GoToSocial's interaction policies are honoured
A remote post's canReply, canLike and canAnnounce (with the older always and approvalRequired) are kept beside canQuote and judged for each persona: let in at once when the rule names the public, the persona, the author's followers while it follows the author, or the accounts the author follows while the author follows it; asked first when only the manual list names it; refused (422) otherwise. Asked first, a ReplyRequest, LikeRequest or AnnounceRequest with the interaction as its instrument goes to the author alone, and the interaction waits (privapub.approval: pending). The author's Accept brings an authorization, verified on the author's origin as naming the interaction and the post; the reply then goes out with replyAuthorization, the boost with announceAuthorization, the like with likeAuthorization. A Reject leaves the reply ours alone and takes a like or a boost back. As a third party, a reply a policy does not let in at once is kept only with an authorization that verifies. Clients see the rules as GoToSocial's interaction_policy. Checked live against GoToSocial 0.22.1: the scenario's nine new checks pass (64 in all), a reply and a like approved through its interaction requests and a boost refused. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
c65a44ba88
commit
5860b71223
21 files changed
+687
-26
No files matched your search
@@ -17,12 +17,14 @@ namespace PrivaPub.Federation.Inbox.Handlers
|
||||
readonly DbEntities _dbEntities;
|
||||
readonly ILocalActorService _localActors;
|
||||
readonly IQuoteService _quotes;
|
||||
readonly IInteractionApprovals _approvals;
|
||||
|
||||
public AcceptHandler(DbEntities dbEntities, ILocalActorService localActors, IQuoteService quotes)
|
||||
public AcceptHandler(DbEntities dbEntities, ILocalActorService localActors, IQuoteService quotes, IInteractionApprovals approvals = default)
|
||||
{
|
||||
_dbEntities = dbEntities;
|
||||
_localActors = localActors;
|
||||
_quotes = quotes;
|
||||
_approvals = approvals;
|
||||
}
|
||||
|
||||
public virtual string Type => "Accept";
|
||||
@@ -34,6 +36,11 @@ namespace PrivaPub.Federation.Inbox.Handlers
|
||||
Arrival.Accept("quote-answer");
|
||||
return;
|
||||
}
|
||||
if (_approvals != default && await _approvals.Answered(activity, actor, accepted: Type == "Accept", token))
|
||||
{
|
||||
Arrival.Accept("interaction-answer");
|
||||
return;
|
||||
}
|
||||
var following = await FindFollowing(activity["object"], actor, _dbEntities, _localActors, token);
|
||||
if (following == default)
|
||||
{
|
||||
@@ -72,7 +79,8 @@ namespace PrivaPub.Federation.Inbox.Handlers
|
||||
|
||||
public class RejectHandler : AcceptHandler
|
||||
{
|
||||
public RejectHandler(DbEntities dbEntities, ILocalActorService localActors, IQuoteService quotes) : base(dbEntities, localActors, quotes)
|
||||
public RejectHandler(DbEntities dbEntities, ILocalActorService localActors, IQuoteService quotes, IInteractionApprovals approvals = default)
|
||||
: base(dbEntities, localActors, quotes, approvals)
|
||||
{
|
||||
}
|
||||
|
||||
|
||||
@@ -40,10 +40,13 @@ namespace PrivaPub.Federation.Inbox.Handlers
|
||||
readonly IPollService _polls;
|
||||
readonly ILinkPreviews _previews;
|
||||
readonly IQuoteService _quotes;
|
||||
readonly IInteractionApprovals _approvals;
|
||||
|
||||
public CreateHandler(DbEntities dbEntities, ILocalActorService localActors, IRemoteActorService remoteActors, IDeliveryService delivery,
|
||||
IDomainBlocks domainBlocks, IFanout fanout, IRemotePosts remotePosts, IGroupDistributor groups, IObjectRecords records, IPollService polls, ILinkPreviews previews, IQuoteService quotes)
|
||||
IDomainBlocks domainBlocks, IFanout fanout, IRemotePosts remotePosts, IGroupDistributor groups, IObjectRecords records, IPollService polls, ILinkPreviews previews, IQuoteService quotes,
|
||||
IInteractionApprovals approvals = default)
|
||||
{
|
||||
_approvals = approvals;
|
||||
_quotes = quotes;
|
||||
_previews = previews;
|
||||
_records = records;
|
||||
@@ -141,6 +144,12 @@ namespace PrivaPub.Federation.Inbox.Handlers
|
||||
var parent = string.IsNullOrEmpty(note.InReplyTo)
|
||||
? default
|
||||
: await _dbEntities.Posts.Match(p => p.ObjectURI == note.InReplyTo && !p.DeletedAt.HasValue).ExecuteFirstAsync(token);
|
||||
// a reply its parent's author has not let in (GoToSocial's canReply), which a third party must not show
|
||||
if (_approvals != default && parent != default && !await _approvals.MayReply(note, author, parent, token))
|
||||
{
|
||||
Arrival.Drop("reply-not-authorized");
|
||||
return;
|
||||
}
|
||||
var circle = localTargets.FirstOrDefault(t => t is { Kind: LocalActorKind.Group, IsCircle: true });
|
||||
if (circle != default)
|
||||
{
|
||||
|
||||
@@ -30,6 +30,9 @@ namespace PrivaPub.Federation.Inbox
|
||||
{
|
||||
post.Poll = note.Poll ?? post.Poll;
|
||||
post.QuotePolicy = note.QuotePolicy;
|
||||
post.ReplyPolicy = note.ReplyPolicy;
|
||||
post.LikePolicy = note.LikePolicy;
|
||||
post.AnnouncePolicy = note.AnnouncePolicy;
|
||||
post.Video = note.Video ?? post.Video;
|
||||
post.Audio = note.Audio ?? post.Audio;
|
||||
post.Event = note.Event ?? post.Event;
|
||||
|
||||
@@ -107,6 +107,9 @@ namespace PrivaPub.Federation.Inbox
|
||||
Source = note.Source,
|
||||
Poll = note.Poll,
|
||||
QuotePolicy = note.QuotePolicy,
|
||||
ReplyPolicy = note.ReplyPolicy,
|
||||
LikePolicy = note.LikePolicy,
|
||||
AnnouncePolicy = note.AnnouncePolicy,
|
||||
Emojis = note.Emojis.ToList(),
|
||||
CoverURL = note.CoverURL,
|
||||
Link = note.Link,
|
||||
|
||||
Reference in new issue
Block a user