trails/openspec/changes/archive/2026-04-24-public-content-visibility/specs/activity-feed/spec.md
Ullrich Schäfer ba6f09171d Archive public-content-visibility
Final tasks ticked post-merge:
- 10.2: verified on prod that journal.routes + journal.activities still
  default to 'private' NOT NULL, with the only public rows being the
  15-each demo-bot seeded content
- 10.3: demo-activity-bot already inserts with visibility='public'
  directly in demo-bot.server.ts

Syncs the three delta specs into main:
  + activity-feed: 2 added, 1 modified
  + public-profiles: new spec (1 added)
  + route-management: 2 added, 1 modified

Moves change to openspec/changes/archive/2026-04-24-public-content-visibility.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-24 21:57:21 +02:00

2.8 KiB

MODIFIED Requirements

Requirement: Activity detail page

The Journal SHALL display an activity detail page with map, stats, and description. Access depends on the activity's visibility: public activities are viewable by anyone including unauthenticated visitors, unlisted activities are viewable by anyone who has the URL, and private activities are viewable only by the owner.

Scenario: Owner views own activity

  • WHEN a logged-in user navigates to an activity they own at any visibility
  • THEN they see the activity name, description, a map with the GPS trace, distance, duration, and elevation stats

Scenario: Anyone views a public activity

  • WHEN any visitor (including unauthenticated) navigates to a public activity's URL
  • THEN they see the full activity detail page as above

Scenario: Anyone with the URL views an unlisted activity

  • WHEN any visitor navigates directly to an unlisted activity's URL
  • THEN they see the full activity detail page as above

Scenario: Non-owner is blocked from a private activity

  • WHEN a visitor who is not the owner requests a private activity URL
  • THEN the server responds with HTTP 404 (not 403), so the existence of the private activity is not leaked

Scenario: Public and unlisted activity pages emit social-share metadata

  • WHEN a visitor loads a public or unlisted activity detail page
  • THEN the response emits Open Graph and Twitter Card meta tags (og:title, og:description, og:type="article", og:site_name, twitter:card="summary")

ADDED Requirements

Requirement: Activity visibility

The Journal SHALL persist a visibility value on every activity and SHALL allow the owner to change it.

Scenario: New activities default to private

  • WHEN an activity is created without an explicit visibility
  • THEN the activity row is persisted with visibility = 'private'

Scenario: Owner changes an activity's visibility

  • WHEN an activity owner selects a different visibility (private, unlisted, public) and saves
  • THEN the stored visibility is updated and subsequent access checks use the new value immediately

Requirement: Activity listings respect visibility

The Journal's own-activities feed SHALL show the owner everything regardless of visibility, while any cross-user listing SHALL only include activities with visibility = 'public'.

Scenario: Own activity feed is unchanged

  • WHEN a logged-in user views their own activity feed
  • THEN the feed includes all of their own activities regardless of visibility

Scenario: Public profile lists only public activities

  • WHEN a visitor loads /users/:username
  • THEN the rendered list of activities includes only the user's public activities; unlisted and private activities are omitted