Skip to content

iCaptcha gate fails OPEN in enforce mode when the public key cannot load #206

Description

@beardthelion

Surfaced during review of #196 (pre-existing; icaptcha.rs untouched by that PR). Flagging as a product decision, not a clear-cut bug.

crates/gitlawb-node/src/icaptcha.rs:302-304 — inside decide, if v.key.is_none() { return Decision::Allow; } runs before the mode match, so in Mode::Enforce a missing key (iCaptcha unreachable at startup, DNS/BGP block, bad ICAPTCHA_PUBKEY) allows every create/registration with no proof. init() (icaptcha.rs:160-166) leaves key = None and only warns. The inline comment frames this as an intentional 'stay inert' fail-safe, so this is a deliberate-vs-safe call: enforce mode silently disabling on a fetch hiccup weakens the abuse protection the node leans on after PoW removal.

Options: in enforce mode fail closed (reject) when key.is_none(), or refuse to start in enforce mode without a key; at minimum document that enforce + no-key == fail-open. Needs a maintainer decision on which. Control flow verified by execution during the #196 review.

Activity

  1. added
    crate:nodegitlawb-node — the serving node and REST API
    kind:securityVulnerability fix or hardening
    sev:highMajor break or real security/trust risk, no easy workaround
    subsystem:apiNode REST API request/response surface
    subsystem:encryptionEncrypted subtrees, recipient blinding, key zeroization
    on Jul 15, 2026
  2. added
    sev:mediumDegraded but workaround exists
    and removed
    sev:highMajor break or real security/trust risk, no easy workaround
    on Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:nodegitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround existssubsystem:apiNode REST API request/response surfacesubsystem:encryptionEncrypted subtrees, recipient blinding, key zeroization

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions