Owner decisions (2026-10-04, recorded in docs/ROADMAP.md): production runs everything that is built, and nothing waits
on a person running a command.
- Geolocation updates itself. GeoUpdater, a hosted service, checks daily whether each DB-IP Lite database was built this
month. If not, it fetches this month's, or last month's early in the month. It installs a file only once it opens as
the right kind of database, then swaps it in atomically, and the locator reloads at once. Lookups now run under the
lock, so a reload can no longer dispose a reader mid-lookup. The systemd timer, its script and their setup.sh lines
are gone: the root step they needed never happened, and none is needed now. /stargazing names the database in use.
- The admin CLI runs after the app is built, with every service and nothing started.
- `create-root <login> [--admin]` takes the password on stdin; it is how the first login is made while sign-up is
closed.
- `smoke <persona>` keeps the root `deploy-smoke` and an undiscoverable persona, and gives the root a new password
on every run.
- The deploy signs in as @thepra. It runs the CLI, gets a token through the real OAuth flow (tools/smoke/oauth.sh,
moved out of the pasture's privapub_token, which now uses it), checks the signed-in API and that @thepra is
undiscoverable, then revokes the token. PRIVAPUB_SMOKE_TOKEN is gone.
- The deploy also fails when:
- NodeInfo and the instance API disagree about registrations;
- /stargazing does not say the crawler is on;
- the geolocation databases are missing or more than 40 days old.
- The crawler is on in production, seeded with ten large servers of different kinds. FEDERATION.md now describes it
and how to opt out.
- One registrations switch (Registrations:Mode, default Invitations; Open in tests and the pasture). It is read by
open sign-up (403 when closed), NodeInfo `openRegistrations`, and v1 and v2 of the instance API, so they can no longer
disagree. Before, NodeInfo said open and the instance API said closed. Group invitations always work, so
invites_enabled is true.
- A persona edit through /clientapi no longer resets what the Mastodon API set (discoverable, locked, quote policy…):
the theme is merged into the settings instead of replacing them.
650 tests pass. The deploy's smoke step was rehearsed against the pasture's PrivaPub.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ELjqpznMFMNrJoJUj6K5p2
207 lines
7.4 KiB
C#
207 lines
7.4 KiB
C#
using Microsoft.Extensions.Localization;
|
|
|
|
using MongoDB.Entities;
|
|
|
|
using PrivaPub.ClientModels;
|
|
using PrivaPub.ClientModels.User;
|
|
using PrivaPub.ClientModels.User.Avatar;
|
|
using PrivaPub.Models.Federation;
|
|
using PrivaPub.Models.User;
|
|
using PrivaPub.Resources;
|
|
using PrivaPub.StaticServices;
|
|
using PrivaPub.Federation.Actors;
|
|
using PrivaPub.Federation.Outbox;
|
|
|
|
namespace PrivaPub.Services.ClientToServer.Private
|
|
{
|
|
public interface IPrivateAvatarUsersService
|
|
{
|
|
Task<WebResult> UpdateAvatar(UpdateAvatarForm form);
|
|
Task<WebResult> InsertAvatar(InsertAvatarForm form);
|
|
Task<WebResult> GetRootAvatars(string rootUserId, CancellationToken token);
|
|
}
|
|
|
|
public class PrivateAvatarUsersService : IPrivateAvatarUsersService
|
|
{
|
|
readonly ILocalActorService _localActors;
|
|
readonly IOutboxPublisher _outbox;
|
|
readonly DbEntities _dbEntities;
|
|
