Reports reach Lemmy's moderators, from an anonymous reporter
Lemmy takes a report only from a person or a service, about one post or comment, addressed to its community, and it answered PrivaPub's Flag (the instance actor's, an Application, with no `to` and the account and posts as its object) 400. A report of a post or comment in a community on a server whose NodeInfo names Lemmy now leaves from `privapub_reports`, a Service with its own key that names nobody: one Flag per post, `to` the community (its own audience, else its thread's), with the persona's words, or the category, in `summary` and `content`, sent to the community's inbox. This is the second exception to "a server's software is for display" (owner decision 2026-10-06, `ReportService.ServiceReportTakers`). Every other server keeps the instance actor's report. An account alone is not reported to Lemmy, which takes no such report, and `forwarded` now says whether anything left. The reporter is read unsigned in SecureMode and answers WebFinger like the instance actor. Nobody follows or mentions it, the Mastodon API has no account for it, and a migration reserves its name. Checked live: Lemmy 1.0 and 0.19 keep the reports of a thread and of a comment, with alice's words, from "Reports from privapub.test", and none names her (69 checks). A sweep of every scenario with this and the next commit: 876 checks pass; Ghost's Network feed listed alice's post too late once, and Ghost passes alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
10ff4b3d2a
commit
f66c280b0b
33 files changed
+561
-46
No files matched your search
+6
-3
@@ -275,6 +275,7 @@ and circles (see Owner decisions).
|
||||
|---|---|
|
||||
| May a persona join a remote event? | **Yes.** A persona joins and leaves another server's event (`Join`/`Leave`, sent to the event's organiser only). Its participation is public on that server, as on every platform with events. Events that take participants only by invitation or on another site are refused before anything is sent. |
|
||||
| A first private message to Lemmy 0.19 or Mbin (G-0008) | **Decide by the server's software.** Lemmy before 1.0 and Mbin take a private message only as a `ChatMessage` and their actors do not say so, so a direct message to one account on a server whose NodeInfo names one of them goes as a `ChatMessage`: the one exception to "a server's software is for display only". |
|
||||
| Reports to Lemmy (2026-10-06) | **In Lemmy's shape, for Lemmy only.** Lemmy takes a report only from a person or a service, about one post or comment, addressed to its community, so a report of a post in a community on a server whose NodeInfo names Lemmy leaves from an anonymous `Service`, `privapub_reports`, one `Flag` per post: the second exception to "a server's software is for display only". PieFed and Mbin, which speak Lemmy's shapes, join only once the pasture shows each keeps such a report with its reason; every other server keeps the instance actor's report. |
|
||||
| An account a persona follows moves | **Move the follow, as Mastodon does.** After a verified `Move` the persona follows the new account (a Follow to its server) and unfollows the old, in the same lists; a mute or a block of the old account carries over. |
|
||||
| Should PrivaPub pass on replies to a persona's posts? | **Yes, "the fediverse is broken without".** A public or unlisted reply that someone on another server writes to a persona's post goes on to the persona's followers, as Mastodon forwards it: the activity as its author signed it, never to the replier's own server, never for a post that is local-only, in a group or not shown to followers. Its edits and deletion follow the same way. |
|
||||
|
||||
@@ -540,8 +541,9 @@ The first refactor commit is a pure move with namespaces only. Logic changes fol
|
||||
tags at `/tattoos`.
|
||||
- **Blocks and mutes:** per avatar. **Block is not federated**: it sends Reject or Undo Follow instead and drops the
|
||||
blocked actor's traffic. Domain blocks per account as well.
|
||||
- **Reports:** inbound Flag becomes a `Report`. Outbound Flag is **sent by the instance actor**, so the reporting
|
||||
persona isn't revealed. Moderator endpoints on `/clientapi`.
|
||||
- **Reports:** inbound Flag becomes a `Report`. Outbound Flag is **sent by the instance actor**, or for a post in a
|
||||
Lemmy community by the reporter `privapub_reports` (2026-10-06), so the reporting persona isn't revealed. Moderator
|
||||
endpoints on `/clientapi`.
|
||||
- **Locked accounts:** the follow-request flow.
|
||||
|
||||
### P4 Groups and privacy features
|
||||
@@ -663,7 +665,8 @@ it, raw where it doesn't.
|
||||
- the outbound shape Lemmy requires;
|
||||
- communities we host announce to the author's own instance too: **done 2026-10-06** (its server's shared inbox,
|
||||
whether anyone there follows the community or not: Lemmy keeps its user's post pending until it is announced back);
|
||||
- Flags from a `Service`-typed reporter actor.
|
||||
- Flags from a `Service`-typed reporter actor: **done 2026-10-06** for Lemmy (owner decision below; `privapub_reports`,
|
||||
one Flag per post `to` its community, checked live on 1.0 and 0.19).
|
||||
- **GoToSocial interaction policies** (**done 2026-10-05**, `InteractionApprovals`): stored and shown as
|
||||
`interaction_policy`; `ReplyRequest`/`LikeRequest`/`AnnounceRequest` where approval is needed; `Accept{result}`
|
||||
verified and carried; replies a policy does not let in kept only with an authorization.
|
||||
|
||||
Reference in new issue
Block a user