source: Klonkt/src/config/database.js@ e685f55

main
Last change on this file since e685f55 was 9e9e6f9, checked in by Robin <roboburr@…>, 7 weeks ago

Feature: paid posts slice 3, patron link + passkey (cookie-less)

The registration leg of the paid-posts flow (klonkt-demo-aki). A
visitor links once via Patreon and gets a pseudonymous passkey entitlement,
with no session and no patron identity stored.

  • Dependency (approved): @simplewebauthn/server for verification, plus @simplewebauthn/browser vendored (UMD) so the page loads it with no CDN.
  • New paid_entitlements table: {passkey, site, proven cents, expiry}. No name, e-mail or Patreon id, ever.
  • Cookie-less throughout: the OAuth state and the WebAuthn challenge travel in signed blobs (CryptoBox), so nothing is kept between requests.
  • Flow: GET /paid/link -> Patreon authorize; GET /paid/callback verifies the patron (verifyPatron exchanges the code, reads identity?include=memberships.campaign, checks patron_status + currently_entitled_amount_cents against the post's price), then hands out registration options + a signed blob carrying the challenge and proven cents; POST /paid/register verifies the passkey and stores the entitlement. The patron token is used once and discarded.

The gate button and the per-post unlock (assertion) are slice 4; this
leg is what that flow calls to register a passkey on demand.

Changed files:
package.json, package-lock.json

  • @simplewebauthn/server + @simplewebauthn/browser

src/assets/vendor/simplewebauthn-browser.umd.min.js

  • vendored browser UMD (no CDN)

src/config/database.js

  • paid_entitlements table (no patron identity)

src/services/PaidPatreonService.js

  • pickCampaignMembership (pure), verifyPatron (exchange + identity)

src/server.js

  • mount /paid before the /:slug catch-all

New file:
src/services/PasskeyService.js

  • registration options + verify (lib) + entitlement store/prune

src/routes/paid.js

  • link / callback / register (cookie-less)

src/views/pages/paid-passkey.ejs, paid-result.ejs

  • passkey creation + not-a-supporter pages

test/paid-patron.test.js

  • membership parse, patron exchange (mock), options challenge, entitlement store/expiry/prune/delete, no-identity-columns

-robo
Co-Authored-By: Claude Opus 4.8 <noreply@…>

  • Property mode set to 100644
File size: 24.3 KB
RevLine 
[7bc636b]1import Database from 'better-sqlite3';
2import path from 'path';
3import { fileURLToPath } from 'url';
4import fs from 'fs';
5
6const __dirname = path.dirname(fileURLToPath(import.meta.url));
7const dbPath = process.env.DATABASE_PATH || path.join(__dirname, '../../storage/database.sqlite');
8
9// Ensure storage directory exists
10const storageDir = path.dirname(dbPath);
11if (!fs.existsSync(storageDir)) {
12 fs.mkdirSync(storageDir, { recursive: true });
13}
14
15// Initialize database
16const db = new Database(dbPath);
17db.pragma('journal_mode = WAL');
18db.pragma('foreign_keys = ON');
[7b07035]19// With WAL + several concurrent writers (request handlers, the delivery worker, the
20// background thread-crawler) a short write-lock should retry rather than throw SQLITE_BUSY.
21db.pragma('busy_timeout = 5000'); // wait up to 5s for a lock instead of failing immediately
22db.pragma('synchronous = NORMAL'); // safe with WAL (no torn writes); fewer fsyncs = faster writes
[7bc636b]23
24export function initializeDatabase() {
25 const tableExists = db.prepare(`
26 SELECT name FROM sqlite_master WHERE type='table' AND name='users'
27 `).get();
28
29 if (!tableExists) {
30 console.log('🔧 Initializing database schema...');
31 const schemaPath = path.join(__dirname, '..', 'db', 'migrations', '001-init.sql');
32 const schema = fs.readFileSync(schemaPath, 'utf-8');
33 db.exec(schema);
34 console.log('✅ Database initialized with v9-soul schema');
35 }
36
37 // Additive column migrations — safe to run every boot.
38 // SQLite throws if the column already exists; we swallow that.
39 ensureColumn('sites', 'enable_audio_player', 'INTEGER DEFAULT 1');
40 ensureColumn('sites', 'profile_photo', 'TEXT');
41 ensureColumn('audio_tracks', 'cover_url', 'TEXT');
42 ensureColumn('audio_tracks', 'album', 'TEXT');
43 ensureColumn('users', 'reset_token', 'TEXT');
44 ensureColumn('users', 'reset_token_expires', 'DATETIME');
[834bcc3]45 // Google OAuth: link a Google account to a user (login via Google).
[c80e78b]46 ensureColumn('users', 'google_sub', 'TEXT');
[834bcc3]47 // Read-only/viewer account: can view everything but make no changes.
[640b39c]48 ensureColumn('users', 'readonly', 'INTEGER DEFAULT 0');
[834bcc3]49 // Personal interface language (nl|en|de). Null = follow the default (site/env/browser).
[5e61b17]50 ensureColumn('users', 'lang', 'TEXT');
[7bc636b]51 // Site-level moderation toggle. 'trust' = auto-approve, 'moderate' = pending until reviewed.
[834bcc3]52 // Circles: whether this site may appear in other sites' circles (surfacing opt-out).
[0091cb7]53 ensureColumn('sites', 'allow_circle', 'INTEGER DEFAULT 1');
[7bc636b]54
[834bcc3]55 // One EXPLICIT primary/main site (= the company/label site in hub mode,
56 // the only site in solo) instead of the fragile "oldest = main" convention
57 // that was duplicated in 4 places. Backfill: mark the oldest if no primary
58 // site exists yet, so existing behaviour is preserved exactly.
[7881080]59 ensureColumn('sites', 'is_primary', 'INTEGER DEFAULT 0');
60 try {
61 const hasPrimary = db.prepare('SELECT 1 FROM sites WHERE is_primary = 1 LIMIT 1').get();
62 if (!hasPrimary) {
63 const oldest = db.prepare('SELECT id FROM sites ORDER BY created_at ASC LIMIT 1').get();
64 if (oldest) db.prepare('UPDATE sites SET is_primary = 1 WHERE id = ?').run(oldest.id);
65 }
[834bcc3]66 } catch (e) { /* sites table still empty/absent on fresh init — ensurePrimarySite handles it */ }
[7881080]67
[7bc636b]68 // v9 audit additions —————————————————————————————————————————
69 // SEO/social columns the v9 template uses (most live in 001-init.sql already
70 // for fresh DBs but ensureColumn is idempotent for existing DBs).
71 ensureColumn('sites', 'twitter', 'TEXT'); // @handle (with @)
72 ensureColumn('sites', 'schema_type', "TEXT DEFAULT 'Person'"); // Person|Organization
73 ensureColumn('sites', 'publisher_name', 'TEXT');
74 ensureColumn('sites', 'publisher_url', 'TEXT');
75 ensureColumn('sites', 'publisher_logo', 'TEXT');
76 ensureColumn('sites', 'profile_enabled', 'INTEGER DEFAULT 1');
77 ensureColumn('sites', 'profile_name', 'TEXT'); // display name (falls back to title)
78 ensureColumn('sites', 'profile_bio', 'TEXT'); // short bio for header
79 ensureColumn('sites', 'profile_links', 'TEXT'); // JSON array [{platform, url}]
[8ea3d0d]80 ensureColumn('sites', 'feed_view_default', "TEXT DEFAULT 'grid'"); // timeline | grid
[7bc636b]81 ensureColumn('sites', 'feed_view_switch', 'INTEGER DEFAULT 1'); // show switcher
82 ensureColumn('sites', 'show_search', 'INTEGER DEFAULT 1');
83 ensureColumn('sites', 'show_archive_link', 'INTEGER DEFAULT 1');
[3b4095f]84 ensureColumn('sites', 'og_theme', 'TEXT'); // OG share-card variant: NULL=auto (follow site theme) | 'light' | 'dark'
[7bc636b]85
86 // Per-post noindex + type
87 ensureColumn('posts', 'noindex', 'INTEGER DEFAULT 0');
[834bcc3]88 ensureColumn('posts', 'publish_at', 'DATETIME'); // release planning (premium #3): scheduled go-live
[b9dc94c]89 ensureColumn('posts', 'fan_only', 'INTEGER DEFAULT 0'); // fan-only preview (premium #3)
[837fc9c]90 ensureColumn('posts', 'nsfw', 'INTEGER DEFAULT 0'); // sensitive content → blur + click-to-reveal; fediverse sensitive
[1d6f9a2]91 ensureColumn('posts', 'cover_video_url', 'TEXT'); // muted loop MP4 for an animated cover (Safari-smooth)
[d18c60e]92 ensureColumn('posts', 'cover_alt', 'TEXT'); // alt text / description for the cover (a11y → AS2 attachment `name`)
[0688b5f]93 ensureColumn('posts', 'language', 'TEXT'); // BCP-47 content language → federates as AS2 contentMap (Mastodon language filter/translate)
[b7d4458]94 ensureColumn('posts', 'content_warning', 'TEXT'); // custom CW label (empty = default "Gevoelige inhoud")
[7bc636b]95 ensureColumn('posts', 'type', "TEXT DEFAULT 'post'"); // post | foto | video | audio
[0403187]96 ensureColumn('posts', 'poll_json', 'TEXT'); // a poll WE host → federates as AS2 Question: {multiple,options[{name}],endTime,closed}
[7bc636b]97
[834bcc3]98 // Statistics (premium module) — bare counters, cookie-free.
99 ensureColumn('posts', 'view_count', 'INTEGER DEFAULT 0'); // views per post
[d549549]100 ensureColumn('audio_tracks', 'play_count', 'INTEGER DEFAULT 0'); // plays per track
[834bcc3]101 ensureColumn('audio_tracks', 'downloadable', 'INTEGER DEFAULT 0'); // download-for-email (premium #2)
102 ensureColumn('audio_tracks', 'credit', 'TEXT'); // owner/credit (copyright holder)
103 ensureColumn('audio_tracks', 'license', 'TEXT'); // license (e.g. "CC BY 4.0", "All rights reserved")
104 ensureColumn('audio_tracks', 'link_spotify', 'TEXT'); // "open in" links per track
[183875b]105 ensureColumn('audio_tracks', 'link_youtube', 'TEXT');
106 ensureColumn('audio_tracks', 'link_soundcloud', 'TEXT');
[f2eacca]107 // Per-track: federate the actual audio file as an AS2 Audio attachment so it plays inline
108 // in EVERY fediverse client (incl. the Mastodon apps). Default 0 = gated (web player only,
109 // file not exposed). Opt-in 1 = the file is served ungated + shared on the fediverse.
