net10, the refactor finished, and federation that works
The tree had not compiled since its first commit: Group, DmGroup and
IGroupUsersService were referenced and never written, an IDE rename had
turned the user-settings DTO into the ViewAvatarServer enum, and the settings
were saved as an entity they no longer were.
Built now:
- Group (an ActivityPub Group actor with its own keys, members, invitation
code and optional password) and DmGroup (a conversation), with
/clientapi/group/{list,insert,update,join,leave,approve}.
- Posts and DMs: /clientapi/post/{list,insert,delete}, /clientapi/dm/{list,insert};
DM recipients are local usernames or user@host handles resolved by WebFinger.
- Invitation sign-up and login against the group's invitation code, checking
the password before any account is created.
- Federation: WebFinger, NodeInfo 2.0, actors at /peasants/{name} (Person,
Group, and an Application instance actor) with SPKI keys, draft-cavage
RSA-SHA256 HTTP signatures both ways, an inbox handling Follow (+Accept),
Undo, Create, Delete and Update, an outbox, notes at /posts/{id}, and a
persisted, retried, signed delivery queue. A post to a group is announced
by the group to its followers (FEP-1b12).
- The unused, broken typed ActivityPub models are replaced by a renderer;
NSign's HMAC setup, which could not federate, is gone.
Upgrade: net10.0, MongoDB.Entities 25.1 (instance DB API, Standard GUIDs),
Swashbuckle 10 / OpenApi 2, Serilog.AspNetCore 10, MailKit 4.18,
PasswordGenerator 3. The JWT keys are 64 bytes (IdentityModel 8 refuses
shorter for HS512). Production runs its own mongod on 127.0.0.1:27022, as
Sintopia's apps do, and deploys to privapub.thepra.dev from the build runner.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
56c5396106
commit
075c22228a
78 files changed
+3419
-1091
No files matched your search
@@ -0,0 +1,366 @@
|
||||
using Microsoft.Extensions.Localization;
|
||||
|
||||
using MongoDB.Entities;
|
||||
|
||||
using PrivaPub.ClientModels;
|
||||
using PrivaPub.ClientModels.Post;
|
||||
using PrivaPub.Models.Federation;
|
||||
using PrivaPub.Models.Group;
|
||||
using PrivaPub.Resources;
|
||||
using PrivaPub.Services.Federation;
|
||||
using PrivaPub.StaticServices;
|
||||
|
||||
using System.Text.Json.Nodes;
|
||||
|
||||
using DmPostEntity = PrivaPub.Models.Post.DmPost;
|
||||
using PostEntity = PrivaPub.Models.Post.Post;
|
||||
|
||||
namespace PrivaPub.Services
|
||||
{
|
||||
public interface IPostsService
|
||||
{
|
||||
Task<WebResult> InsertPost(string rootUserId, InsertPostForm form, CancellationToken token);
|
||||
Task<WebResult> DeletePost(string rootUserId, DeletePostForm form, CancellationToken token);
|
||||
Task<WebResult> GetPosts(string rootUserId, string avatarId, string groupId, CancellationToken token);
|
||||
Task<WebResult> InsertDm(string rootUserId, InsertDmForm form, CancellationToken token);
|
||||
Task<WebResult> GetDms(string rootUserId, string avatarId, string dmGroupId, CancellationToken token);
|
||||
}
|
||||
|
||||
public class PostsService : IPostsService
|
||||
{
|
||||
const int PageSize = 50;
|
||||
|
||||
readonly DbEntities _dbEntities;
|
||||
readonly ILocalActorService _localActors;
|
||||
readonly IRemoteActorService _remoteActors;
|
||||
readonly IDeliveryService _delivery;
|
||||
readonly IStringLocalizer<GenericRes> _localizer;
