trails/apps/journal/app/routes/feed.server.ts
Ullrich Schäfer bf2d8bfbd4 feat(journal): audience-aware social feed with remote activities (§8+§9)
8.1/8.2: listSocialFeed is now a UNION ALL of local and remote
branches, sorted on COALESCE(remote_published_at, created_at):
- local rows: visibility='public' from accepted local follows — and
  the previously missing accepted_at filter is added (the spec's
  'Pending follows contribute nothing' scenario)
- remote rows: gated structurally by joining the viewer's OWN accepted
  follow against the originating actor — which is exactly the
  followers-only audience rule (a row reaches only viewers whose
  follow brought it in); attribution from the remote_actors cache;
  cards link outward to the canonical origin page (no local detail
  page for remote rows)

9.1: annotated — local Pending button shipped with locked accounts;
remote Pending lives on /follows/outgoing.
9.2: already enforced + tested since §3 (actor/webfinger 404).
9.3 hardening: deliver-activity now re-checks the OWNER's profile
visibility at send time, closing the enqueue→delivery flip window
(enqueue-side and inbound-side gates already existed).

Integration tests: the §8 audience-leak guard (A sees followers-only,
B does not), public remote attribution + outward link, pending
contributes nothing, mixed local/remote COALESCE ordering.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 12:32:11 +02:00

41 lines
1.4 KiB
TypeScript

// Server-only loader for /feed. See `home.server.ts`.
import { redirect } from "react-router";
import { getSessionUser } from "~/lib/auth/session.server";
import { listSocialFeed, listRecentPublicActivities } from "~/lib/activities.server";
type View = "followed" | "public";
export async function loadFeed(request: Request) {
const user = await getSessionUser(request);
if (!user) throw redirect("/auth/login");
const url = new URL(request.url);
const view: View = url.searchParams.get("view") === "public" ? "public" : "followed";
const rows =
view === "public"
? await listRecentPublicActivities(50)
: await listSocialFeed(user.id, 50);
return {
view,
activities: rows.map((a) => ({
id: a.id,
name: a.name,
distance: a.distance,
elevationGain: a.elevationGain,
duration: a.duration,
startedAt: a.startedAt?.toISOString() ?? null,
createdAt: a.createdAt.toISOString(),
geojson: a.geojson ?? null,
ownerUsername: a.ownerUsername,
ownerDisplayName: a.ownerDisplayName,
// Remote (federated) attribution — only the followed view can
// contain remote rows; the public view is local-only.
ownerDomain: "ownerDomain" in a ? a.ownerDomain : null,
externalUrl: "externalUrl" in a ? a.externalUrl : null,
remote: "remote" in a ? a.remote : false,
})),
};
}