110 ensureColumn('audio_tracks', 'fedi_open', 'INTEGER DEFAULT 0');
[d549549]111
[7bc636b]112 // Playlists (v9 feature) — first-class entity. CREATE IF NOT EXISTS is
113 // idempotent so it's safe to run on every boot regardless of DB age.
114 db.exec(`
115 CREATE TABLE IF NOT EXISTS playlists (
116 id TEXT PRIMARY KEY,
117 site_id TEXT NOT NULL,
118 title TEXT NOT NULL,
119 artist TEXT,
120 year INTEGER,
121 cover_url TEXT,
122 kind TEXT DEFAULT 'album',
123 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
124 updated_at DATETIME DEFAULT CURRENT_TIMESTAMP,
125 FOREIGN KEY (site_id) REFERENCES sites(id)
126 );
127 CREATE TABLE IF NOT EXISTS playlist_tracks (
128 playlist_id TEXT NOT NULL,
129 track_id TEXT NOT NULL,
130 position INTEGER NOT NULL DEFAULT 0,
131 PRIMARY KEY (playlist_id, track_id),
132 FOREIGN KEY (playlist_id) REFERENCES playlists(id) ON DELETE CASCADE,
133 FOREIGN KEY (track_id) REFERENCES audio_tracks(id) ON DELETE CASCADE
134 );
135 CREATE INDEX IF NOT EXISTS idx_playlist_tracks_pos
136 ON playlist_tracks(playlist_id, position);
137 `);
[6351545]138
[834bcc3]139 // Global app settings (key/value singleton). Includes the tenancy mode
140 // (solo = one site, hub = company site + /user/). Default = solo.
[6351545]141 db.exec(`
142 CREATE TABLE IF NOT EXISTS app_settings (
143 key TEXT PRIMARY KEY,
144 value TEXT,
145 updated_at DATETIME DEFAULT CURRENT_TIMESTAMP
146 );
147 `);
148 db.prepare("INSERT OR IGNORE INTO app_settings (key, value) VALUES ('tenancy', 'solo')").run();
[b300682]149
[834bcc3]150 // ── Statistics (premium) — cookie-free ──────────────────────
151 // stat_daily: pageview count per day per site (bare counter).
152 // stat_visitor_day: one row per UNIQUE visitor hash per day per site
153 // (sha256 of IP+UA+day-salt; the salt rotates daily and is never stored
154 // → no persistent identifier, no cookie, no consent required).
[d549549]155 db.exec(`
156 CREATE TABLE IF NOT EXISTS stat_daily (
157 site_id TEXT NOT NULL,
158 day TEXT NOT NULL,
159 pageviews INTEGER NOT NULL DEFAULT 0,
160 PRIMARY KEY (site_id, day)
161 );
162 CREATE TABLE IF NOT EXISTS stat_visitor_day (
163 site_id TEXT NOT NULL,
164 day TEXT NOT NULL,
165 visitor_hash TEXT NOT NULL,
166 PRIMARY KEY (site_id, day, visitor_hash)
167 );
168 CREATE INDEX IF NOT EXISTS idx_stat_visitor_day ON stat_visitor_day(site_id, day);
[1794fac]169 CREATE TABLE IF NOT EXISTS stat_referrer (
170 site_id TEXT NOT NULL,
171 host TEXT NOT NULL,
172 count INTEGER NOT NULL DEFAULT 0,
173 PRIMARY KEY (site_id, host)
174 );
[d549549]175 `);
176
[834bcc3]177 // Newsletter / mailing list (premium). Subscribers per site; double opt-in when SMTP
178 // is configured (status 'pending' until confirmed), otherwise single opt-in ('confirmed').
179 // 'unsub' = unsubscribed. token = confirm/unsubscribe key (used in email links).
[2e247e4]180 db.exec(`
181 CREATE TABLE IF NOT EXISTS subscribers (
182 id TEXT PRIMARY KEY,
183 site_id TEXT NOT NULL,
184 email TEXT NOT NULL,
185 status TEXT NOT NULL DEFAULT 'pending',
186 source TEXT DEFAULT 'widget',
187 token TEXT NOT NULL,
188 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
189 confirmed_at DATETIME,
190 UNIQUE(site_id, email)
191 );
192 CREATE INDEX IF NOT EXISTS idx_subscribers_site_status ON subscribers(site_id, status);
193 `);
194
[834bcc3]195 // Sent newsletters (history + counts).
[2e247e4]196 db.exec(`
197 CREATE TABLE IF NOT EXISTS newsletters (
198 id TEXT PRIMARY KEY,
199 site_id TEXT NOT NULL,
200 subject TEXT NOT NULL,
201 body TEXT NOT NULL,
