Interop research: every major platform's wire shapes, gotchas, and what PrivaPub still drops
Build / Build (push) Successful in 1m22s

docs/INTEROP.md collects five research passes from 2026-10-01: Mastodon 4.7 and GoToSocial 0.22, the Misskey and
Pleroma families, the threadiverse (Lemmy 0.19/1.0, PieFed, Mbin, NodeBB), media and long-form (PeerTube, Loops,
Pixelfed, WordPress, Ghost, events, audio, books, Threads, Flipboard, Bridgy Fed), and cross-cutting FEPs and
signatures. Each claim was checked against source code or live fetches, with dates and versions.

It is checked against our own code: what is already right, three cheap things that are wrong today (summary read as a
CW on every type, unchecked usernames, an undefined context term), what the rich client needs kept (a post kind with
typed payloads, raw capture and provenance for the details view), and the six privacy choices the owner has to make.

The roadmap's P5 becomes P5 to P8, ordered by that evidence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 14:01:57 +02:00
1 parent 8f4d6cbdf9
commit 829eae3ccf
4 files changed
+870 -16

No files matched your search

+100 -13
View File
@@ -10,7 +10,10 @@ Written 2026-10-01 from the original 2023 code, the decePubClient UI, a federati
- [x] P2 Mastodon client API: v1.4.0, deployed 2026-10-01; OAuth and the anonymous API verified on production, the signed-in API verified locally (no real-client login on production yet)
- [x] P3 Social features: v1.5.0, deployed 2026-10-01; media, proxy, blocks, mutes, bookmarks, pins and reports verified by tests and locally (no upload on production yet)
- [x] P4 Groups and privacy features: v1.6.0, deployed 2026-10-01; communities, circles and local-only located posts verified by tests. v1.6.1 adds the pasture (`tools/pasture/`): live interop with GoToSocial 0.22.1 passes all 25 checks, three runs in a row. Lemmy and a live Mastodon circle member are not run yet; the pasture has GoToSocial only
- [ ] P5 FEPs and polish
- [ ] P5 Lose nothing: wire tolerance, full objects, raw capture (see `docs/INTEROP.md`)
- [ ] P6 Emoji, polls, quotes, reactions, cards, players
- [ ] P7 Threads, communities, moderation, the social graph
- [ ] P8 Signatures, discovery, the long tail
## Intent
@@ -386,28 +389,112 @@ The first refactor commit is a pure move with namespaces only. Logic changes fol
- **Persona hardening:** optionally re-key existing avatar ids; an optional `SecureMode` (signed GETs required); no
suggestions or directories that could relate sibling avatars.
### P5 FEPs and polish (ongoing)
- **FEP-8fcf:** followers synchronisation.
- **FEP-5feb:** honour remote `indexable` in search.
- **FEP-7628:** Move in both directions, plus editing `alsoKnownAs`.
- **FEP-044f:** quotes and `interactionPolicy`.
- **RFC 9421:** inbound verification with NSign, plus Content-Digest.
- **Mastodon API extras:** polls, the streaming WebSocket (nginx Upgrade headers), Web Push (VAPID), and grouped
notifications v2, after which the advertised version moves to 4.3.
### P5 and beyond: rich content and the rest of the fediverse
Rewritten on 2026-10-01 from the research in `docs/INTEROP.md`, which holds the per-platform evidence and the
priorities. The goal is a future client that shows and links every kind of fediverse content in one place, with a
details view of where each object came from. So the server keeps everything it receives: typed where it understands
it, raw where it doesn't.
#### P5 Lose nothing (wire tolerance and full objects)
- **Cheap fixes that are wrong today:**
- `summary` is a content warning only on a `Note`, or when `sensitive` is set; elsewhere it is an excerpt or
description (INTEROP W2).
- Persona and group usernames must match Mastodon's and Misskey's pattern.
- Define every term we emit in our JSON-LD context.
- `Vary: Accept`; every activity id dereferences.
- **Parsing every shape:**
- `url`, `icon`, `image`, `attachment` and `attributedTo` as a value, an object or an array (W1).
- A Markdown `content` and `source` (W3).
- Inferring a missing `mediaType` (W4).
- Every thumbnail location (W5).
- Language from `@context` (W11); alt text from `summary` (W12).
- A null `id`, a 200 `Tombstone`, a `Delete` before its `Create` (W9, W13).
- **`Post.Kind`** plus typed payloads for article, video, audio, event, link, review and thread (INTEROP §4.1). The
Mastodon API view of each kind: content, a card made from the object without fetching, attachments.
