Persona and group ids say which day, nothing more

An ObjectId carries its creation second and a per-process counter, so two
avatars made one after the other by the same login got ids a few counts
apart: a link between personas that every Mastodon client would have
seen. Avatar and Group now generate ids from the UTC day plus eight random
bytes (still valid ObjectIds), and a remote post's id is made from its
published time with a random tail, so posts page in the order they were
written rather than the order they arrived.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 11:25:48 +02:00
1 parent e6a362c0b8
commit 5a13597c00
5 files changed
+70

No files matched your search

@@ -5,6 +5,7 @@ using PrivaPub.Federation.Actors;
using PrivaPub.Federation.Moderation;
using PrivaPub.Federation.Objects;
using PrivaPub.Federation.Outbox;
using PrivaPub.Infrastructure.Ids;
using PrivaPub.Federation.Rendering;
using PrivaPub.Models.Federation;
using PrivaPub.Models.Group;
@@ -113,6 +114,7 @@ namespace PrivaPub.Federation.Inbox.Handlers
var post = new PostEntity
{
ID = PrivacyIds.At(note.Published),
ObjectURI = note.Id,
ActivityURI = Id(activity),
ActorURI = author.ActorURI,
+20
View File
@@ -0,0 +1,20 @@
using System.Buffers.Binary;
using System.Security.Cryptography;
namespace PrivaPub.Infrastructure.Ids
{
public static class PrivacyIds
{
public static string ForDay(DateTime when) => At(DateTime.SpecifyKind(when, DateTimeKind.Utc).Date);
public static string At(DateTime when)
{
var seconds = Math.Clamp(new DateTimeOffset(DateTime.SpecifyKind(when, DateTimeKind.Utc)).ToUnixTimeSeconds(), 0,
DateTimeOffset.UtcNow.AddDays(1).ToUnixTimeSeconds());
Span<byte> bytes = stackalloc byte[12];
BinaryPrimitives.WriteInt32BigEndian(bytes, (int)seconds);
RandomNumberGenerator.Fill(bytes[4..]);
return Convert.ToHexStringLower(bytes);
}
}
}
+4
View File
@@ -1,5 +1,7 @@
using MongoDB.Entities;
using PrivaPub.Infrastructure.Ids;
namespace PrivaPub.Models.Group
{
public class Group : Entity
@@ -29,6 +31,8 @@ namespace PrivaPub.Models.Group
public DateTime CreationDate { get; set; } = DateTime.UtcNow;
public DateTime UpdatedAt { get; set; } = DateTime.UtcNow;
public DateTime? DeletionAt { get; set; }
public override object GenerateNewID() => PrivacyIds.ForDay(DateTime.UtcNow);
}
public class GroupMember
+4
View File
@@ -1,5 +1,7 @@
using MongoDB.Entities;
using PrivaPub.Infrastructure.Ids;
namespace PrivaPub.Models.User
{
public class Avatar : Entity
@@ -34,6 +36,8 @@ namespace PrivaPub.Models.User
public DateTime? SuspendedAt { get; set; }
public DateTime? BannedAt { get; set; }
public DateTime? DeletionAt { get; set; }
public override object GenerateNewID() => PrivacyIds.ForDay(DateTime.UtcNow);
}
public class ForeignAvatar : Entity