fix(avatar): use sha256 and inline the federated avatar lookup (#38843)

- Hash emails with sha256. Gravatar moved to sha256, and both it and
libravatar.org serve the same image for either hash.
- Drop `strk.kbt.io/projects/go/libravatar` for a 46 line inline SRV
lookup. It could not bound or cancel its DNS query and panicked on an
unexpected resolver error. The replacement carries the request context
and a 3s timeout.
- Fix federated avatars querying DNS for every avatar on every render.
`loadAvatarSetting` compared a cache field that was never assigned, so
each call rebuilt the resolver and dropped its cache. That cache is
gone, both settings are read where they are used.
- Migration 348 recreates `email_hash` with a 64 char hash column and a
`hash_type` column, so a later algorithm change can tell old rows apart.
The MD5 rows are unreachable and their `UNIQUE` email index would reject
the SHA256 replacements.
- Fix a re-saved avatar form replacing an uploaded avatar with a random
one.
- Remove the `duoshuo` `GRAVATAR_SOURCE` alias, that service shut down
in 2017.
- Remove dead i18n key.

Fixes: https://github.com/go-gitea/gitea/issues/34284
Fixes: https://github.com/go-gitea/gitea/issues/28110
Docs: https://gitea.com/gitea/docs/pulls/499
Signed-off-by: silverwind <me@silverwind.io>
This commit is contained in:
silverwind
2026-08-10 23:13:28 +00:00
committed by GitHub
parent 52d0e18dac
commit e3ee28f15b
17 changed files with 221 additions and 216 deletions
+30 -36
View File
@@ -4,54 +4,48 @@
package avatars_test
import (
"strconv"
"testing"
avatars_model "gitea.dev/models/avatars"
system_model "gitea.dev/models/system"
"gitea.dev/models/unittest"
"gitea.dev/modules/setting"
"gitea.dev/modules/setting/config"
"github.com/stretchr/testify/assert"
)
const gravatarSource = "https://secure.gravatar.com/avatar/"
func disableGravatar(t *testing.T) {
err := system_model.SetSettings(t.Context(), map[string]string{setting.Config().Picture.EnableFederatedAvatar.DynKey(): "false"})
assert.NoError(t, err)
err = system_model.SetSettings(t.Context(), map[string]string{setting.Config().Picture.DisableGravatar.DynKey(): "true"})
assert.NoError(t, err)
}
func enableGravatar(t *testing.T) {
err := system_model.SetSettings(t.Context(), map[string]string{setting.Config().Picture.DisableGravatar.DynKey(): "false"})
assert.NoError(t, err)
setting.GravatarSource = gravatarSource
}
func TestHashEmail(t *testing.T) {
assert.Equal(t,
"d41d8cd98f00b204e9800998ecf8427e",
avatars_model.HashEmail(""),
)
assert.Equal(t,
"353cbad9b58e69c96154ad99f92bedc7",
avatars_model.HashEmail("gitea@example.com"),
)
}
func TestSizedAvatarLink(t *testing.T) {
func TestEmailAvatarLink(t *testing.T) {
const email = "gitea@example.com"
const emailHash = "72af1071d72449afe29e816060e78e78fd85829ba6e2497aa1d4eedd3c9dc611"
setting.AppSubURL = "/testsuburl"
setting.GravatarSource = "https://secure.gravatar.com/avatar/"
disableGravatar(t)
config.GetDynGetter().InvalidateCache()
assert.Equal(t, emailHash, avatars_model.HashEmail(" Gitea@Example.com "))
setAvatarConfig := func(disableGravatar, enableFederatedAvatar bool) {
assert.NoError(t, system_model.SetSettings(t.Context(), map[string]string{
setting.Config().Picture.DisableGravatar.DynKey(): strconv.FormatBool(disableGravatar),
setting.Config().Picture.EnableFederatedAvatar.DynKey(): strconv.FormatBool(enableFederatedAvatar),
}))
config.GetDynGetter().InvalidateCache()
}
setAvatarConfig(true, false)
assert.Equal(t, "/testsuburl/assets/img/avatar_default.png",
avatars_model.GenerateEmailAvatarFastLink(t.Context(), "gitea@example.com", 100))
avatars_model.GenerateEmailAvatarFastLink(t.Context(), email, 100))
enableGravatar(t)
config.GetDynGetter().InvalidateCache()
assert.Equal(t,
"https://secure.gravatar.com/avatar/353cbad9b58e69c96154ad99f92bedc7?d=identicon&s=100",
avatars_model.GenerateEmailAvatarFastLink(t.Context(), "gitea@example.com", 100),
)
setAvatarConfig(false, false)
assert.Equal(t, "https://secure.gravatar.com/avatar/"+emailHash+"?d=identicon&s=100",
avatars_model.GenerateEmailAvatarFastLink(t.Context(), email, 100))
// the DNS query waits until the browser follows the link
setAvatarConfig(false, true)
assert.Equal(t, "/testsuburl/avatar/"+emailHash+"?size=100",
avatars_model.GenerateEmailAvatarFastLink(t.Context(), email, 100))
storedEmail, err := avatars_model.GetEmailForHash(t.Context(), emailHash)
assert.NoError(t, err)
assert.Equal(t, email, storedEmail)
assert.Equal(t, "sha256", unittest.AssertExistsAndLoadBean(t, &avatars_model.EmailHash{Hash: emailHash}, unittest.OrderBy("hash")).HashType)
}