202 sent_at DATETIME DEFAULT CURRENT_TIMESTAMP,
203 recipient_count INTEGER DEFAULT 0
204 );
205 `);
[37edecd]206
[834bcc3]207 // Show agenda (premium #8): tour dates / gigs per site.
[8d32dcf]208 db.exec(`
209 CREATE TABLE IF NOT EXISTS shows (
210 id TEXT PRIMARY KEY,
211 site_id TEXT NOT NULL,
212 date TEXT NOT NULL,
213 time TEXT,
214 city TEXT NOT NULL,
215 venue TEXT,
216 country TEXT,
217 ticket_url TEXT,
218 notes TEXT,
219 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
220 );
221 CREATE INDEX IF NOT EXISTS idx_shows_site_date ON shows(site_id, date);
222 `);
223
[834bcc3]224 // Link-in-bio click statistics (premium #6). One counter per (site, url); the
225 // link-in-bio page links via /links/go/:i which counts the click and redirects.
[37edecd]226 db.exec(`
227 CREATE TABLE IF NOT EXISTS link_clicks (
228 site_id TEXT NOT NULL,
229 url TEXT NOT NULL,
230 clicks INTEGER DEFAULT 0,
231 updated_at DATETIME DEFAULT CURRENT_TIMESTAMP,
232 PRIMARY KEY (site_id, url)
233 );
234 `);
[535f955]235
[6bd25d1]236
237 // ── ActivityPub (fediverse bridge) ──────────────────────────
238 // RSA keypair per actor (Mastodon-compatible HTTP Signatures; separate from
239 // the Cirkels Ed25519 keys). ap_followers = remote AP actors following us.
240 db.exec(`
241 CREATE TABLE IF NOT EXISTS ap_keys (
242 slug TEXT PRIMARY KEY,
243 public_pem TEXT NOT NULL,
244 private_pem TEXT NOT NULL,
245 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
246 );
247 CREATE TABLE IF NOT EXISTS ap_followers (
248 id INTEGER PRIMARY KEY AUTOINCREMENT,
249 slug TEXT NOT NULL,
250 actor_uri TEXT NOT NULL,
251 inbox TEXT,
252 shared_inbox TEXT,
253 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
254 UNIQUE(slug, actor_uri)
255 );
256 CREATE INDEX IF NOT EXISTS idx_ap_followers_slug ON ap_followers(slug);
[c16e0a5]257 CREATE TABLE IF NOT EXISTS ap_interactions (
258 id INTEGER PRIMARY KEY AUTOINCREMENT,
259 kind TEXT NOT NULL, -- 'reply' | 'like' | 'announce'
260 post_id TEXT NOT NULL,
261 object_uri TEXT NOT NULL DEFAULT '', -- remote note id (reply) or '' (like/announce)
262 actor_uri TEXT NOT NULL,
263 actor_name TEXT,
264 actor_handle TEXT,
265 actor_url TEXT,
266 actor_icon TEXT,
267 content TEXT, -- sanitized HTML (reply)
268 published TEXT,
[7d932ce]269 parent_uri TEXT, -- the note this reply replies to (for nesting)
[c16e0a5]270 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
271 UNIQUE(kind, post_id, actor_uri, object_uri)
272 );
273 CREATE INDEX IF NOT EXISTS idx_ap_inter_post ON ap_interactions(post_id, kind);
[67c1f24]274 -- Moderation tombstones: object URIs the site owner removed. Checked at ingest
275 -- (handleInbox) AND by the thread-crawler, so a removed reply never comes back
276 -- via thread-filling. Private notes can't be flagged via authorize_interaction
277 -- (their fetch 401s), so owner moderation acts on the locally stored copy.
278 CREATE TABLE IF NOT EXISTS ap_rejected_objects (
279 object_uri TEXT PRIMARY KEY,
280 post_id TEXT,
281 reason TEXT,
282 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
283 );
[d49b60b]284 -- ActivityPub C2S (client-to-server): OAuth 2.0 for native/web clients (Shaer).
285 -- Public clients + PKCE (RFC 8252); tokens stored hashed; token is per user+site.
286 CREATE TABLE IF NOT EXISTS oauth_clients (
287 client_id TEXT PRIMARY KEY,
288 client_name TEXT,
289 redirect_uris TEXT NOT NULL, -- JSON array
290 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
291 );
292 CREATE TABLE IF NOT EXISTS oauth_codes (
293 code TEXT PRIMARY KEY,
294 client_id TEXT NOT NULL,
295 user_id TEXT NOT NULL,
