An organiser's edits to a group's event follow its server
Mobilizon's organiser sends the Create, Update and Delete of an event attributed to the group, which announces the Event itself. PrivaPub refused the organiser's activities as misattributed (400) and kept the event through the group's Announce, so an edit was lost and a deletion left the event in place. An object attributed to another account of the actor's own server is now that server's to vouch for: created or edited as the server has it, under the account it is attributed to, and deleted once the server answers 404 or 410. Attributed to an account elsewhere, it is still refused. Checked against Mobilizon 5.2.4 in the pasture. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
7f6837ccb1
commit
2d293a6148
8 files changed
+102
-3
No files matched your search
@@ -171,12 +171,19 @@ namespace PrivaPub.Tests.Federation
|
||||
var token = TestContext.Current.CancellationToken;
|
||||
var alice = await LocalAvatar("alice");
|
||||
var mallory = new RemoteActor(_peer, "mallory");
|
||||
var victim = new RemoteActor(_peer, "victim");
|
||||
var victim = new RemoteActor(_peer, "victim", _peer.B);
|
||||
|
||||
var result = await Deliver(mallory, $"/peasants/{alice.UserName}/mouth", DirectCreate(mallory, alice.Uri, attributedTo: victim.Id));
|
||||
|
||||
Assert.Equal(400, result.StatusCode);
|
||||
Assert.False(await DB.Default.Find<Post>().Match(p => p.ActorURI == victim.Id).ExecuteAnyAsync(token));
|
||||
|
||||
// a colleague on mallory's own server is that server's to vouch for: believed only as the server has it, and
|
||||
// it has no such note
|
||||
var colleague = new RemoteActor(_peer, "colleague");
|
||||
result = await Deliver(mallory, $"/peasants/{alice.UserName}/mouth", DirectCreate(mallory, alice.Uri, attributedTo: colleague.Id));
|
||||
Assert.Equal(202, result.StatusCode);
|
||||
Assert.False(await DB.Default.Find<Post>().Match(p => p.ActorURI == colleague.Id).ExecuteAnyAsync(token));
|
||||
}
|
||||
|
||||
[Fact]
|
||||
|
||||
Reference in new issue
Block a user