Communities: - a post addressed to a community (to, cc or audience) is accepted according to its posting policy - followers, anyone, or moderators - and GroupDistributor announces the whole activity with `audience` to the community's followers, plus the object for new posts so Mastodon shows them; updates and deletes of community content are announced too; - top-level posts are Pages with a name (the title, or a headline from the text); /flock counts members, /wardens lists moderators; - a Mastodon client posts into a community by mentioning it, or into a remote group, which sets `audience`; - an Announce of an activity from a remote group a persona follows (Lemmy) is followed through: the object is fetched from its own origin, kept with its AudienceURI, and fanned out to the group's local followers; updates are applied in place and deletes checked against the origin. Circles stop being local-only: an undiscoverable Group actor whose follows are all requests the owner approves; posts addressed to the circle and its /flock and delivered to members' own inboxes, never announced, never public; a remote member's post into the circle is accepted from members only. SignedFetchAuthorizer serves circle posts and collections only to a signed request from a member or a member server's instance actor - 404 for anyone else. Circles never surface in search, lookups, mentions, account ids or profile pages. Federation:SecureMode requires a valid signature on every GET under /peasants except the instance actor. Group forms take a posting policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
41 lines
1.6 KiB
C#
41 lines
1.6 KiB
C#
using PrivaPub.Federation.Actors;
|
|
using PrivaPub.Federation.Objects;
|
|
using PrivaPub.Models.User;
|
|
|
|
using GroupEntity = PrivaPub.Models.Group.Group;
|
|
|
|
namespace PrivaPub.Federation.Signing
|
|
{
|
|
public interface ISignedFetchAuthorizer
|
|
{
|
|
Task<ForeignAvatar> Requester(HttpRequest request, CancellationToken token);
|
|
}
|
|
|
|
public class SignedFetchAuthorizer : ISignedFetchAuthorizer
|
|
{
|
|
readonly IRemoteActorService _remoteActors;
|
|
|
|
public SignedFetchAuthorizer(IRemoteActorService remoteActors)
|
|
{
|
|
_remoteActors = remoteActors;
|
|
}
|
|
|
|
public async Task<ForeignAvatar> Requester(HttpRequest request, CancellationToken token)
|
|
{
|
|
var parameters = HttpSignatures.Parse(request.Headers["Signature"].ToString());
|
|
if (parameters == default || HttpSignatures.CheckRequest(request, parameters, body: default) != default)
|
|
return default;
|
|
var signingString = HttpSignatures.SigningString(request, parameters);
|
|
var actor = await _remoteActors.GetActorByKeyId(parameters.KeyId, refresh: false, token);
|
|
if (actor != default && HttpSignatures.Verify(actor.PublicKey, signingString, parameters.Signature))
|
|
return actor;
|
|
actor = await _remoteActors.GetActorByKeyId(parameters.KeyId, refresh: true, token);
|
|
return actor != default && HttpSignatures.Verify(actor.PublicKey, signingString, parameters.Signature) ? actor : default;
|
|
}
|
|
|
|
public static bool MayReadCircle(GroupEntity circle, ForeignAvatar requester) =>
|
|
requester != default && circle.Members.Any(m => m.IsForeign
|
|
&& (m.AvatarId == requester.ActorURI || requester.AvatarType == AvatarType.Application && Origin.Same(m.AvatarId, requester.ActorURI)));
|
|
}
|
|
}
|