A persona's archive: exported in Mastodon's layout, imported without telling anyone
A root exports one of its personas (a job) as Mastodon's account archive, so other servers' importers read it: the actor with its public key only, its own posts and boosts with their media, likes, bookmarks and Mastodon's CSV files, plus PrivaPub's filters, followed hashtags, notification policy, pins, scheduled and located posts; nothing of its root, its siblings, its keys or anyone's token. A ticket link downloads it, for a week. An archive (PrivaPub's or Mastodon's) uploaded in pieces is imported into a persona in a job, the parts the root picks, with progress and a stop. SafeArchive refuses links, escaping paths, duplicates, bombs and oversized items, and reads the outbox one item at a time. Imported posts are delivered to no one, put in no home and notify nobody, yet show on the profile, outbox, hashtags and search; back home a post keeps its id, from another actor it gets one of its date and ImportedFromURI, so importing twice changes nothing. Relationships go through the existing services; located, scheduled and likes only when asked; followers never. tools/pasture/scenarios/persona-archive.sh imports mastouser's real Mastodon archive (156 posts, 24 pictures) into a persona Mastodon follows: Mastodon receives none of it, and a second import changes nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
bdc8be4508
commit
3d7d406834
18 files changed
+2377
-7
No files matched your search
@@ -541,6 +541,28 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
|
||||
Every call checks the administrator against the database, not only the token. nginx streams downloads for an hour and
|
||||
takes upload pieces unbuffered (`deploy/nginx`, applied by `setup.sh`).
|
||||
- **A persona's archive** (`Domain/Portability/`, `PersonaArchiveController` at `/clientapi/persona/{avatarId}/archive`;
|
||||
owner decision 2026-10-07), for the persona's own root only, never a banned one. State per persona in `PersonaArchive`
|
||||
(never in a backup), files in `<backups>/.personas/<avatarId>/`, a week.
|
||||
- **Export** (`ExportArchiveJob`): Mastodon's account-archive layout, so other servers' importers read it: `actor.json`
|
||||
(its public key only), `outbox.json` (its own posts as Creates, addressed as delivered, but circles' and located
|
||||
posts; its boosts as Announces), `media_attachments/files/` (what the attachments' urls name), avatar and header,
|
||||
`likes.json`, `bookmarks.json` and Mastodon's CSV files; then `privapub/`: filters, followed hashtags, the
|
||||
notification policy, pins, scheduled and located posts, `archive.json`. Nothing of its root, its siblings, its keys,
|
||||
anyone's token. Downloaded through a ten-minute ticket in the link's path.
|
||||
- **Import** (`ImportArchiveJob`, the parts the root picks, with progress, stoppable): uploaded in pieces like a backup,
|
||||
read through `SafeArchive`, which refuses links, paths leaving it, names twice, too many or too large files, a file
|
||||
compressed over 100:1, and streams the outbox an item at a time (none over 1 MB). Only the archive actor's own
|
||||
Creates become posts; boosts, direct and circle posts are counted. **Imported posts are delivered to no one**, put in
|
||||
no home and notify nobody (an exception next to located posts), yet show on the profile, the outbox, hashtags and
|
||||
search. Back home (same actor) a post keeps its id and address, and one already here, even deleted, or tombstoned,
|
||||
stays as it is; from another actor it gets an id of its date, its address here and `ImportedFromURI` (unique per
|
||||
persona), so importing twice changes nothing. Replies and self-quotes inside the archive point at their copies; polls
|
||||
come closed without votes; mentions stay links; HTML is sanitized; media go through `MediaService` and the quota.
|
||||
The other parts go through the existing services: follows asked again (never on a blocked server), blocks, mutes,
|
||||
blocked servers, lists (members only if followed), bookmarks (by signed fetch), filters, followed hashtags, the
|
||||
notification policy, pins (no `Add` delivered), the profile (announced as Settings would). Located and scheduled
|
||||
posts (PrivaPub's archives) and likes (each tells its author) only when asked. Followers are never imported.
|
||||
|
||||
## Code style
|
||||
|
||||
|
||||
Reference in new issue
Block a user