Posts reach their audience, edits follow them, deletes leave a tombstone

OutboxPublisher works out who a post goes to, Mastodon's way: followers'
shared inboxes for public, unlisted and followers-only; every mentioned
remote account's own inbox; the recipients only for direct; the parent's
author for a reply; a community's followers for a post in it; nobody for
a circle. Creates, updates and deletes all use it.

- Local posts take a visibility (public, unlisted, followers-only) and a
  spoiler text next to the content-warning flag.
- /clientapi/post/update keeps the previous version as a revision,
  re-renders, and sends Update{Note} with `updated` to the same to/cc.
- Deleting is now soft: the content, title, spoiler, media and revisions
  are cleared, timeline entries removed, the parent's reply count goes
  down, Delete goes to the stored audience, and the object answers 410
  with a Tombstone instead of 404.
- Editing a persona's profile sends Update{Person} to its followers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 11:34:35 +02:00
1 parent 61f6ca0676
commit a76cc34557
10 files changed
+368 -33

No files matched your search

@@ -111,7 +111,7 @@ namespace PrivaPub.Federation.Controllers
{
var (local, post) = await PublicPost(actor, postId, token);
if (post == default)
return NotFound();
return await Tombstone(actor, postId, token) ?? NotFound();
if (WantsHtml())
return Redirect(local.PostHtmlUrl(post.ID));
@@ -159,6 +159,28 @@ namespace PrivaPub.Federation.Controllers
return (local, post);
}
async Task<IActionResult> Tombstone(string actor, string postId, CancellationToken token)
{
var local = await _localActors.FindByUserName(actor, token);
if (local is not { IsFederated: true, Kind: LocalActorKind.Person })
return default;
var deleted = await _dbEntities.Posts
.Match(p => p.ID == postId && p.GroupUserId == local.Id && !p.IsFederatedCopy && p.DeletedAt.HasValue
&& (p.Visibility == PostVisibility.Public || p.Visibility == PostVisibility.Unlisted))
.ExecuteFirstAsync(token);
if (deleted == default)
return default;
var tombstone = new JsonObject
{
["@context"] = ActivityPubRenderer.ActivityStreams,
["id"] = local.PostUri(deleted.ID),
["type"] = "Tombstone",
["formerType"] = "Note",
["deleted"] = ActivityPubRenderer.Timestamp(deleted.DeletedAt.Value)
};
return new ContentResult { Content = tombstone.ToJsonString(), ContentType = ActivityContentType, StatusCode = StatusCodes.Status410Gone };
}
async Task<JsonObject> CreateFor(PostEntity post, LocalActor author, CancellationToken token)
{
var group = string.IsNullOrEmpty(post.GroupId) ? default : await _localActors.FindById(LocalActorKind.Group, post.GroupId, token);