Replies to a persona's posts reach its followers; personas join remote events
Two owner decisions of 2026-10-05, recorded in the roadmap.
Replies passed on ("the fediverse is broken without"): a public or unlisted
reply from another server to a persona's public, unlisted or followers-only
post goes on to the persona's followers as its author's server sent it, as
Mastodon forwards it, never to the replier's own server, never for a
local-only or group post; its edit and deletion follow. Only an activity its
own actor delivered is passed on (Arrival.Raw), so nothing forwarded is
forwarded again. The town checks it as relay.reply cells (specs/relay-five:
882 checks pass); Mastodon takes a passed-on activity only with an LD
signature, which GoToSocial and Akkoma don't add, and the checker knows it.
Events: a persona joins another server's event with a Join and leaves it with
a Leave, both to the organiser only, through
POST /api/privapub/v1/statuses/:id/join|leave; the organiser's Accept or
Reject is routed by our join id and shows as privapub.event.participation.
Events by invitation or taken on another site are refused before anything
is sent. Mobilizon's scenario joins and leaves an event (28 checks) and keeps
one for decePubClient's e2e.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
2b42377b3f
commit
0646de22bd
24 files changed
+676
-26
No files matched your search
@@ -88,7 +88,8 @@ PrivaPub/ ASP.NET Core Web API, net10.0
|
||||
Inbox/ InboxReceiver (verify, queue, 202) → InboxProcessor (job) → Handlers/{Follow,Accept,Reject,
|
||||
Undo,Create,Update,Delete,Like,Announce}; RemotePosts (build, fetch parents, FetchAncestors);
|
||||
RemoteReplies (FetchReplies: a thread's `context`, else `replies` two levels down);
|
||||
Forwarded (what a thread's server passes on, believed as far as the origin vouches)
|
||||
Forwarded (what a thread's server passes on, believed as far as the origin vouches);
|
||||
ReplyRelay (third-party replies to a persona's posts passed on to its followers)
|
||||
Outbox/ OutboxPublisher (who a post goes to), DeliveryService (queues jobs) + DeliveryJobHandler
|
||||
Rendering/ ActivityPubRenderer (Mastodon @context, actors, notes, collections)
|
||||
Domain/
|
||||
@@ -99,7 +100,8 @@ PrivaPub/ ASP.NET Core Web API, net10.0
|
||||
Relationships/ RelationshipService (blocks, mutes, account domain blocks; Hidden), ReportService
|
||||
Media/ MediaService (libvips, ffmpeg remux, blurhash), MediaProxy, MediaJanitor
|
||||
Domain/Statuses/ StatusService: publish, edit, remove, favourite, reblog, for a persona (both client APIs use it);
|
||||
InteractionApprovals: GoToSocial's canReply/canLike/canAnnounce, judged, asked and answered
|
||||
InteractionApprovals: GoToSocial's canReply/canLike/canAnnounce, judged, asked and answered;
|
||||
Participations: a persona's Join and Leave of a remote event, and the organiser's answer
|
||||
Api/Mastodon/
|
||||
Auth/ OpenIddict setup (keys in Mongo), MastodonScopes, TokenController, OAuthPruner
|
||||
Infrastructure/ MastodonController (avatar context, scopes, errors, Link), MastodonParams, MastodonJson, Page
|
||||
@@ -231,6 +233,14 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
fetched as context. Followers-only is detected by the author's stored `followers` URL.
|
||||
14. **Home timelines are written, not computed:** every stored or created post goes through `Fanout.Distribute`, and
|
||||
every delete removes its `TimelineEntry` rows. Local deletes are soft (content cleared, 410 Tombstone).
|
||||
15. **What PrivaPub passes on is exactly what it received** (owner decision 2026-10-05). A public or unlisted reply from
|
||||
another server to a persona's public, unlisted or followers-only post, and its Update and Delete, go to the
|
||||
persona's followers as the activity arrived (`Arrival.Raw`, `Federation/Inbox/ReplyRelay.cs`), signed by the
|
||||
persona for the transport only: never to the replier's own server, never for a local-only or group post. Only an
|
||||
activity its own actor delivered carries `Raw`, so a forwarded one is never passed on again.
|
||||
16. **An `Accept` or `Reject` is routed by what it answers:** our Follow (`FollowService`, any `-again-N` resend), an
|
||||
interaction request (`InteractionApprovals`, with the author's authorization read back from its origin) or a
|
||||
persona's `Join` (`Participations`, by its `/grunts/join-<id>` id), each only from the origin of what it answers.
|
||||
|
||||
## Mastodon client API invariants
|
||||
|
||||
@@ -552,8 +562,9 @@ tools/pasture/run.sh down # removes e
|
||||
extension), with the pasture's bundle mounted over certifi's and castore's CA files (hackney trusts only those) and
|
||||
the system store, and geocoding pointed at a closed local port. `mobilizon_ctl users.new` makes mzuser (it splits
|
||||
its arguments on spaces); the API is GraphQL (`/api`), signed in by the `login` mutation. An event made through it
|
||||
without options has its comments closed. `scenarios/mobilizon.sh`, 23 checks: a group and its events (dates, place),
|
||||
comments both ways, the organiser's edit, closed comments and deletes, a group post, the unfollow.
|
||||
without options has its comments closed. `scenarios/mobilizon.sh`, 27 checks: a group and its events (dates, place),
|
||||
alice joining an event (Mobilizon's participant row and its Accept) and leaving it, comments both ways, the
|
||||
organiser's edit, closed comments and deletes, a group post, the unfollow.
|
||||
- **Gancio (1.28.2):** cisti's image on sqlite in the `pasture-gancio-data` volume, whose `config.json` is written before
|
||||
the first start (without it Gancio waits in its setup wizard), trusting Caddy's CA through `NODE_EXTRA_CA_CERTS`.
|
||||
`gancio users create` makes gcadmin; `gancio settings set enable_resources true` keeps fediverse replies. One
|
||||
|
||||
Reference in new issue
Block a user