snac2 joins the pasture, built from its tag (images/snac2); scenarios/snac.sh drives its Mastodon API and reads its own files, since its timelines lag behind what it has taken in: follows, posts, replies, likes, boosts, a poll, edits, deletions, direct messages, the unfollow and statistics, 27 checks, with no change to PrivaPub. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
41 lines
2.8 KiB
Bash
41 lines
2.8 KiB
Bash
# snac2 2.95 (grunfink): a small ActivityPub server in C that keeps everything in files, with a Mastodon API. Built from
|
|
# its tag (images/snac2), as snac.test; its libcurl reads the system's roots, over which the pasture's bundle goes. Its
|
|
# data directory is made by `snac init` and snacuser by `snac adduser`; the API token comes from its own login form
|
|
# (/oauth/x-snac-login) and a code grant.
|
|
SNAC_IMAGE=${SNAC_IMAGE:-localhost/pasture-snac2:2.95}
|
|
|
|
snac_up() {
|
|
podman image exists "$SNAC_IMAGE" || podman build -q -t "$SNAC_IMAGE" "$here/images/snac2" >/dev/null
|
|
local st="$here/.state/snac"
|
|
mkdir -p "$st"
|
|
podman volume exists pasture-snac || podman volume create --label pasture=1 pasture-snac >/dev/null
|
|
if ! podman run --rm -v pasture-snac:/data $SNAC_IMAGE test -e /data/data/server.json; then
|
|
printf '0.0.0.0\n8001\nsnac.test\n\n\n' | podman run --rm -i -v pasture-snac:/data $SNAC_IMAGE snac init /data/data >/dev/null
|
|
podman run --rm -v pasture-snac:/data $SNAC_IMAGE snac adduser /data/data snacuser </dev/null >/dev/null 2>&1
|
|
fi
|
|
# a password the pasture knows ("New password for user snacuser is ...")
|
|
[ -s "$st/password" ] || podman run --rm -v pasture-snac:/data $SNAC_IMAGE snac resetpwd /data/data snacuser 2>&1 </dev/null \
|
|
| sed -n 's/.* is \([^ ]*\)$/\1/p' | head -1 > "$st/password"
|
|
podman run -d --replace --name pasture-snac --label pasture=1 --network $net -v pasture-snac:/data \
|
|
-v "$ca/bundle.pem:/etc/ssl/certs/ca-certificates.crt:z,ro" $SNAC_IMAGE snac httpd /data/data >/dev/null
|
|
for _ in $(seq 1 30); do
|
|
site snac.test -s -o /dev/null -w '%{http_code}' https://snac.test:6443/.well-known/nodeinfo 2>/dev/null | grep -q 200 && break
|
|
sleep 1
|
|
done
|
|
snac_token > "$st/snacuser.token"
|
|
echo "snac: https://snac.test:6443"
|
|
}
|
|
|
|
# snac_token: an API token for snacuser, through an app, its login form and a code grant
|
|
snac_token() {
|
|
local app id secret code
|
|
app=$(site snac.test -s -X POST https://snac.test:6443/api/v1/apps -d 'client_name=pasture&redirect_uris=urn:ietf:wg:oauth:2.0:oob&scopes=read+write+follow')
|
|
id=$(echo "$app" | python3 -c 'import json, sys; print(json.load(sys.stdin)["client_id"])')
|
|
secret=$(echo "$app" | python3 -c 'import json, sys; print(json.load(sys.stdin)["client_secret"])')
|
|
code=$(site snac.test -s -X POST https://snac.test:6443/oauth/x-snac-login --data-urlencode login=snacuser \
|
|
--data-urlencode "passwd=$(cat "$here/.state/snac/password")" --data-urlencode redir=urn:ietf:wg:oauth:2.0:oob --data-urlencode "cid=$id")
|
|
site snac.test -s -X POST https://snac.test:6443/oauth/token --data-urlencode grant_type=authorization_code --data-urlencode "code=$code" \
|
|
--data-urlencode "client_id=$id" --data-urlencode "client_secret=$secret" --data-urlencode redirect_uri=urn:ietf:wg:oauth:2.0:oob \
|
|
| python3 -c 'import json, sys; print(json.load(sys.stdin).get("access_token", ""))'
|
|
}
|