OutboxPublisher works out who a post goes to, Mastodon's way: followers'
shared inboxes for public, unlisted and followers-only; every mentioned
remote account's own inbox; the recipients only for direct; the parent's
author for a reply; a community's followers for a post in it; nobody for
a circle. Creates, updates and deletes all use it.
- Local posts take a visibility (public, unlisted, followers-only) and a
spoiler text next to the content-warning flag.
- /clientapi/post/update keeps the previous version as a revision,
re-renders, and sends Update{Note} with `updated` to the same to/cc.
- Deleting is now soft: the content, title, spoiler, media and revisions
are cleared, timeline entries removed, the parent's reply count goes
down, Delete goes to the stored audience, and the object answers 410
with a Tombstone instead of 404.
- Editing a persona's profile sends Update{Person} to its followers.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
67 lines
2.2 KiB
C#
67 lines
2.2 KiB
C#
using Microsoft.AspNetCore.Http;
|
|
using Microsoft.AspNetCore.Http.Features;
|
|
|
|
using PrivaPub.Federation.Signing;
|
|
|
|
using System.Globalization;
|
|
using System.Security.Cryptography;
|
|
using System.Text;
|
|
using System.Text.Json.Nodes;
|
|
|
|
namespace PrivaPub.Tests.Support
|
|
{
|
|
public sealed class RemoteActor
|
|
{
|
|
readonly RSA _key = RSA.Create(2048);
|
|
|
|
public RemoteActor(Peer peer, string name, string origin = default)
|
|
{
|
|
Name = $"{name}{Guid.NewGuid():N}"[..20];
|
|
Id = $"{origin ?? peer.A}/users/{Name}";
|
|
peer.Serve($"/users/{Name}", Document().ToJsonString());
|
|
}
|
|
|
|
public string Name { get; }
|
|
public string Id { get; }
|
|
public string KeyId => Id + "#main-key";
|
|
public string SharedInbox => Id.Split("/users/")[0] + "/inbox";
|
|
|
|
public JsonObject Document() => new()
|
|
{
|
|
["id"] = Id,
|
|
["type"] = "Person",
|
|
["preferredUsername"] = Name,
|
|
["inbox"] = Id + "/inbox",
|
|
["followers"] = Id + "/followers",
|
|
["publicKey"] = new JsonObject
|
|
{
|
|
["id"] = KeyId,
|
|
["owner"] = Id,
|
|
["publicKeyPem"] = _key.ExportSubjectPublicKeyInfoPem()
|
|
}
|
|
};
|
|
|
|
public HttpRequest Post(string host, string path, JsonNode activity)
|
|
{
|
|
var body = Encoding.UTF8.GetBytes(activity.ToJsonString());
|
|
var date = DateTimeOffset.UtcNow.ToString("r", CultureInfo.InvariantCulture);
|
|
var digest = HttpSignatures.Digest(body);
|
|
var signingString = $"(request-target): post {path}\nhost: {host}\ndate: {date}\ndigest: {digest}";
|
|
var signature = Convert.ToBase64String(_key.SignData(Encoding.UTF8.GetBytes(signingString), HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1));
|
|
|
|
var context = new DefaultHttpContext();
|
|
context.Request.Method = "POST";
|
|
context.Request.Host = new HostString(host);
|
|
context.Request.Path = path;
|
|
context.Features.Get<IHttpRequestFeature>().RawTarget = path;
|
|
context.Request.Headers["Date"] = date;
|
|
context.Request.Headers["Digest"] = digest;
|
|
context.Request.Headers["Content-Type"] = "application/activity+json";
|
|
context.Request.Headers["Signature"] = $"keyId=\"{KeyId}\",algorithm=\"rsa-sha256\",headers=\"(request-target) host date digest\",signature=\"{signature}\"";
|
|
context.Request.Body = new MemoryStream(body);
|
|
context.Request.ContentLength = body.Length;
|
|
return context.Request;
|
|
}
|
|
}
|
|
}
|