Merge pull request #142 from theta42/duckdns-validate-via-txt

DuckDNS: validate token via a TXT write, not the A/AAAA record
This commit is contained in:
2026-07-16 12:56:24 -04:00
committed by GitHub
+7 -6
View File
@@ -67,14 +67,15 @@ class DuckDns extends DnsApi{
} }
// No API to enumerate owned subdomains, so the operator supplies them. // No API to enumerate owned subdomains, so the operator supplies them.
// This call both validates the token and, as a side effect, syncs each // This call validates the token by writing a fixed marker to the TXT
// domain's A/AAAA record to this host's current public IP if the token // record only -- never `ip`/`ipv6` -- so adding/validating a provider
// is valid (DuckDNS auto-detects the caller's IP when `ip` is omitted) // never changes where the domain's A/AAAA records actually point. (An
// — the same thing an operator would need to do anyway when pointing a // earlier version omitted `ip` here, which made DuckDNS auto-detect and
// fresh DuckDNS domain at this proxy. // apply this host's public IP as a side effect of validation; that's
// exactly what this call must not do.)
async listDomains(){ async listDomains(){
let labels = this.subdomains.split(',').map(d => this.__normalizeLabel(d.trim())).filter(Boolean); let labels = this.subdomains.split(',').map(d => this.__normalizeLabel(d.trim())).filter(Boolean);
await this.update(labels.join(','), {}); await this.update(labels.join(','), {txt: 'theta42-proxy-validated'});
return labels.map(label => ({domain: `${label}.duckdns.org`})); return labels.map(label => ({domain: `${label}.duckdns.org`}));
} }