296 site_slug TEXT NOT NULL,
297 redirect_uri TEXT NOT NULL,
298 code_challenge TEXT, -- PKCE S256 (verplicht voor public clients)
299 scope TEXT,
300 expires_at DATETIME NOT NULL,
301 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
302 );
303 CREATE TABLE IF NOT EXISTS oauth_tokens (
304 token_hash TEXT PRIMARY KEY, -- sha256(bearer); het token zelf slaan we nooit op
305 client_id TEXT NOT NULL,
306 user_id TEXT NOT NULL,
307 site_slug TEXT NOT NULL,
308 scope TEXT,
309 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
310 last_used_at DATETIME
311 );
[61e3daf]312 -- Paid posts (klonkt-demo-aki): the site owner's own Patreon campaign.
313 -- Secrets are encrypted at rest (CryptoBox). Never reuses the instance-level
314 -- patreon_* settings, which are Klonkt Premium's separate license flow.
315 CREATE TABLE IF NOT EXISTS paid_patreon (
316 site_id TEXT PRIMARY KEY,
317 client_id TEXT,
318 client_secret_enc TEXT,
319 campaign_id TEXT,
320 access_token_enc TEXT,
321 refresh_token_enc TEXT,
322 token_exp INTEGER, -- unix seconds
323 default_min_cents INTEGER DEFAULT 0,
324 updated_at DATETIME DEFAULT CURRENT_TIMESTAMP
325 );
[9e9e6f9]326 -- One row per passkey. NO patron identity is stored (design decision):
327 -- {passkey, site, proven cents, expiry}. Not traceable to a person.
328 CREATE TABLE IF NOT EXISTS paid_entitlements (
329 credential_id TEXT PRIMARY KEY, -- WebAuthn credential id (opaque, base64url)
330 site_id TEXT NOT NULL,
331 public_key TEXT NOT NULL, -- COSE public key, base64url
332 counter INTEGER DEFAULT 0,
333 transports TEXT,
334 min_cents INTEGER DEFAULT 0, -- the amount proven at link time
335 expires_at INTEGER NOT NULL, -- unix seconds; re-link after
336 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
337 );
[55bc7f9]338 CREATE TABLE IF NOT EXISTS ap_outbox (
339 id TEXT PRIMARY KEY, -- note path segment (uuid) → /ap/notes/<id>
340 site_slug TEXT NOT NULL,
341 post_id TEXT NOT NULL,
342 post_slug TEXT,
343 in_reply_to TEXT, -- remote status uri we reply to
344 to_actor TEXT, -- remote actor uri (mentioned)
345 to_handle TEXT,
346 content TEXT NOT NULL, -- sanitized HTML of our reply
347 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
348 );
349 CREATE INDEX IF NOT EXISTS idx_ap_outbox_post ON ap_outbox(post_id);
[3d37c67]350 -- Your like/boost state on a REMOTE post (the interact page), so those become toggles.
351 CREATE TABLE IF NOT EXISTS ap_my_reactions (
352 site_slug TEXT NOT NULL,
353 target_uri TEXT NOT NULL,
354 kind TEXT NOT NULL, -- 'like' | 'boost'
355 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
356 UNIQUE(site_slug, target_uri, kind)
357 );
[6bd25d1]358 `);
[7d932ce]359 ensureColumn('ap_interactions', 'parent_uri', 'TEXT'); // nesting (existing DBs)
[c745659]360 ensureColumn('ap_interactions', 'acted_boost', 'INTEGER DEFAULT 0'); // owner boosted this comment (🔁) → can undo
[3289a64]361 ensureColumn('ap_interactions', 'acted_like', 'INTEGER DEFAULT 0'); // owner liked this comment (⭐) → can undo
[914eb9f]362
363 // Fediverse CLIENT: accounts WE follow (outbound) + the home timeline of their posts.
364 db.exec(`
365 CREATE TABLE IF NOT EXISTS ap_following (
366 id INTEGER PRIMARY KEY AUTOINCREMENT,
367 slug TEXT NOT NULL, -- our site that follows
368 actor_uri TEXT NOT NULL, -- the followed account's actor id
369 handle TEXT, name TEXT, icon TEXT, url TEXT,
370 inbox TEXT, -- their inbox (for Create delivery / Undo)
371 follow_id TEXT, -- the Follow activity id we sent (Accept matching)
372 status TEXT DEFAULT 'pending', -- pending | accepted
