Files
SocialPub/tools/pasture/town/dialects/privapub.py
T
thepraandClaude Opus 5.5 2873344690 The town: a fake community across the pasture, checked for coherence
tools/pasture/town/ (run through tools/pasture/town.sh) seeds a fake
community across every running peer and checks that all of them, and
PrivaPub, agree on what happened:

- drivers per platform on four dialect bases (Mastodon API, Misskey API,
  Lemmy API, PrivaPub with /clientapi), each with a selftest against
  its own server; what a server holds is read from its database, never
  by making it fetch;
- a deterministic generator (specs/village.json: 23 accounts on seven
  servers, roots with several personas, circles and communities, a
  cross-server follow graph, posts of every kind and visibility, reply
  rounds, likes, boosts, reactions, votes, edits, deletes, blocks,
  mutes and a report) and a seeder that keeps a ledger of what happened;
- a sweep that expects delivery and confinement per server, what each
  account sees, counts, threads, edits, deletes, follows and privacy
  rows (sibling keys, published days, canary root credentials in every
  peer's database, located posts that never leave), with what the peers
  do on purpose modelled (Misskey drops orphan replies, Lemmy keeps only
  community content, edits go to the post's own audience);
- known gaps (gaps.json) turn failures into xfail and passes into xpass;
  a self-contained report.html, and docs/INTEROP-BACKLOG.md.

The pasture moves to a public-looking subnet (peers with no private
address switch can join), takes PASTURE_PORT when 6971 is in use, adds
peers to a running pasture (run.sh add, Caddy recreated with its CA
kept), removes its volumes on down, writes every scenario check to
out/scenarios.jsonl, serves decePub as decepub.test for its e2e tests,
lifts GoToSocial's and Lemmy's own rate limits, trusts Caddy in
Mastodon (TRUSTED_PROXY_IP) and gains Hollo (Fedify), whose one login
owning several accounts is the nearest peer to PrivaPub's personas.

The first village found the four PrivaPub bugs fixed in the commits
before this one; the second run, on the fixed server, passes 2319 checks
with 11 failures left, all between peers or from Lemmy's send worker,
which the seeder now warms up first. ROADMAP records the owner's
decisions of 2026-10-04 (the town, and P9 back from the cut list).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
2026-10-05 00:32:54 +02:00