|
||||
readonly ILogger<PostsService> _logger;
|
||||
|
||||
public PostsService(DbEntities dbEntities,
|
||||
ILocalActorService localActors,
|
||||
IRemoteActorService remoteActors,
|
||||
IDeliveryService delivery,
|
||||
IStringLocalizer<GenericRes> localizer,
|
||||
ILogger<PostsService> logger)
|
||||
{
|
||||
_dbEntities = dbEntities;
|
||||
_localActors = localActors;
|
||||
_remoteActors = remoteActors;
|
||||
_delivery = delivery;
|
||||
_localizer = localizer;
|
||||
_logger = logger;
|
||||
}
|
||||
|
||||
public async Task<WebResult> InsertPost(string rootUserId, InsertPostForm form, CancellationToken token)
|
||||
{
|
||||
var result = new WebResult();
|
||||
try
|
||||
{
|
||||
var author = await OwnedAvatar(rootUserId, form.AvatarId, token);
|
||||
if (author == default)
|
||||
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
LocalActor group = default;
|
||||
if (!string.IsNullOrEmpty(form.GroupId))
|
||||
{
|
||||
var groupEntity = await _dbEntities.Groups.MatchID(form.GroupId).ExecuteFirstAsync(token);
|
||||
if (groupEntity == default || groupEntity.DeletionAt.HasValue
|
||||
|| !groupEntity.Members.Any(m => !m.IsForeign && m.AvatarId == form.AvatarId))
|
||||
return result.Invalidate(_localizer["Group not found."], StatusCodes.Status404NotFound);
|
||||
group = _localActors.FromGroup(groupEntity);
|
||||
}
|
||||
|
||||
var post = new PostEntity
|
||||
{
|
||||
GroupUserId = author.Id,
|
||||
GroupId = group?.Id,
|
||||
Title = form.Title,
|
||||
Text = form.Text,
|
||||
HasContentWarning = form.HasContentWarning,
|
||||
AnsweringToPostId = form.AnsweringToPostId,
|
||||
ActorURI = author.Uri
|
||||
};
|
||||
post.ID = (string)post.GenerateNewID();
|
||||
post.ObjectURI = author.PostUri(post.ID);
|
||||
await DB.Default.SaveAsync(post, token);
|
||||
|
||||
var inReplyTo = await ReplyTarget(form.AnsweringToPostId, token);
|
||||
var note = ActivityPubRenderer.Note(post, author, group, inReplyTo);
|
||||
var create = ActivityPubRenderer.Create(author, note, $"create-{post.ID}");
|
||||
await _delivery.EnqueueToFollowers(author, create, token);
|
||||
if (group != default)
|
||||
await _delivery.EnqueueToFollowers(group, ActivityPubRenderer.Announce(group, post.ObjectURI, $"announce-{post.ID}"), token);
|
||||
|
||||
result.Data = ToView(post);
|
||||
return result;
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
_logger.LogError(ex, $"{nameof(PostsService)}.{nameof(InsertPost)}");
|
||||
return result.Invalidate(_localizer["Error: {0}", ex.Message], exception: ex);
|
||||
}
|
||||
}
|
||||
|
||||
public async Task<WebResult> DeletePost(string rootUserId, DeletePostForm form, CancellationToken token)
|
||||
{
|
||||
var result = new WebResult();
|
||||
try
|
||||
{
|
||||
var author = await OwnedAvatar(rootUserId, form.AvatarId, token);
|
||||
if (author == default)
|
||||
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
var post = await _dbEntities.Posts
|
||||
.Match(p => p.ID == form.PostId && p.GroupUserId == author.Id && !p.IsFederatedCopy)
|
||||
.ExecuteFirstAsync(token);
|
||||
if (post == default)
|
||||
return result.Invalidate(_localizer["Post not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
await DB.Default.DeleteAsync<PostEntity>(post.ID);
|
||||
|
||||
var delete = ActivityPubRenderer.Delete(author, post.ObjectURI, $"delete-{post.ID}",