readonly IStringLocalizer<GenericRes> _localizer;
|
|
readonly ILogger<PrivateAvatarUsersService> _logger;
|
|
|
|
public PrivateAvatarUsersService(ILocalActorService localActors,
|
|
IOutboxPublisher outbox,
|
|
DbEntities dbEntities,
|
|
IStringLocalizer<GenericRes> localizer,
|
|
ILogger<PrivateAvatarUsersService> logger)
|
|
{
|
|
_localActors = localActors;
|
|
_outbox = outbox;
|
|
_dbEntities = dbEntities;
|
|
_localizer = localizer;
|
|
_logger = logger;
|
|
}
|
|
|
|
public async Task<WebResult> InsertAvatar(InsertAvatarForm form)
|
|
{
|
|
var result = new WebResult();
|
|
try
|
|
{
|
|
var userName = form.UserName?.Trim().ToLowerInvariant();
|
|
if (string.IsNullOrEmpty(userName) || !userName.All(c => char.IsAsciiLetterOrDigit(c) || c == '_'))
|
|
return result.Invalidate(_localizer["The username may contain only letters, digits and underscores."]);
|
|
|
|
if (await _localActors.IsUserNameTaken(userName, default))
|
|
return result.Invalidate(_localizer["The username '{0}' is already take.", userName]);
|
|
|
|
if (!await IsValidRootUser(form.RootId))
|
|
return result.Invalidate(_localizer["You can't do this action because of your account status."]);
|
|
|
|
var (privateKey, publicKey) = Keys.NewKeyPair();
|
|
var newAvatar = new Avatar
|
|
{
|
|
Name = form.Name,
|
|
UserName = userName,
|
|
Biography = form.Biography,
|
|
Fields = form.Fields,
|
|
PersonalNote = form.PersonalNote,
|
|
PrivateKey = privateKey,
|
|
PublicKey = publicKey,
|
|
Domain = _localActors.BaseAddress
|
|
};
|
|
newAvatar.ID = (string)newAvatar.GenerateNewID();
|
|
if (!await _localActors.TryReserveUserName(userName, LocalActorKind.Person, newAvatar.ID, default))
|
|
return result.Invalidate(_localizer["The username '{0}' is already take.", userName]);
|
|
if (form.Settings is { IsDefault: false })
|
|
Apply(newAvatar.Settings, form.Settings);
|
|
|
|
var actor = _localActors.FromAvatar(newAvatar);
|
|
newAvatar.Url = actor.Uri;
|
|
newAvatar.InboxURL = actor.Inbox;
|
|
newAvatar.OutboxURL = actor.Outbox;
|
|
|
|
await DB.Default.SaveAsync(newAvatar);
|
|
await DB.Default.SaveAsync(new RootToAvatar { RootId = form.RootId, AvatarId = newAvatar.ID });
|
|
|
|
result.Data = ToView(newAvatar);
|
|
return result;
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, $"{nameof(PrivateAvatarUsersService)}.{nameof(InsertAvatar)}");
|
|
return result.Invalidate(_localizer["Something went wrong."], exception: ex);
|
|
}
|
|
}
|
|
|
|
public async Task<WebResult> UpdateAvatar(UpdateAvatarForm form)
|
|
{
|
|
var result = new WebResult();
|
|
try
|
|
{
|
|
if (!await IsValidRootUser(form.RootId))
|
|
return result.Invalidate(_localizer["You can't do this action because of your account status."]);
|
|
|
|
var owns = await _dbEntities.RootToAvatars
|
|
.Match(ra => ra.RootId == form.RootId && ra.AvatarId == form.AvatarId)
|
|
.ExecuteAnyAsync();
|
|
if (!owns)
|
|
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
|
|
|
var avatar = await _dbEntities.Avatars.MatchID(form.AvatarId).ExecuteFirstAsync();
|
|
if (avatar == default || avatar.DeletionAt.HasValue)
|
|
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
|
|
|
avatar.Name = form.Name;
|
|
avatar.Biography = form.Biography;
|
|
avatar.Fields = form.Fields ?? new();
|
|
avatar.PersonalNote = form.PersonalNote;
|
|
if (form.Settings != default)
|
|
Apply(avatar.Settings ??= new(), form.Settings);
