trails/openspec/changes/social-federation
Ullrich Schäfer bf2d8bfbd4 feat(journal): audience-aware social feed with remote activities (§8+§9)
8.1/8.2: listSocialFeed is now a UNION ALL of local and remote
branches, sorted on COALESCE(remote_published_at, created_at):
- local rows: visibility='public' from accepted local follows — and
  the previously missing accepted_at filter is added (the spec's
  'Pending follows contribute nothing' scenario)
- remote rows: gated structurally by joining the viewer's OWN accepted
  follow against the originating actor — which is exactly the
  followers-only audience rule (a row reaches only viewers whose
  follow brought it in); attribution from the remote_actors cache;
  cards link outward to the canonical origin page (no local detail
  page for remote rows)

9.1: annotated — local Pending button shipped with locked accounts;
remote Pending lives on /follows/outgoing.
9.2: already enforced + tested since §3 (actor/webfinger 404).
9.3 hardening: deliver-activity now re-checks the OWNER's profile
visibility at send time, closing the enqueue→delivery flip window
(enqueue-side and inbound-side gates already existed).

Integration tests: the §8 audience-leak guard (A sees followers-only,
B does not), public remote attribution + outward link, pending
contributes nothing, mixed local/remote COALESCE ordering.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-07 12:32:11 +02:00
..
specs Propose: social-federation (ActivityPub via Fedify) 2026-04-25 22:31:28 +02:00
.openspec.yaml Propose: social-federation (ActivityPub via Fedify) 2026-04-25 22:31:28 +02:00
design.md feat(journal): outbox-poll ingestion of remote trails activities (§7) 2026-06-07 12:27:10 +02:00
proposal.md feat(journal): federation inbox — Mastodon follows land here 2026-06-06 14:33:43 +02:00
tasks.md feat(journal): audience-aware social feed with remote activities (§8+§9) 2026-06-07 12:32:11 +02:00