work.
85
-
- The usual JSON parsing rules apply. To prevent potential Denial of Service (DoS) attack, clients should ignore responses larger than 100 providers and introduce a byte size limit that is applicable to their use case.
0 commit comments