|
|
avatar.UpdatedAt = DateTime.UtcNow;
|
|
await DB.Default.SaveAsync(avatar);
|
|
await _outbox.PublishProfile(_localActors.FromAvatar(avatar), default);
|
|
|
|
result.Data = ToView(avatar);
|
|
return result;
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, $"{nameof(PrivateAvatarUsersService)}.{nameof(UpdateAvatar)}");
|
|
return result.Invalidate(_localizer["Something went wrong."], exception: ex);
|
|
}
|
|
}
|
|
|
|
public async Task<WebResult> GetRootAvatars(string rootUserId, CancellationToken token)
|
|
{
|
|
var result = new WebResult();
|
|
try
|
|
{
|
|
var avatarIds = (await _dbEntities.RootToAvatars.Match(ra => ra.RootId == rootUserId).ExecuteAsync(token))
|
|
.Select(ra => ra.AvatarId)
|
|
.ToList();
|
|
var avatars = avatarIds.Count == 0
|
|
? new List<Avatar>()
|
|
: await _dbEntities.Avatars.Match(a => avatarIds.Contains(a.ID) && !a.DeletionAt.HasValue).ExecuteAsync(token);
|
|
result.Data = avatars.Select(ToView).ToList();
|
|
return result;
|
|
}
|
|
catch (Exception ex)
|
|
{
|
|
_logger.LogError(ex, $"{nameof(PrivateAvatarUsersService)}.{nameof(GetRootAvatars)}");
|
|
return result.Invalidate(_localizer["Something went wrong."], exception: ex);
|
|
}
|
|
}
|
|
|
|
async ValueTask<bool> IsValidRootUser(string rootUserId) =>
|
|
!string.IsNullOrEmpty(rootUserId)
|
|
&& await _dbEntities.RootUsers.MatchID(rootUserId)
|
|
.Match(ru => !ru.DeletedAt.HasValue && !ru.IsBanned)
|
|
.ExecuteAnyAsync();
|
|
|
|
// The client API carries only the theme; the rest (discoverable, locked, quote policy…) is set through the Mastodon API
|
|
// and must survive an edit made here.
|
|
static void Apply(AvatarSettings target, ViewAvatarSettings settings)
|
|
{
|
|
target.IsDefault = settings.IsDefault;
|
|
target.DarkThemeIndexColour = settings.DarkThemeIndexColour;
|
|
target.IconsThemeIndexColour = settings.IconsThemeIndexColour;
|
|
target.LanguageCode = settings.LanguageCode;
|
|
target.LightThemeIndexColour = settings.LightThemeIndexColour;
|
|
target.PreferSystemTheming = settings.PreferSystemTheming;
|
|
target.ThemeIsDarkGray = settings.ThemeIsDarkGray;
|
|
target.ThemeIsDarkMode = settings.ThemeIsDarkMode;
|
|
target.ThemeIsLightGray = settings.ThemeIsLightGray;
|
|
}
|
|
|
|
ViewAvatar ToView(Avatar avatar) => new()
|
|
{
|
|
Id = avatar.ID,
|
|
Url = avatar.Url,
|
|
Handle = _localActors.FromAvatar(avatar).Handle,
|
|
Name = avatar.Name,
|
|
UserName = avatar.UserName,
|
|
Biography = avatar.Biography,
|
|
Fields = avatar.Fields,
|
|
PictureURL = avatar.PictureURL,
|
|
ThumbnailURL = avatar.ThumbnailURL,
|
|
SharedPersonalContacts = avatar.SharedPersonalContacts,
|
|
AccountState = (ViewAvatarState)(int)avatar.AccountState,
|
|
ServerType = ViewAvatarServer.PrivaPub,
|
|
Settings = new()
|
|
{
|
|
IsDefault = avatar.Settings.IsDefault,
|
|
LanguageCode = avatar.Settings.LanguageCode,
|
|
IconsThemeIndexColour = avatar.Settings.IconsThemeIndexColour,
|
|
LightThemeIndexColour = avatar.Settings.LightThemeIndexColour,
|
|
DarkThemeIndexColour = avatar.Settings.DarkThemeIndexColour,
|
|
PreferSystemTheming = avatar.Settings.PreferSystemTheming,
|
|
ThemeIsDarkMode = avatar.Settings.ThemeIsDarkMode,
|
|
ThemeIsDarkGray = avatar.Settings.ThemeIsDarkGray,
|
|
ThemeIsLightGray = avatar.Settings.ThemeIsLightGray
|
|
},
|
|
UpdatedAt = avatar.UpdatedAt,
|
|
CreatedAt = avatar.CreatedAt
|
|
};
|
|
}
|
|
}
|