GoToSocial's interaction policies are honoured
A remote post's canReply, canLike and canAnnounce (with the older always and approvalRequired) are kept beside canQuote and judged for each persona: let in at once when the rule names the public, the persona, the author's followers while it follows the author, or the accounts the author follows while the author follows it; asked first when only the manual list names it; refused (422) otherwise. Asked first, a ReplyRequest, LikeRequest or AnnounceRequest with the interaction as its instrument goes to the author alone, and the interaction waits (privapub.approval: pending). The author's Accept brings an authorization, verified on the author's origin as naming the interaction and the post; the reply then goes out with replyAuthorization, the boost with announceAuthorization, the like with likeAuthorization. A Reject leaves the reply ours alone and takes a like or a boost back. As a third party, a reply a policy does not let in at once is kept only with an authorization that verifies. Clients see the rules as GoToSocial's interaction_policy. Checked live against GoToSocial 0.22.1: the scenario's nine new checks pass (64 in all), a reply and a like approved through its interaction requests and a boost refused. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
c65a44ba88
commit
5860b71223
21 files changed
+687
-26
No files matched your search
@@ -194,6 +194,37 @@ until_true 20 '[ "$(gcurl -s -H "$GH" "$G/api/v1/accounts/relationships?id[]=$lo
|
||||
echo "smoke"
|
||||
"$here/../smoke/mastodon-api.sh" "$P" "$PT" >/dev/null 2>&1 && ok "the deploy's Mastodon smoke check passes, signed in" || ko "the Mastodon smoke check fails"
|
||||
|
||||
echo "interaction policies"
|
||||
# gtsuser's post asks before anyone but its author replies or likes, and lets nobody else boost it: PrivaPub shows the
|
||||
# policy, refuses the boost, and sends the reply and the like as requests, which go out for real once approved
|
||||
run_id=$(date +%s)
|
||||
gp=$(gcurl -s -X POST -H "$GH" -H 'Content-Type: application/json' "$G/api/v1/statuses" -d '{"status":"ask before you answer '"$run_id"'","visibility":"public",
|
||||
"interaction_policy":{"can_reply":{"automatic_approval":["author"],"manual_approval":["public"]},
|
||||
"can_favourite":{"automatic_approval":["author"],"manual_approval":["public"]},"can_reblog":{"automatic_approval":["author"],"manual_approval":[]}}}')
|
||||
gp_id=$(echo "$gp" | j "print(d['id'])")
|
||||
gp_on_pp_of() { curl -s -H "$PH" "$P/api/v1/timelines/home?limit=40" | j "print(next((s['id'] for s in d if 'ask before you answer $run_id' in s['content']), ''))"; }
|
||||
until_true 30 '[ -n "$(gp_on_pp_of)" ]' && ok "gtsuser's post with an interaction policy arrives" || ko "the post with a policy never arrived"
|
||||
gp_on_pp=$(gp_on_pp_of)
|
||||
[ "$(curl -s -H "$PH" "$P/api/v1/statuses/$gp_on_pp" | j "p = d.get('interaction_policy') or {}; print(p.get('can_reply', {}).get('manual_approval'), p.get('can_reblog', {}).get('automatic_approval'))")" = "['public'] ['author']" ] \
|
||||
&& ok "PrivaPub shows its policy as GoToSocial states it" || ko "the post's interaction policy is not shown"
|
||||
[ "$(curl -s -o /dev/null -w '%{http_code}' -X POST -H "$PH" "$P/api/v1/statuses/$gp_on_pp/reblog")" = "422" ] \
|
||||
&& ok "a boost its policy shuts out is refused" || ko "PrivaPub boosted a post whose policy shuts boosts out"
|
||||
asked=$(curl -s -X POST -H "$PH" "$P/api/v1/statuses" -d "status=@gtsuser@gts.test may I answer $run_id?&in_reply_to_id=$gp_on_pp&visibility=public")
|
||||
asked_id=$(echo "$asked" | j "print(d['id'])")
|
||||
[ "$(echo "$asked" | j "print((d.get('privapub') or {}).get('approval'))")" = "pending" ] && ok "alice's reply waits for gtsuser's approval" || ko "the reply was not held for approval"
|
||||
request_of() { gcurl -s -H "$GH" "$G/api/v1/interaction_requests?$1=true" | j "print(next((r['id'] for r in d if r['status']['id'] == '$gp_id' and r['type'] == '$2'), ''))"; }
|
||||
until_true 30 '[ -n "$(request_of replies reply)" ]' && ok "it reaches gtsuser as a reply request" || ko "no reply request on GoToSocial"
|
||||
gcurl -s -o /dev/null -X POST -H "$GH" "$G/api/v1/interaction_requests/$(request_of replies reply)/authorize"
|
||||
until_true 30 '[ "$(curl -s -H "$PH" "$P/api/v1/statuses/$asked_id" | j "print((d.get(\"privapub\") or {}).get(\"approval\"))")" = "None" ]' \
|
||||
&& ok "gtsuser's approval reaches PrivaPub" || ko "the approval never reached PrivaPub"
|
||||
until_true 30 'gcurl -s -H "$GH" "$G/api/v1/statuses/$gp_id/context" | grep -q "may I answer $run_id"' \
|
||||
&& ok "the approved reply threads under gtsuser's post" || ko "the approved reply is missing under gtsuser's post"
|
||||
curl -s -o /dev/null -X POST -H "$PH" "$P/api/v1/statuses/$gp_on_pp/favourite"
|
||||
until_true 30 '[ -n "$(request_of favourites favourite)" ]' && ok "alice's like reaches gtsuser as a like request" || ko "no like request on GoToSocial"
|
||||
gcurl -s -o /dev/null -X POST -H "$GH" "$G/api/v1/interaction_requests/$(request_of favourites favourite)/authorize"
|
||||
until_true 30 '[ "$(gcurl -s -H "$GH" "$G/api/v1/statuses/$gp_id" | j "print(d[\"favourites_count\"])")" = "1" ]' \
|
||||
&& ok "the approved like counts on GoToSocial" || ko "the approved like does not count"
|
||||
|
||||
echo "unfollow"
|
||||
curl -s -o /dev/null -X POST -H "$PH" $P/api/v1/accounts/$gts_on_pp/unfollow
|
||||
until_true 20 '[ "$(gcurl -s -H "$GH" "$G/api/v1/accounts/relationships?id[]=$alice_on_gts" | j "print(d[0][\"followed_by\"])")" = "False" ]' && ok "alice's unfollow reaches GoToSocial" || ko "unfollow not applied"
|
||||
|
||||
Reference in new issue
Block a user