8.1/8.2: listSocialFeed is now a UNION ALL of local and remote branches, sorted on COALESCE(remote_published_at, created_at): - local rows: visibility='public' from accepted local follows — and the previously missing accepted_at filter is added (the spec's 'Pending follows contribute nothing' scenario) - remote rows: gated structurally by joining the viewer's OWN accepted follow against the originating actor — which is exactly the followers-only audience rule (a row reaches only viewers whose follow brought it in); attribution from the remote_actors cache; cards link outward to the canonical origin page (no local detail page for remote rows) 9.1: annotated — local Pending button shipped with locked accounts; remote Pending lives on /follows/outgoing. 9.2: already enforced + tested since §3 (actor/webfinger 404). 9.3 hardening: deliver-activity now re-checks the OWNER's profile visibility at send time, closing the enqueue→delivery flip window (enqueue-side and inbound-side gates already existed). Integration tests: the §8 audience-leak guard (A sees followers-only, B does not), public remote attribution + outward link, pending contributes nothing, mixed local/remote COALESCE ordering. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
41 lines
1.4 KiB
TypeScript
41 lines
1.4 KiB
TypeScript
// Server-only loader for /feed. See `home.server.ts`.
|
|
|
|
import { redirect } from "react-router";
|
|
import { getSessionUser } from "~/lib/auth/session.server";
|
|
import { listSocialFeed, listRecentPublicActivities } from "~/lib/activities.server";
|
|
|
|
type View = "followed" | "public";
|
|
|
|
export async function loadFeed(request: Request) {
|
|
const user = await getSessionUser(request);
|
|
if (!user) throw redirect("/auth/login");
|
|
|
|
const url = new URL(request.url);
|
|
const view: View = url.searchParams.get("view") === "public" ? "public" : "followed";
|
|
|
|
const rows =
|
|
view === "public"
|
|
? await listRecentPublicActivities(50)
|
|
: await listSocialFeed(user.id, 50);
|
|
|
|
return {
|
|
view,
|
|
activities: rows.map((a) => ({
|
|
id: a.id,
|
|
name: a.name,
|
|
distance: a.distance,
|
|
elevationGain: a.elevationGain,
|
|
duration: a.duration,
|
|
startedAt: a.startedAt?.toISOString() ?? null,
|
|
createdAt: a.createdAt.toISOString(),
|
|
geojson: a.geojson ?? null,
|
|
ownerUsername: a.ownerUsername,
|
|
ownerDisplayName: a.ownerDisplayName,
|
|
// Remote (federated) attribution — only the followed view can
|
|
// contain remote rows; the public view is local-only.
|
|
ownerDomain: "ownerDomain" in a ? a.ownerDomain : null,
|
|
externalUrl: "externalUrl" in a ? a.externalUrl : null,
|
|
remote: "remote" in a ? a.remote : false,
|
|
})),
|
|
};
|
|
}
|