134 lines
6.3 KiB
Python

"""PrivaPub: roots signed up on /clientapi, personas made under them, and each persona's Mastodon token exchanged for the
root's JWT exactly as decePubClient does (RFC 8693, client `decepub`). Everything a Mastodon client can say goes
through the Mastodon API; circles, communities and located posts through /clientapi. Objects are read from Mongo."""
from core import podman
from dialects.base import Made, Session, Stored, Unsupported
from dialects.mastodon_api import MastodonApi
VIS = {0: "public", 1: "unlisted", 2: "followers", 3: "direct", 4: "circle", 5: "located",
"Public": "public", "Unlisted": "unlisted", "FollowersOnly": "followers", "Direct": "direct", "Circle": "circle",
"LocalGeo": "located"}
class PrivaPub(MastodonApi):
platform = "privapub"
caps = MastodonApi.caps | {"react", "quote", "circle", "community", "located"}
def __init__(self, host="privapub.test"):
super().__init__(host)
self._jwts = {}
# -- roots and personas
def jwt(self, root, password):
if root in self._jwts:
return self._jwts[root]
body = {"userName": root, "password": password}
r = self.http.post(self.base + "/clientapi/user/signup", json=body)
token = (r.json() or {}).get("token") if r.ok else None
if not token:
token = self.http.post(self.base + "/clientapi/user/login", json=body, ok={200}).json()["token"]
self._jwts[root] = token
return token
def personas(self, root, password):
jwt = self.jwt(root, password)
r = self.http.get(self.base + "/clientapi/avatar/private/list", headers={"Authorization": f"Bearer {jwt}"}, ok={200})
return {p["userName"]: p for p in r.json() or []}
def provision(self, accounts):
"""Each account is a persona; `account.root` names its root, whose password is `account.password`."""
sessions = []
for root in dict.fromkeys(a.root for a in accounts):
mine = [a for a in accounts if a.root == root]
password = mine[0].password
jwt = self.jwt(root, password)
existing = self.personas(root, password)
for a in mine:
if a.username not in existing:
self.http.post(self.base + "/clientapi/avatar/private/insert", ok={200, 201},
headers={"Authorization": f"Bearer {jwt}"},
json={"userName": a.username, "name": a.name or a.username, "biography": a.bio or a.name or a.username,
"fields": dict(a.fields)})
existing = self.personas(root, password)
for a in mine:
token = self.exchange(jwt, existing[a.username]["id"])
sessions.append(self.session_from_token(a, token))
by_name = {s.account.username: s for s in sessions}
return [by_name[a.username] for a in accounts]
def exchange(self, jwt, avatar_id):
return self.http.post(self.base + "/oauth/token", ok={200}, form={
"grant_type": "urn:ietf:params:oauth:grant-type:token-exchange", "client_id": "decepub",
"subject_token": jwt, "subject_token_type": "urn:ietf:params:oauth:token-type:jwt",
"avatar_id": avatar_id, "scope": "read write follow"}).json()["access_token"]
def actor_uri(self, username):
return f"https://{self.host}/peasants/{username}"
# -- groups: communities (FEP-1b12) and circles
def group(self, s, username, name, community, policy="followers", approve=False):
jwt = self._jwts[s.account.root]
r = self.http.post(self.base + "/clientapi/group/insert", headers={"Authorization": f"Bearer {jwt}"}, ok={200, 201},
json={"avatarId": s.local_id, "userName": username, "name": name, "description": name,
"isCommunity": community, "postingPolicy": policy, "isDiscoverable": community,
"manuallyApprovesMembers": approve})
return r.json()
# -- content
def post(self, s, spec):
if spec.visibility in ("circle", "community", "located"):
return self._client_post(s, spec)
return super().post(s, spec)
def _client_post(self, s, spec):
jwt = self._jwts[s.account.root]
body = {"avatarId": s.local_id, "text": spec.text, "title": spec.title, "hasContentWarning": bool(spec.cw),
"spoilerText": spec.cw}
if spec.visibility == "located":
loc = spec.location
body.update({"latitude": loc["lat"], "longitude": loc["lng"], "rangeKm": loc.get("range_km", 5)})
else:
body["groupId"] = spec.group
if spec.reply_to_uri:
body["answeringToPostId"] = self.local_status_id(s, spec.reply_to_uri)
r = self.http.post(self.base + "/clientapi/post/insert", headers={"Authorization": f"Bearer {jwt}"},
ok={200, 201}, json=body).json()
post_id = r.get("id") if isinstance(r, dict) else None
if not post_id:
raise RuntimeError(f"/clientapi/post/insert answered {r!r}")
row = podman.mongo(f"db.Post.findOne({{_id: ObjectId('{post_id}')}}, {{ObjectURI: 1}})")
return Made(row["ObjectURI"], post_id, None)
def react(self, s, uri, emoji):
import urllib.parse
sid = self.local_status_id(s, uri) or self.resolve(s, uri)
self.api(s, "PUT", f"/api/v1/pleroma/statuses/{sid}/reactions/{urllib.parse.quote(emoji)}", ok={200})
# -- reading back
def _rows(self, uris):
if not uris:
return {}
import json
docs = podman.mongo(f"db.Post.find({{ObjectURI: {{$in: {json.dumps(list(uris))}}}}}, "
"{ObjectURI: 1, Visibility: 1, Text: 1, ContentHtml: 1, SpoilerText: 1, EditedAt: 1, "
"InReplyToURI: 1, FavouritesCount: 1, ReblogsCount: 1, RepliesCount: 1, DownvotesCount: 1, "
"Poll: 1, DeletedAt: 1, ReblogOfPostId: 1, AuthorGone: 1, GroupId: 1, ConversationId: 1}).toArray()") or []
ids = [d["_id"]["$oid"] if isinstance(d["_id"], dict) else d["_id"] for d in docs]
reactions = {}
if ids:
for g in podman.mongo(f"db.Reaction.aggregate([{{$match: {{PostId: {{$in: {json.dumps(ids)}}}}}}}, "
"{$group: {_id: {p: '$PostId', e: '$Emoji'}, n: {$sum: 1}}}]).toArray()") or []:
reactions.setdefault(g["_id"]["p"], {})[g["_id"]["e"]] = g["n"]
out = {}
for d in docs:
if d.get("ReblogOfPostId"):
continue
pid = d["_id"]["$oid"] if isinstance(d["_id"], dict) else d["_id"]
poll = d.get("Poll") or {}
votes = [o.get("Votes", o.get("VotesCount", 0)) for o in poll.get("Options", [])] if poll else None
out[d["ObjectURI"]] = Stored(True, bool(d.get("DeletedAt")), pid, VIS.get(d.get("Visibility"), str(d.get("Visibility"))),
d.get("Text") or d.get("ContentHtml"), d.get("SpoilerText") or None,
bool(d.get("EditedAt")), d.get("InReplyToURI"), d.get("FavouritesCount", 0),
d.get("ReblogsCount", 0), d.get("RepliesCount", 0), votes, reactions.get(pid, {}), d)
return out