- **Raw capture for the details view:** the object as received, how it arrived, the signature scheme and key, received
versus `published`, the extensions detected, and the origin's software (§4.3). Exposed at
`/api/privapub/v1/statuses/:id/provenance` and `/api/privapub/v1/instances/:host`.
- **Routing by object type:**
- `Accept`/`Reject`/`TentativeAccept` routed by what their object is (W6).
- `ChatMessage` in as a direct message.
- `Dislike` and votes recorded in a ledger.
- A `Join` answered with `Ignore` until RSVP exists.
- Friendica's thread-`Follow` refused without an error.
- **Delivery:** honour 503 with `Retry-After`; answer 503 ourselves when a key fetch fails temporarily.
#### P6 What people see: emoji, polls, quotes, reactions, cards, players
- **Custom emoji** on posts, names, fields and poll options, proxied.
- **Polls** in and out, with the Misskey, Pleroma and PieFed vote shapes. A count refresh is never an edit.
- **Quotes (FEP-044f):**
- read every key; verify `QuoteAuthorization` on all of its fields; handle revocation;
- be quotable: `canQuote`, answer `QuoteRequest`, serve and revoke stamps;
- then advertise `api_versions.mastodon ≥ 7` (4.5.0).
- **Emoji reactions** in all three inbound forms, plus outbound `EmojiReact`, exposed as `emoji_reactions`.
- **Link cards:**
- from the object, or from FEP-8967 `preview`, without fetching;
- fetching the page itself is the owner's decision (INTEROP §6.1).
- **Media:**
- video playback through the proxy (Range requests, HLS playlist rewriting, the poster), with a `video` card;
- audio attachments;
- an article reader view;
- JPEG/PNG renditions kept for Pixelfed.
#### P7 Threads, communities and the social graph
- **Thread backfill:**
- read in order: `contextHistory`, then `context` (paged, with ETag), then `replies`;
- group by the root post;
- publish our own `context` and a paged `replies`.
- **Lemmy, PieFed and Mbin:**
- the moderation set: removals, locks, bans, featured, moderators, `Warn`, `Resolve`;
- votes in and out; link posts; flairs; `Feed` actors; community polls; post `Move`;
- the outbound shape Lemmy requires;
- communities we host announce to the author's own instance too;
- Flags from a `Service`-typed reporter actor.
- **GoToSocial interaction policies:** stored and shown; send `ReplyRequest`/`LikeRequest` where approval is
needed; handle `Accept{result}`.
- **Accounts and follows:**
- inbound `Move` with Mastodon's checks;
- re-run WebFinger on a rename;
- inbound `Block`, plus `Add`/`Remove` of pins;
- FEP-8fcf followers sync;
- `indexable`/`discoverable`/`searchableBy`;
- edit history from `formerRepresentations`;
- PeerTube reply rules and `ApproveReply`.
- **Events:** structured RSVP (`Join`/`Leave` with stable ids).
#### P8 Signatures, discovery and the long tail
- **Signatures:**
- RFC 9421 inbound (RSA and Ed25519, Content-Digest);
- outbound double-knock, remembered per host;
- `publicKey` arrays and FEP-521a Multikey;
- FEP-8b32 proof verification;
- `hs2019` with SHA-512.
- **Discovery:**
- a relay client for both relay styles;
- instance actor discovery (FEP-d556, FEP-2677);
- `implements` (FEP-844e).
- **Mastodon API:** streaming WebSocket, Web Push, grouped notifications. Then advertise an honest version.
- **Backfill:** an author's outbox after following them.
- **Later:** FEP-521a, FEP-8b32, FEP-e232, relays.
- **Long tail:**
- MFM rendering data;
- Misskey actor extras;
- book reviews (`relatedWith`, `rating`);
- Funkwhale and Castopod metadata;
- Pixelfed `place` (display only, never re-federated);
- Bluesky bridging per persona.
### Cut or deferred (deliberately)
- **Cut:**
- Link-preview cards: an SSRF and privacy risk.
- Link-preview cards *fetched from the linked page* by default. Cards built from the object, or from FEP-8967
`preview` data, are in P6; fetching the page is an owner decision (INTEROP §6.1).
- Translation, trends, directory and lists (filters stay as stubs).
- Scheduled posts.
- The Mastodon admin API: moderation stays on `/clientapi`.
- `POST /api/v1/accounts` registration: avatars are created through `/clientapi`.
- Local custom emoji.
- S3 storage.
- JSON-LD and LD-signature processing.
- Outbound RFC 9421.
- JSON-LD and LD-signature processing. FEP-8b32 proofs need neither (JCS), so they are in P8.
- **Deferred:** video transcoding (remux only for now).
- **Out of scope:** moving decePubClient onto the Mastodon API.