|
||||
new JsonArray(ActivityPubRenderer.Public), new JsonArray(author.Followers));
|
||||
var extraInboxes = Enumerable.Empty<string>();
|
||||
if (!string.IsNullOrEmpty(post.GroupId))
|
||||
{
|
||||
var group = await _localActors.FindById(LocalActorKind.Group, post.GroupId, token);
|
||||
if (group != default)
|
||||
extraInboxes = await _delivery.FollowerInboxes(group, token);
|
||||
}
|
||||
await _delivery.EnqueueToFollowers(author, delete, token, extraInboxes);
|
||||
return result;
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
_logger.LogError(ex, $"{nameof(PostsService)}.{nameof(DeletePost)}");
|
||||
return result.Invalidate(_localizer["Error: {0}", ex.Message], exception: ex);
|
||||
}
|
||||
}
|
||||
|
||||
public async Task<WebResult> GetPosts(string rootUserId, string avatarId, string groupId, CancellationToken token)
|
||||
{
|
||||
var result = new WebResult();
|
||||
try
|
||||
{
|
||||
var avatar = await OwnedAvatar(rootUserId, avatarId, token);
|
||||
if (avatar == default)
|
||||
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
var query = _dbEntities.Posts;
|
||||
if (string.IsNullOrEmpty(groupId))
|
||||
query.Match(p => p.GroupUserId == avatar.Id);
|
||||
else
|
||||
{
|
||||
var isMember = await _dbEntities.Groups
|
||||
.Match(g => g.ID == groupId && g.Members.Any(m => !m.IsForeign && m.AvatarId == avatar.Id))
|
||||
.ExecuteAnyAsync(token);
|
||||
if (!isMember)
|
||||
return result.Invalidate(_localizer["Group not found."], StatusCodes.Status404NotFound);
|
||||
query.Match(p => p.GroupId == groupId);
|
||||
}
|
||||
|
||||
var posts = await query.Sort(p => p.CreationDate, Order.Descending).Limit(PageSize).ExecuteAsync(token);
|
||||
result.Data = posts.Select(ToView).ToList();
|
||||
return result;
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
_logger.LogError(ex, $"{nameof(PostsService)}.{nameof(GetPosts)}");
|
||||
return result.Invalidate(_localizer["Error: {0}", ex.Message], exception: ex);
|
||||
}
|
||||
}
|
||||
|
||||
public async Task<WebResult> InsertDm(string rootUserId, InsertDmForm form, CancellationToken token)
|
||||
{
|
||||
var result = new WebResult();
|
||||
try
|
||||
{
|
||||
var author = await OwnedAvatar(rootUserId, form.AvatarId, token);
|
||||
if (author == default)
|
||||
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
DmGroup dmGroup;
|
||||
if (!string.IsNullOrEmpty(form.DmGroupId))
|
||||
{
|
||||
dmGroup = await _dbEntities.DmGroups.MatchID(form.DmGroupId).ExecuteFirstAsync(token);
|
||||
if (dmGroup == default || !dmGroup.Members.Any(m => !m.IsForeign && m.AvatarId == author.Id))
|
||||
return result.Invalidate(_localizer["Conversation not found."], StatusCodes.Status404NotFound);
|
||||
}
|
||||
else
|
||||
{
|
||||
if (form.Recipients.Count == 0)
|
||||
return result.Invalidate(_localizer["At least one recipient is required."]);
|
||||
var members = new List<GroupMember> { new() { AvatarId = author.Id } };
|
||||
foreach (var recipient in form.Recipients.Distinct(StringComparer.OrdinalIgnoreCase))
|
||||
{
|
||||
var member = await ResolveRecipient(recipient, token);
|
||||
if (member == default)
|
||||
return result.Invalidate(_localizer["Recipient '{0}' not found.", recipient], StatusCodes.Status404NotFound);
|
||||
if (members.All(m => m.AvatarId != member.AvatarId))
|
||||
members.Add(member);
|
