Reports reach Lemmy's moderators, from an anonymous reporter
Lemmy takes a report only from a person or a service, about one post or comment, addressed to its community, and it answered PrivaPub's Flag (the instance actor's, an Application, with no `to` and the account and posts as its object) 400. A report of a post or comment in a community on a server whose NodeInfo names Lemmy now leaves from `privapub_reports`, a Service with its own key that names nobody: one Flag per post, `to` the community (its own audience, else its thread's), with the persona's words, or the category, in `summary` and `content`, sent to the community's inbox. This is the second exception to "a server's software is for display" (owner decision 2026-10-06, `ReportService.ServiceReportTakers`). Every other server keeps the instance actor's report. An account alone is not reported to Lemmy, which takes no such report, and `forwarded` now says whether anything left. The reporter is read unsigned in SecureMode and answers WebFinger like the instance actor. Nobody follows or mentions it, the Mastodon API has no account for it, and a migration reserves its name. Checked live: Lemmy 1.0 and 0.19 keep the reports of a thread and of a comment, with alice's words, from "Reports from privapub.test", and none names her (69 checks). A sweep of every scenario with this and the next commit: 876 checks pass; Ghost's Network feed listed alice's post too late once, and Ghost passes alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
10ff4b3d2a
commit
f66c280b0b
33 files changed
+561
-46
No files matched your search
@@ -21,6 +21,9 @@ Its defining idea: **one private login owns several public personas.**
|
||||
becoming two kinds: a public **community** (FEP-1b12, Lemmy-compatible) and a private, invitation-only **circle**.
|
||||
- **`DmGroup` is a direct-message conversation.**
|
||||
- **`privapub` is the instance actor** (type Application). It signs fetches no persona should be tied to.
|
||||
- **`privapub_reports` is the reporter** (type Service, `LocalActorKind.Reporter`). It carries reports to Lemmy, which
|
||||
takes none from an Application, and names nobody. Both are server actors (`LocalActor.IsServerActor`): never followed,
|
||||
mentioned or shown as accounts.
|
||||
|
||||
Privacy features in the model:
|
||||
- location-ranged posts (`Post.Location`, `RangeKm`), to become local-only and never federated;
|
||||
@@ -245,10 +248,12 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
16. **An `Accept` or `Reject` is routed by what it answers:** our Follow (`FollowService`, any `-again-N` resend), an
|
||||
interaction request (`InteractionApprovals`, with the author's authorization read back from its origin) or a
|
||||
persona's `Join` (`Participations`, by its `/grunts/join-<id>` id), each only from the origin of what it answers.
|
||||
17. **A server's software is for display, with one exception** (owner decision 2026-10-05): a direct message to one
|
||||
account on a server whose NodeInfo names Lemmy before 1.0 or Mbin goes as a `ChatMessage`
|
||||
(`StatusService.TakesOnlyChatMessages`), as one to an account that writes to us that way does. Nothing else may
|
||||
branch on `RemoteInstance.Software`.
|
||||
17. **A server's software is for display, with two exceptions** (owner decisions 2026-10-05 and 2026-10-06): a direct
|
||||
message to one account on a server whose NodeInfo names Lemmy before 1.0 or Mbin goes as a `ChatMessage`
|
||||
(`StatusService.TakesOnlyChatMessages`), as one to an account that writes to us that way does; and a report of a
|
||||
post in a community on a server whose NodeInfo is in `ReportService.ServiceReportTakers` leaves in Lemmy's shape,
|
||||
from the reporter, one `Flag` per post. A server joins that set only once the pasture shows it keeps such a report
|
||||
with its reason. Nothing else may branch on `RemoteInstance.Software`.
|
||||
|
||||
## Mastodon client API invariants
|
||||
|
||||
@@ -327,7 +332,8 @@ group www-data and reaches the private mongod; `sudo -u www-data` works too.
|
||||
see ids. Never emit `CreatedAt`.
|
||||
- **Per-avatar state stays per avatar:** blocks, mutes, notifications, follows. Nothing may relate sibling avatars.
|
||||
- **Blocks federate** (owner decision, 2026-10-01): a block is sent as `Block` from the blocking avatar, an unblock as
|
||||
`Undo{Block}`. Reports still leave as `Flag` from the instance actor, never from the reporting avatar.
|
||||
`Undo{Block}`. Reports still leave as `Flag` from the server's own actors (the instance actor, or the reporter for
|
||||
Lemmy's communities), never from the reporting avatar.
|
||||
- **What PrivaPub reveals is the owner's call.** Previews, blocks, website authorship, views, bridging and reactions were
|
||||
decided in `docs/ROADMAP.md` ("Owner decisions on what PrivaPub reveals"). Anything new that tells another server
|
||||
something about an avatar gets the same treatment: ask, then record it there.
|
||||
|
||||
Reference in new issue
Block a user