From 7ff3a61e7535f4c0a88153dd7e69ff0859bcef2f Mon Sep 17 00:00:00 2001 From: thepra Date: Thu, 1 Oct 2026 11:40:02 +0200 Subject: [PATCH] FEDERATION.md and CLAUDE.md describe follows, likes, boosts and timelines Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB --- CLAUDE.md | 14 ++++++++++---- FEDERATION.md | 13 +++++++++---- 2 files changed, 19 insertions(+), 8 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 79024e2..95cd944 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -81,11 +81,14 @@ PrivaPub/ ASP.NET Core Web API, net10.0 Objects/ Origin, ActivityJson, NoteParser, Addressing, ContentSanitizer Moderation/ DomainBlocks (suspend / silence / reject media) Signing/ HttpSignatures (draft-cavage sign/verify) - Inbox/ InboxReceiver (verify, queue, 202) → InboxProcessor (job) → Handlers/{Follow,Undo,Create,Update,Delete} - Outbox/ DeliveryService (queues jobs) + DeliveryJobHandler + Inbox/ InboxReceiver (verify, queue, 202) → InboxProcessor (job) → Handlers/{Follow,Accept,Reject, + Undo,Create,Update,Delete,Like,Announce}; RemotePosts (build, fetch parents, FetchAncestors) + Outbox/ OutboxPublisher (who a post goes to), DeliveryService (queues jobs) + DeliveryJobHandler Rendering/ ActivityPubRenderer (Mastodon @context, actors, notes, collections) Domain/ Content/ ContentRenderer (Markdown or plain text → HTML with h-card mentions and hashtags) + Social/ FollowService (local in-process, remote Follow/Accept), Notifications + Timelines/ Fanout (TimelineEntry rows, Mastodon's home rules), TimelineService Privacy/ VisibilityPolicy (IsPublic expression, CanSee) Web/Pages/ Razor: /@{user}, /@{user}/{id} (public posts only, strict CSP, noindex) Services/ RootUsersService, GroupUsersService, PostsService, AppConfigurationService, … @@ -162,8 +165,11 @@ cd /var/www/privapub.thepra.dev && sudo -u www-data ASPNETCORE_ENVIRONMENT=Produ leased, retried on Mastodon's curve, at most two per host, paused per host by `RemoteInstance`. The inbox answers 202 once it has verified and queued; a handler must be idempotent (unique `ObjectURI`, job `DedupeKey`). 11. **Every "may anyone see this" goes through `VisibilityPolicy.IsPublic`;** a persona-specific read uses `CanSee`. -12. **Remote content is stored only when someone here asked for it:** a local persona addressed or mentioned, a reply to - a local post, or a community the author follows. Followers-only is detected by the author's stored `followers` URL. +12. **Remote content is stored only when someone here asked for it:** a persona follows the author, is addressed or + mentioned, it replies to a local post, or it is addressed to a community the author follows; a public parent is + fetched as context. Followers-only is detected by the author's stored `followers` URL. +13. **Home timelines are written, not computed:** every stored or created post goes through `Fanout.Distribute`, and + every delete removes its `TimelineEntry` rows. Local deletes are soft (content cleared, 410 Tombstone). ## Privacy invariants diff --git a/FEDERATION.md b/FEDERATION.md index bbb5bdf..002b044 100644 --- a/FEDERATION.md +++ b/FEDERATION.md @@ -59,13 +59,17 @@ Received: | Activity | Effect | |---|---| | `Follow` | follows an avatar or community; `Accept` is sent unless the community approves members by hand | -| `Undo{Follow}` | unfollows | -| `Create{Note, Article, Page, Question, …}` | stored when it addresses or mentions a local avatar, replies to a local post, or is addressed to a community the author follows | +| `Accept{Follow}`, `Reject{Follow}` | completes or ends a follow an avatar requested | +| `Undo{Follow, Like, Announce}` | reverses it | +| `Create{Note, Article, Page, Question, …}` | stored when a local avatar follows the author, is addressed or mentioned, when it replies to a local post, or when it is addressed to a community the author follows; a public parent is fetched to complete the thread | | `Update{Note}` | replaces the content; the previous version is kept | | `Update{Person}` | refetches the actor | +| `Like` | counted and notified, on posts the liker could see | +| `Announce` | counted and notified for local posts; shown to followers of the announcer, with the original refetched from its origin | | `Delete` | deletes the object, or the actor and its follows | -Sent: `Create{Note}`, `Delete{Tombstone}`, `Accept{Follow}`, `Announce` (communities). +Sent: `Follow`, `Undo{Follow}`, `Create{Note}`, `Update{Note}`, `Update{Person}`, `Delete{Tombstone}`, `Accept{Follow}`, +`Announce` (communities). A deleted post answers 410 with a `Tombstone`. A `Create`'s `Note` carries Mastodon's `content`, `contentMap`, `summary` and `sensitive`, plus `Mention` and `Hashtag` tags. A post's title becomes `name` and is also the first, bold line of `content`, because Mastodon does not show @@ -90,6 +94,7 @@ followers-only posts are recognised by the author's own `followers` collection. ## Known limitations -- Likes, boosts, follow requests to remote accounts, media uploads and polls are not implemented yet. +- Avatars cannot send likes or boosts yet (that arrives with the Mastodon client API), and media uploads and polls are not + implemented. - Collections expose counts, not members. - Only `rsa-sha256`-style keys are verified. RFC 9421 signatures are planned.