373 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
374 UNIQUE(slug, actor_uri)
375 );
376 CREATE TABLE IF NOT EXISTS ap_timeline (
377 id TEXT NOT NULL, -- the remote note's AP id
378 slug TEXT NOT NULL, -- whose home timeline (our site)
379 author_uri TEXT, author_name TEXT, author_handle TEXT, author_icon TEXT, author_url TEXT,
380 content TEXT, url TEXT, published TEXT, media_json TEXT,
381 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
382 UNIQUE(slug, id)
383 );
384 CREATE INDEX IF NOT EXISTS idx_ap_timeline_slug ON ap_timeline(slug, published);
[f5c3870]385 CREATE TABLE IF NOT EXISTS ap_blocks (
386 id INTEGER PRIMARY KEY AUTOINCREMENT,
387 slug TEXT NOT NULL, -- our site that set the block
388 target TEXT NOT NULL, -- actor URI (actor block) or domain (domain block)
389 kind TEXT NOT NULL, -- 'actor' | 'domain'
390 label TEXT, -- display (@handle or domain)
391 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
392 UNIQUE(slug, target)
393 );
394 CREATE INDEX IF NOT EXISTS idx_ap_blocks_target ON ap_blocks(target);
[5a6a457]395 CREATE TABLE IF NOT EXISTS ap_delivery (
396 id INTEGER PRIMARY KEY AUTOINCREMENT,
397 slug TEXT NOT NULL, -- our site/actor that signs the delivery
398 inbox TEXT NOT NULL, -- recipient inbox URL
399 body TEXT NOT NULL, -- the activity JSON to POST
400 attempts INTEGER NOT NULL DEFAULT 0,
401 next_at DATETIME NOT NULL DEFAULT CURRENT_TIMESTAMP,
402 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
403 );
404 CREATE INDEX IF NOT EXISTS idx_ap_delivery_due ON ap_delivery(next_at);
[0403187]405 CREATE TABLE IF NOT EXISTS poll_votes (
406 id INTEGER PRIMARY KEY AUTOINCREMENT,
407 post_id INTEGER NOT NULL, -- our local poll post (posts.id)
408 actor_uri TEXT NOT NULL, -- the remote voter's AP actor URI
409 choice TEXT NOT NULL, -- the chosen option's name (matches poll_json options[].name)
410 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
411 UNIQUE(post_id, actor_uri, choice)
412 );
413 CREATE INDEX IF NOT EXISTS idx_poll_votes_post ON poll_votes(post_id);
[fe97cc3]414 CREATE TABLE IF NOT EXISTS ap_mentions (
415 id INTEGER PRIMARY KEY AUTOINCREMENT,
416 slug TEXT NOT NULL, -- our mentioned site/actor
417 object_uri TEXT NOT NULL, -- the remote note that mentions us
418 note_url TEXT, -- its human URL (open/interact)
419 actor_uri TEXT, actor_name TEXT, actor_handle TEXT, actor_icon TEXT, actor_url TEXT,
420 content TEXT, -- sanitized HTML snippet of the mentioning note
421 published TEXT,
422 created_at DATETIME DEFAULT CURRENT_TIMESTAMP,
423 UNIQUE(slug, object_uri)
424 );
425 CREATE INDEX IF NOT EXISTS idx_ap_mentions_slug ON ap_mentions(slug, created_at);
[737ea05]426 CREATE TABLE IF NOT EXISTS ap_reports (
427 id INTEGER PRIMARY KEY AUTOINCREMENT,
428 slug TEXT NOT NULL, -- our site the report is about (its owner moderates)
429 actor_uri TEXT, -- the reporter's actor URI
430 actor_name TEXT, actor_handle TEXT, actor_icon TEXT,
431 content TEXT, -- the reason (plain text)
432 objects TEXT, -- JSON array of reported object URIs (our actor + statuses)
433 seen INTEGER DEFAULT 0,
434 created_at DATETIME DEFAULT CURRENT_TIMESTAMP
435 );
436 CREATE INDEX IF NOT EXISTS idx_ap_reports_slug ON ap_reports(slug, created_at);
[914eb9f]437 `);
[5045c30]438 // "Feature" a followed account: its posts show in the local Cirkel.
[f278df9]439 ensureColumn('ap_following', 'auto_boost', 'INTEGER DEFAULT 0');
[5045c30]440 // A timeline post you boosted (🔁) — also shown in the Cirkel (mixed by date).
441 ensureColumn('ap_timeline', 'boosted', 'INTEGER DEFAULT 0');