||||
}
|
||||
dmGroup = new DmGroup { Members = members };
|
||||
dmGroup.ID = (string)dmGroup.GenerateNewID();
|
||||
dmGroup.ConversationURI = $"{author.Uri}/conversations/{dmGroup.ID}";
|
||||
await DB.Default.SaveAsync(dmGroup, token);
|
||||
}
|
||||
|
||||
var dm = new DmPostEntity
|
||||
{
|
||||
GroupUserId = author.Id,
|
||||
GroupId = dmGroup.ID,
|
||||
Text = form.Text,
|
||||
HasContentWarning = form.HasContentWarning,
|
||||
ActorURI = author.Uri
|
||||
};
|
||||
dm.ID = (string)dm.GenerateNewID();
|
||||
dm.ObjectURI = author.PostUri(dm.ID);
|
||||
await DB.Default.SaveAsync(dm, token);
|
||||
await DB.Default.Update<DmGroup>().MatchID(dmGroup.ID).Modify(g => g.UpdatedAt, DateTime.UtcNow).ExecuteAsync(token);
|
||||
|
||||
var remote = new List<(string Uri, string Handle)>();
|
||||
var inboxes = new List<string>();
|
||||
foreach (var member in dmGroup.Members.Where(m => m.IsForeign))
|
||||
{
|
||||
var foreign = await _dbEntities.ForeignAvatars.Match(a => a.ActorURI == member.AvatarId).ExecuteFirstAsync(token);
|
||||
if (foreign == default)
|
||||
continue;
|
||||
remote.Add((foreign.ActorURI, $"{foreign.UserName}@{foreign.Domain}"));
|
||||
inboxes.Add(foreign.InboxURL);
|
||||
}
|
||||
foreach (var member in dmGroup.Members.Where(m => !m.IsForeign && m.AvatarId != author.Id))
|
||||
{
|
||||
var local = await _localActors.FindById(LocalActorKind.Person, member.AvatarId, token);
|
||||
if (local != default)
|
||||
remote.Add((local.Uri, local.Handle));
|
||||
}
|
||||
|
||||
if (inboxes.Count > 0)
|
||||
{
|
||||
var note = ActivityPubRenderer.DirectNote(dm, author, remote, dmGroup.ConversationURI);
|
||||
var create = ActivityPubRenderer.Create(author, note, $"create-{dm.ID}");
|
||||
await _delivery.Enqueue(author, inboxes, create, token);
|
||||
}
|
||||
|
||||
result.Data = ToView(dm);
|
||||
return result;
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
_logger.LogError(ex, $"{nameof(PostsService)}.{nameof(InsertDm)}");
|
||||
return result.Invalidate(_localizer["Error: {0}", ex.Message], exception: ex);
|
||||
}
|
||||
}
|
||||
|
||||
public async Task<WebResult> GetDms(string rootUserId, string avatarId, string dmGroupId, CancellationToken token)
|
||||
{
|
||||
var result = new WebResult();
|
||||
try
|
||||
{
|
||||
var avatar = await OwnedAvatar(rootUserId, avatarId, token);
|
||||
if (avatar == default)
|
||||
return result.Invalidate(_localizer["Avatar not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
if (string.IsNullOrEmpty(dmGroupId))
|
||||
{
|
||||
var groups = await _dbEntities.DmGroups
|
||||
.Match(g => !g.DeletionAt.HasValue && g.Members.Any(m => !m.IsForeign && m.AvatarId == avatar.Id))
|
||||
.Sort(g => g.UpdatedAt, Order.Descending)
|
||||
.ExecuteAsync(token);
|
||||
result.Data = groups.Select(g => new ViewDmGroup
|
||||
{
|
||||
Id = g.ID,
|
||||
Members = g.Members.Select(m => m.AvatarId).ToList(),
|
||||
UpdatedAt = g.UpdatedAt
|
||||
}).ToList();
|
||||
return result;
|
||||
}
|
||||
|
||||
var isMember = await _dbEntities.DmGroups
|
||||
.Match(g => g.ID == dmGroupId && g.Members.Any(m => !m.IsForeign && m.AvatarId == avatar.Id))
|
||||
.ExecuteAnyAsync(token);
|
||||
if (!isMember)
|
||||
return result.Invalidate(_localizer["Conversation not found."], StatusCodes.Status404NotFound);
|
||||
|
||||
var dms = await _dbEntities.DmPosts
