From 5c1ddb4e2174aeeb76dfead9ac05cea61d2ebd74 Mon Sep 17 00:00:00 2001 From: Simon Vareille Date: Sun, 14 Jun 2020 18:03:24 +0200 Subject: [PATCH] Do not display unverified uids as part of a key for hkp index and vindex output This is not for security or privacy reasons, but to provide an accurate answer to a search request. --- src/route/hkp.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/route/hkp.js b/src/route/hkp.js index dcf7a4a..cfc69b7 100644 --- a/src/route/hkp.js +++ b/src/route/hkp.js @@ -136,7 +136,9 @@ class HKP { ctx.body = `info:${VERSION}:${COUNT}\npub:${fp}:${algo}:${key.keySize}:${created}::\n`; for (const uid of key.userIds) { - ctx.body += `uid:${encodeURIComponent(`${uid.name} <${uid.email}>`)}:::\n`; + if(uid.verified) { + ctx.body += `uid:${encodeURIComponent(`${uid.name} <${uid.email}>`)}:::\n`; + } } } }