S5 of the roadmap. ContentSanitizer wraps HtmlSanitizer with Mastodon's allowlist: the inline and list tags Mastodon keeps, href/rel/class and the list attributes, microformat and mention/hashtag/ellipsis/invisible classes, Mastodon's link schemes, every link rel=nofollow noopener noreferrer, relative links unlinked, headings folded to a bold paragraph, and the contents of script, style, svg, iframe and friends dropped rather than kept as text. Post and DmPost gain ContentHtml (what is shown) and ContentFormat (Markdown for local, Html for remote). Inbound Create and Update, and a remote actor's biography, are sanitized on the way in; local posts store their Markdig rendering. Migration _002 does the same to what is already stored, and migrations now run at startup. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
28 lines
917 B
C#
28 lines
917 B
C#
using MongoDB.Entities;
|
|
|
|
namespace PrivaPub.Models.Post
|
|
{
|
|
public class Post : Entity
|
|
{
|
|
public string GroupUserId { get; set; }
|
|
public string AnsweringToPostId { get; set; }
|
|
public string GroupId { get; set; }
|
|
public string Title { get; set; }
|
|
public string Text { get; set; }
|
|
public string ContentHtml { get; set; }
|
|
public ContentFormat ContentFormat { get; set; }
|
|
public List<PostMedia> Media { get; set; } = new();
|
|
public List<float> Location { get; set; } = new();
|
|
public float RangeKm { get; set; } = 5.0f;
|
|
public bool HasContentWarning { get; set; } = false;
|
|
|
|
public bool IsFederatedCopy { get; set; }
|
|
public string ObjectURI { get; set; }//the Note's id
|
|
public string ActorURI { get; set; }//attributedTo
|
|
|
|
public DateTime CreationDate { get; set; } = DateTime.UtcNow;
|
|
public DateTime? UpdateDate { get; set; } = DateTime.UtcNow;
|
|
public string UpdateReason { get; set; }
|
|
}
|
|
}
|