[9d34855]442 ensureColumn('ap_timeline', 'liked', 'INTEGER DEFAULT 0'); // a feed post you liked (⭐) → toggle
[b7d4458]443 ensureColumn('ap_timeline', 'nsfw', 'INTEGER DEFAULT 0'); // remote sensitive post → blur in the Cirkel
444 ensureColumn('ap_timeline', 'cw', 'TEXT'); // remote content-warning text
[c6cdce6]445 ensureColumn('ap_timeline', 'reblog_name', 'TEXT'); // a followed account boosted this → "X boosted"
446 ensureColumn('ap_timeline', 'reblog_handle', 'TEXT'); // the booster's @handle
447 ensureColumn('ap_timeline', 'reblog_icon', 'TEXT'); // the booster's avatar
[6053c6c]448 ensureColumn('ap_timeline', 'poll_json', 'TEXT'); // a Question (poll): {multiple,options[{name,count}],endTime,closed,voters,voted}
[8878814]449
450 // Delivery health per follower → surface dead accounts for manual cleanup.
451 ensureColumn('ap_followers', 'last_delivery_at', 'DATETIME'); // last SUCCESSFUL delivery to this follower's inbox
452 ensureColumn('ap_followers', 'last_error_at', 'DATETIME'); // last time a delivery to it gave up (max retries)
[2d6a9c3]453
454 // ActivityPub `source` model: content_rendered = baked display HTML (#hashtags / URLs /
455 // @mentions linkified once at save). `content` stays the raw source used for editing and
456 // re-rendering. NULL on old posts → the render route bakes on the fly as a fallback.
457 ensureColumn('posts', 'content_rendered', 'TEXT');
[3778ddb]458
459 // AP addressing of an incoming interaction: 'public' | 'unlisted' | 'followers' | 'direct',
460 // derived from the note's to/cc at ingest. The public post page only renders public/unlisted
461 // replies; followers/direct replies surface in notifications (and later Messages) with post
462 // context instead. Existing rows default to 'public' (historically almost all were).
463 ensureColumn('ap_interactions', 'visibility', "TEXT DEFAULT 'public'");
[33e1dbd]464 // Rich replies: the reply's language (BCP47 code) → contentMap on the outgoing Note.
465 ensureColumn('ap_outbox', 'language', 'TEXT');
[feced2c]466 // Rich replies: JSON array [{url, mediaType, name}] → `attachment` on the Note.
467 ensureColumn('ap_outbox', 'attachments', 'TEXT');
[81b2e1e]468 ensureColumn('posts', 'ap_visibility', 'TEXT'); // public|quiet|friends|direct (C2S addressing, shaer-60b)
[928d1c7]469 ensureColumn('posts', 'paid', 'INTEGER DEFAULT 0'); // paid post (klonkt-demo-aki)
470 ensureColumn('posts', 'paid_min_cents', 'INTEGER'); // required support; null = owner default
[024f4f8]471 ensureColumn('ap_outbox', 'visibility', 'TEXT'); // 'direct' = private mention, never Public (shaer-tqc)
472 ensureColumn('ap_outbox', 'to_actors', 'TEXT'); // JSON array of recipient actor URIs for direct notes
[155c24e]473 ensureColumn('ap_outbox', 'help_request', 'INTEGER'); // FEP-633c shaer:helpRequest (ward's call for help)
[7922694]474 ensureColumn('ap_followers', 'name', 'TEXT'); // cached display name (shaer-aa3)
475 ensureColumn('ap_followers', 'handle', 'TEXT'); // @user@host
476 ensureColumn('ap_followers', 'icon', 'TEXT'); // avatar URL
[7bc636b]477}
478
479function ensureColumn(table, column, definition) {
480 try {
481 db.exec(`ALTER TABLE ${table} ADD COLUMN ${column} ${definition}`);
482 console.log(`🔧 Added column ${table}.${column}`);
483 } catch (e) {
484 // "duplicate column name" → already there. Anything else, surface it.
485 if (!/duplicate column/i.test(e.message)) {
486 console.error(`❌ ensureColumn(${table}.${column}):`, e.message);
487 }
488 }
489}
490
491export default db;
Note: See TracBrowser for help on using the repository browser.