An ObjectId carries its creation second and a per-process counter, so two avatars made one after the other by the same login got ids a few counts apart: a link between personas that every Mastodon client would have seen. Avatar and Group now generate ids from the UTC day plus eight random bytes (still valid ObjectIds), and a remote post's id is made from its published time with a random tail, so posts page in the order they were written rather than the order they arrived. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
21 lines
666 B
C#
21 lines
666 B
C#
using System.Buffers.Binary;
|
|
using System.Security.Cryptography;
|
|
|
|
namespace PrivaPub.Infrastructure.Ids
|
|
{
|
|
public static class PrivacyIds
|
|
{
|
|
public static string ForDay(DateTime when) => At(DateTime.SpecifyKind(when, DateTimeKind.Utc).Date);
|
|
|
|
public static string At(DateTime when)
|
|
{
|
|
var seconds = Math.Clamp(new DateTimeOffset(DateTime.SpecifyKind(when, DateTimeKind.Utc)).ToUnixTimeSeconds(), 0,
|
|
DateTimeOffset.UtcNow.AddDays(1).ToUnixTimeSeconds());
|
|
Span<byte> bytes = stackalloc byte[12];
|
|
BinaryPrimitives.WriteInt32BigEndian(bytes, (int)seconds);
|
|
RandomNumberGenerator.Fill(bytes[4..]);
|
|
return Convert.ToHexStringLower(bytes);
|
|
}
|
|
}
|
|
}
|