trails/openspec/changes/social-federation
Ullrich Schäfer f4d2cf027c docs(journal): federation privacy manifest + runbook + honest home blurb (§10)
10.1 Privacy manifest (legal/privacy):
- German legal half: Föderation entry under Empfänger/Drittanbieter —
  what a public profile exposes, what accepted followers' servers
  receive, the loss-of-control over delivered copies, Art. 6(1)(a)
  basis, private profiles don't federate.
- English manifest half: dedicated Federation (ActivityPub) section —
  actor object contents, push delivery + retraction semantics (incl.
  the tombstone caveat), encrypted-at-rest signing keys, remote actor
  cache, ingested remote content with the followers-only viewer gate,
  inbox logging/rate limits. PRIVACY_LAST_UPDATED bumped.

10.2 docs/deployment.md federation runbook: enabling per environment,
key rotation posture, abuse monitoring, and the troubleshooting
checklist distilled from the 2026-06-06/07 soak (IP families first,
no outbox backfill, tombstones, the 10s delivery timeout, actor
re-fetch).

10.3 Home marketing blurb (en+de) aligned to what actually ships:
Mastodon can follow you + trails-to-trails outbound — no more 'follow
friends anywhere' overstatement.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 12:21:51 +02:00
..
specs Propose: social-federation (ActivityPub via Fedify) 2026-04-25 22:31:28 +02:00
.openspec.yaml Propose: social-federation (ActivityPub via Fedify) 2026-04-25 22:31:28 +02:00
design.md fix(journal): retract federated activities only on public→non-public 2026-06-07 08:52:23 +02:00
proposal.md feat(journal): federation inbox — Mastodon follows land here 2026-06-06 14:33:43 +02:00
tasks.md docs(journal): federation privacy manifest + runbook + honest home blurb (§10) 2026-06-07 12:21:51 +02:00