|
||||
.Match(p => p.GroupId == dmGroupId)
|
||||
.Sort(p => p.CreationDate, Order.Descending)
|
||||
.Limit(PageSize)
|
||||
.ExecuteAsync(token);
|
||||
result.Data = dms.Select(ToView).ToList();
|
||||
return result;
|
||||
}
|
||||
catch (Exception ex)
|
||||
{
|
||||
_logger.LogError(ex, $"{nameof(PostsService)}.{nameof(GetDms)}");
|
||||
return result.Invalidate(_localizer["Error: {0}", ex.Message], exception: ex);
|
||||
}
|
||||
}
|
||||
|
||||
async Task<GroupMember> ResolveRecipient(string recipient, CancellationToken token)
|
||||
{
|
||||
var handle = recipient.Trim().TrimStart('@');
|
||||
if (!handle.Contains('@') || handle.EndsWith("@" + new Uri(_localActors.BaseAddress).Authority, StringComparison.OrdinalIgnoreCase))
|
||||
{
|
||||
var local = await _localActors.FindByUserName(handle.Split('@')[0], token);
|
||||
return local is { Kind: LocalActorKind.Person } ? new GroupMember { AvatarId = local.Id } : default;
|
||||
}
|
||||
|
||||
var actorUri = await _remoteActors.ResolveHandle(handle, token);
|
||||
if (actorUri == default)
|
||||
return default;
|
||||
var foreign = await _remoteActors.GetActor(actorUri, await _localActors.GetInstanceActor(token), refresh: false, token);
|
||||
return foreign == default ? default : new GroupMember { AvatarId = foreign.ActorURI, IsForeign = true };
|
||||
}
|
||||
|
||||
async Task<string> ReplyTarget(string answeringToPostId, CancellationToken token)
|
||||
{
|
||||
if (string.IsNullOrEmpty(answeringToPostId))
|
||||
return default;
|
||||
if (answeringToPostId.StartsWith("https://", StringComparison.OrdinalIgnoreCase))
|
||||
return answeringToPostId;
|
||||
var parent = await _dbEntities.Posts.MatchID(answeringToPostId).ExecuteFirstAsync(token);
|
||||
return parent?.ObjectURI;
|
||||
}
|
||||
|
||||
async Task<LocalActor> OwnedAvatar(string rootUserId, string avatarId, CancellationToken token)
|
||||
{
|
||||
if (string.IsNullOrEmpty(rootUserId) || string.IsNullOrEmpty(avatarId))
|
||||
return default;
|
||||
if (!await _dbEntities.RootToAvatars.Match(ra => ra.RootId == rootUserId && ra.AvatarId == avatarId).ExecuteAnyAsync(token))
|
||||
return default;
|
||||
return await _localActors.FindById(LocalActorKind.Person, avatarId, token);
|
||||
}
|
||||
|
||||
static ViewPost ToView(PostEntity post) => new()
|
||||
{
|
||||
Id = post.ID,
|
||||
ObjectURI = post.ObjectURI,
|
||||
AuthorAvatarId = post.IsFederatedCopy ? default : post.GroupUserId,
|
||||
AuthorActorURI = post.ActorURI,
|
||||
GroupId = post.GroupId,
|
||||
AnsweringToPostId = post.AnsweringToPostId,
|
||||
Title = post.Title,
|
||||
Text = post.Text,
|
||||
HasContentWarning = post.HasContentWarning,
|
||||
IsFederatedCopy = post.IsFederatedCopy,
|
||||
CreationDate = post.CreationDate
|
||||
};
|
||||
|
||||
static ViewPost ToView(DmPostEntity post) => new()
|
||||
{
|
||||
Id = post.ID,
|
||||
ObjectURI = post.ObjectURI,
|
||||
AuthorAvatarId = post.IsFederatedCopy ? default : post.GroupUserId,
|
||||
AuthorActorURI = post.ActorURI,
|
||||
DmGroupId = post.GroupId,
|
||||
AnsweringToPostId = post.AnsweringToPostId,
|
||||
Title = post.Title,
|
||||
Text = post.Text,
|
||||
HasContentWarning = post.HasContentWarning,
|
||||
IsFederatedCopy = post.IsFederatedCopy,
|
||||
CreationDate = post.CreationDate
|
||||
};
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user