/clientapi/group had no way to see who is in a group or asks to join it,
so a circle's owner could not answer a request from elsewhere. Now:
- GET /clientapi/group/members: the members (local and remote, with their
role) and the pending requests, for the group's owner and moderators
only;
- POST /clientapi/group/reject: declines a request, telling the asker's
server with a Reject of its Follow;
- POST /clientapi/group/remove: takes a member out (never the owner): a
persona here stops following the group, one elsewhere gets a Reject of
its Follow, as Mastodon removes a follower.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw