source: Klonkt/src/routes/guardian2.js@ 5c373b8

main
Last change on this file since 5c373b8 was 5c373b8, checked in by Robin <roboburr@…>, 7 weeks ago

Guardian 2: follow-goedkeuring (FEP-633c §5.3)

Een Follow op een ward wordt niet meer automatisch geaccepteerd: hij wacht op
goedkeuring van de guardians. Afgebakend zoals de spec: gating geldt ALLEEN voor
ward-actors (die guardians hebben); een gewone site zonder guardians accepteert
als vanouds, geen gedragswijziging. Een gecommitte guardian die zelf volgt wordt
wel meteen geaccepteerd (Barts regel: die heeft geen gate nodig, en zo werkt het
meekijken). Quorum per ward: 'any' (default, één volstaat), 'all' of 'none'; een
enkele reject weigert.

De guardian ziet de verzoeken in /guardian2 (ward en guardian zitten op dezelfde
familie-Klonkt, dus lokaal leesbaar) en tikt Accept/Deny. Bij goedkeuring stuurt
Klonkt de Accept(Follow) en legt de follower vast, zodat bezorging (ook
followers-only) begint. Cross-instance federatie van de goedkeuring is een latere
verfijning (de daemon heeft het patroon).

Changed files:
src/services/ActivityPubService.js

  • inbound Follow: gate voor ward-actors; acceptGatedFollow/rejectGatedFollow

src/config/database.js

  • ap_pending_follows + ap_pending_follow_approvals

src/services/guardianship/index.js

  • follows-module geexporteerd

src/routes/guardian2.js

  • GET /api/follow-requests, POST /api/follow/:id (guardian-gecheckt)

src/views/pages/guardian2.ejs, src/assets/js/guardian2.js

src/services/i18n.js

  • guardian2 follow_title/follow_sub (nl/en/de)

New file:
src/services/guardianship/follows.js

  • de gating-store + quorum-beslissing (any/all), pure en testbaar

test/follow-gating.test.js

  • any/all-quorum en single-reject

remarks: npm test 167/167. v1 /guardian en niet-ward-sites onaangeraakt.

-robo
Co-Authored-By: Claude Opus 4.8 <noreply@…>

  • Property mode set to 100644
File size: 16.3 KB
RevLine 
[c1f5c23]1/**
2 * The Guardian PWA (FEP-633c): a separate, installable corner of Klonkt for
3 * guardians. One place to add and manage wards, a message centre for
4 * incoming help requests and adoption traffic, and its own push channel
5 * (alert types 'help' and 'guardian', web-push slice reused).
6 *
7 * Everything is scoped to a site the logged-in user OWNS: the guardian acts
8 * as one of their own actors (?site=slug picks one when they own several).
9 * Views carry no inline scripts (CSP): logic lives in /assets/js/guardian.js.
10 */
11import express from 'express';
[05665bc]12import crypto from 'crypto';
13import bcrypt from 'bcryptjs';
[c1f5c23]14import path from 'path';
15import { fileURLToPath } from 'url';
16import db from '../config/database.js';
17import { requireAuth } from '../middleware/auth.js';
18import AP from '../services/ActivityPubService.js';
19import * as Guardianship from '../services/guardianship/index.js';
20import { t as i18nT, resolveLang } from '../services/i18n.js';
21import { injectCspNonce } from '../middleware/render.js';
22
23const router = express.Router();
24const __dir = path.dirname(fileURLToPath(import.meta.url));
25
26/** The acting site: ?site=slug when owned, else the user's first site. */
27function siteForUser(req) {
28 const userId = req.session.user.id;
29 const want = String(req.query.site || req.body?.site || '').trim();
30 if (want) {
31 const s = db.prepare('SELECT * FROM sites WHERE slug = ? AND owner_id = ?').get(want, userId);
32 if (s) return s;
33 }
34 return db.prepare('SELECT * FROM sites WHERE owner_id = ? ORDER BY id LIMIT 1').get(userId);
35}
36
37/** Everything the dashboard shows, one shape for page and API. */
38function uiStrings(L) {
39 const keys = ['sent', 'sent_retry', 'sending', 'not_found', 'failed', 'network',
40 'pending', 'active', 'retract', 'release', 'open', 'push_unavailable',
41 'accept', 'reject', 'complete', 'awaiting_others', 'coguard'];
42 return Object.fromEntries(keys.map((k) => [k, i18nT(L, `guardian.${k}`)]));
43}
44
45function dashboardState(site, L) {
46 const base = (process.env.PUBLIC_BASE_URL || '').replace(/\/+$/, '');
47 const me = AP.actorId(base, site.slug);
48 const help = db.prepare(
49 `SELECT object_uri, note_url, actor_uri, actor_name, actor_handle, actor_icon, content, published, created_at
50 FROM ap_mentions WHERE slug = ? AND help_request = 1 ORDER BY created_at DESC LIMIT 50`
51 ).all(site.slug);
52 return {
53 site: site.slug,
54 me,
55 wards: Guardianship.listWards(site.slug), // committed wards
56 offers: Guardianship.offersCollection(`${me}/queues/offers`, site.slug, me).orderedItems,
57 help,
58 strings: uiStrings(L),
59 };
60}
61
62// ── The PWA page ─────────────────────────────────────────────────────────
63router.get('/', requireAuth, (req, res) => {
64 const site = siteForUser(req);
65 const L = resolveLang(req);
66 if (!site) return res.status(404).send('No site for this account.');
67 const sites = db.prepare('SELECT slug, title FROM sites WHERE owner_id = ? ORDER BY id').all(req.session.user.id);
68 // This standalone PWA page is rendered directly (not through renderPage), so
69 // the CSP nonce must be injected here — otherwise strict-dynamic blocks
70 // guardian.js and the whole dashboard is dead (buttons do nothing).
71 res.render('pages/guardian2', {
72 state: dashboardState(site, L),
73 sites,
74 lang: L,
75 t: (k, v) => i18nT(L, k, v),
76 cspNonce: res.locals.cspNonce,
77 }, (err, html) => {
78 if (err) { console.error('[guardian] render error', err); return res.status(500).send('Internal Server Error'); }
79 res.send(injectCspNonce(html, res.locals.cspNonce));
80 });
81});
82
83// ── JSON state for refreshes ─────────────────────────────────────────────
84router.get('/api/state', requireAuth, (req, res) => {
85 const site = siteForUser(req);
86 if (!site) return res.status(404).json({ error: 'no_site' });
87 res.json(dashboardState(site, resolveLang(req)));
88});
89
[28267519]90// ── Meekijken (FEP-633c §5, interop-hoofdroute): a committed guardian FOLLOWS
91// its wards, so their posts (incl. followers-only) are DELIVERED to the
92// guardian's inbox → timeline. The follow is the mechanism; no new fetch.
93// First contact also backfills the ward's recent PUBLIC posts as a cold
94// start so the corner is not empty before delivery catches up.
95function ensureWardConnections(site) {
96 let wards;
97 try { wards = Guardianship.listWards(site.slug); } catch { return; }
98 for (const w of wards) {
99 const already = db.prepare('SELECT 1 FROM ap_following WHERE slug = ? AND actor_uri = ?')
100 .get(site.slug, w.other_uri);
101 if (already) continue;
102 // Follow (guardian's server auto-accepts today; §5.3 gating is a later fase).
103 AP.followActor(site, w.other_uri).catch(() => { /* retried by the queue */ });
104 // Cold start: pull recent public posts now so oma sees something at once.
105 AP.backfillFromOutbox(site.slug, w.other_uri).catch(() => { /* best-effort */ });
106 }
107}
108
109// ── The wards' corner: your wards' posts, read-only. No reply, no share; a
110// guardian watches, it does not publish (Robins besluit).
111router.get('/api/feed', requireAuth, (req, res) => {
112 const site = siteForUser(req);
113 if (!site) return res.status(404).json({ error: 'no_site' });
114 ensureWardConnections(site);
115 const wardUris = new Set(Guardianship.listWards(site.slug).map((w) => w.other_uri));
116 // Only show the wards you actually guard (the timeline can hold more).
117 const items = AP.getTimeline(site.slug, 60, 0)
118 .filter((p) => wardUris.has(p.author_uri))
119 .map((p) => ({
120 id: p.id,
121 author: p.author_handle || p.author_name || p.author_uri,
122 authorName: p.author_name,
123 authorIcon: p.author_icon,
124 content: p.content,
125 url: p.url,
126 published: p.published || p.created_at,
127 cw: p.cw || null,
128 media: p.media_json ? JSON.parse(p.media_json) : [],
129 }));
130 res.json({ items, following: wardUris.size });
131});
132
[5c373b8]133// ── Follow-gating (FEP-633c §5.3): pending follows on MY wards, for me to
134// approve. Ward and guardian are co-located on the family Klonkt here, so
135// the guardian reads its wards' pending follows locally.
136function wardSlugsOf(site) {
137 const base = (process.env.PUBLIC_BASE_URL || '').replace(/\/+$/, '');
138 return Guardianship.listWards(site.slug)
139 .map((w) => (w.other_uri.startsWith(base) ? w.other_uri.split('/').pop() : null))
140 .filter(Boolean);
141}
142
143router.get('/api/follow-requests', requireAuth, (req, res) => {
144 const site = siteForUser(req);
145 if (!site) return res.status(404).json({ error: 'no_site' });
146 const items = [];
147 for (const wardSlug of wardSlugsOf(site)) {
148 for (const f of Guardianship.follows.listForWard(wardSlug)) {
149 items.push({ id: f.id, ward: wardSlug, follower: f.follower_handle || f.follower_name || f.follower_uri, followerIcon: f.follower_icon, created: f.created_at });
150 }
151 }
152 res.json({ items });
153});
154
155router.post('/api/follow/:id', requireAuth, express.json({ limit: '4kb' }), async (req, res) => {
156 const site = siteForUser(req);
157 if (!site) return res.status(404).json({ error: 'no_site' });
158 const base = (process.env.PUBLIC_BASE_URL || '').replace(/\/+$/, '');
159 const me = AP.actorId(base, site.slug);
160 const decision = req.body?.decision === 'reject' ? 'reject' : 'approve';
161 const pending = Guardianship.follows.getPending(req.params.id);
162 if (!pending) return res.status(404).json({ error: 'gone' });
163 // I must actually be a guardian of this ward.
164 const guardians = Guardianship.listGuardians(pending.ward_slug).map((g) => g.other_uri);
165 if (!guardians.includes(me)) return res.status(403).json({ error: 'not_a_guardian' });
166 const r = Guardianship.follows.decide(pending.id, me, decision, guardians);
167 try {
168 if (r.outcome === 'approved') { await AP.acceptGatedFollow(r.follow); Guardianship.follows.remove(r.follow.id); }
169 else if (r.outcome === 'rejected') { await AP.rejectGatedFollow(r.follow); Guardianship.follows.remove(r.follow.id); }
170 } catch (e) { return res.status(502).json({ error: 'delivery', outcome: r.outcome }); }
171 res.json({ ok: true, outcome: r.outcome });
172});
173
[c1f5c23]174// ── Adopt a ward: handle → resolve → C2S Offer through the same pipeline
175// the Shaer apps use (one path, one behavior).
176router.post('/adopt', requireAuth, express.json({ limit: '4kb' }), async (req, res) => {
177 const site = siteForUser(req);
178 if (!site) return res.status(404).json({ error: 'no_site' });
179 const handle = String(req.body?.handle || '').trim();
180 if (!handle) return res.status(400).json({ error: 'empty_handle' });
181 const wardUri = /^https?:\/\//i.test(handle) ? handle : await AP.webfingerResolve(handle).catch(() => null);
182 if (!wardUri) return res.status(404).json({ error: 'not_found' }); // the handle does not resolve to an account
183 const base = (process.env.PUBLIC_BASE_URL || '').replace(/\/+$/, '');
184 const me = AP.actorId(base, site.slug);
185 const r = await AP.ingestOutboxActivity(site, req.session.user, {
186 type: 'Offer',
187 object: { type: 'Relationship', subject: wardUri, relationship: 'shaer:Guardian', object: me },
188 });
189 // 403/400 = a real refusal (e.g. you are a ward yourself); anything else the
190 // offer is recorded and delivery is retried in the background.
191 if (!r || (r.status >= 400 && r.status !== 502)) return res.status(r?.status || 500).json({ error: r?.error || 'offer_failed' });
192 res.json({ ok: true, ward: wardUri, delivered: r.delivered !== false });
193});
194
195// ── Answer an offer (co-guardian accept/reject, or the candidate's final
196// "complete"). All three are a C2S Accept/Reject on the offer id; the
197// handshake module decides when it commits (§3.1).
198router.post('/offer', requireAuth, express.json({ limit: '4kb' }), async (req, res) => {
199 const site = siteForUser(req);
200 if (!site) return res.status(404).json({ error: 'no_site' });
201 const offerId = String(req.body?.offer || '').trim();
202 const answer = req.body?.answer === 'reject' ? 'Reject' : 'Accept';
203 if (!offerId) return res.status(400).json({ error: 'empty_offer' });
204 const r = await AP.ingestOutboxActivity(site, req.session.user, { type: answer, object: offerId });
205 if (!r || r.status >= 400) return res.status(r?.status || 500).json({ error: r?.error || 'answer_failed' });
206 res.json({ ok: true, committed: !!r.committed, readyToCommit: !!r.readyToCommit });
207});
208
209// ── PWA assets served no-cache, so an update is never masked by the 1-year
210// /assets cache or a stuck install (that was the whole "nothing works after
211// a deploy" bug). Small files; the browser revalidates and gets a 304 when
212// unchanged, the fresh file when changed.
213function pwaAsset(rel, type) {
214 return (req, res) => {
215 res.set('Cache-Control', 'no-cache');
216 res.type(type);
217 res.sendFile(path.join(__dir, '..', 'assets', rel));
218 };
219}
220router.get('/app.js', pwaAsset('js/guardian2.js', 'application/javascript'));
221router.get('/app.css', pwaAsset('css/guardian2.css', 'text/css'));
222
223// ── Manage: release a committed ward (local Undo; federation is Fase 4). ──
224router.post('/wards/remove', requireAuth, express.json({ limit: '4kb' }), (req, res) => {
225 const site = siteForUser(req);
226 if (!site) return res.status(404).json({ error: 'no_site' });
227 const uri = String(req.body?.uri || '').trim();
228 if (!uri) return res.status(400).json({ error: 'empty_uri' });
229 Guardianship.removeRelation(site.slug, 'guardian', uri);
230 res.json({ ok: true });
231});
232
233// ── The installable identity: own scope so the Guardian corner installs as
234// its own app next to the site PWA.
235router.get('/manifest.webmanifest', (req, res) => {
236 const site = res.locals.site;
237 res.set('Cache-Control', 'no-cache');
238 res.json({
239 id: `klonkt-guardian2-${site?.slug || 'guardian'}`,
240 name: 'Klonkt Guardian',
241 short_name: 'Guardian 2',
242 description: 'Ward management and help requests for guardians.',
243 scope: '/guardian2/',
244 start_url: '/guardian?source=pwa',
245 display: 'standalone',
246 display_override: ['standalone', 'minimal-ui'],
247 orientation: 'any',
248 background_color: '#141a24',
249 theme_color: '#ff6b35',
250 lang: site?.language || 'nl',
251 icons: [
252 { src: '/guardian2/icon.svg', sizes: 'any', type: 'image/svg+xml' },
253 ],
254 });
255});
256
257// The buoy mark, in the guardian accent (mirrors the site favicon pattern).
258router.get('/icon.svg', (req, res) => {
259 const svg = `<?xml version="1.0" encoding="UTF-8"?>
260<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 64 64">
261 <rect width="64" height="64" rx="14" fill="#ff6b35"/>
262 <text x="50%" y="50%" dy="0.35em" text-anchor="middle" font-size="36">&#128735;</text>
263</svg>`;
264 res.set('Content-Type', 'image/svg+xml');
265 res.set('Cache-Control', 'public, max-age=86400');
266 res.send(svg);
267});
268
[05665bc]269// ── Losse guardians (Guardian 2): uitnodigen en aansluiten ───────────────
270// De familie nodigt oma uit; zij kiest naam + wachtwoord en heeft daarmee een
271// guardian-only account: user + minimale site (guardian_only=1). Alles wat al
272// per slug werkt (actor, inbox, offers, push, deze PWA) werkt dan meteen.
273
274router.post('/invite', requireAuth, (req, res) => {
275 const token = crypto.randomBytes(16).toString('base64url');
276 db.prepare('INSERT INTO ap_guardian_invites (token, created_by) VALUES (?,?)')
277 .run(token, req.session.user.id);
278 const base = (process.env.PUBLIC_BASE_URL || '').replace(/\/+$/, '');
279 const url = `${base}/guardian2/join/${token}`;
280 res.send(`<!doctype html><meta charset="utf-8"><body style="font-family:sans-serif;max-width:480px;margin:40px auto">
281 <h2>Invite a guardian</h2>
282 <p>Share this link. It lets one person create a guardian account here:</p>
283 <p><a href="${url}">${url}</a></p>
284 <p><a href="/guardian2">Back</a></p></body>`);
285});
286
287function joinForm(token, error) {
288 return `<!doctype html><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1">
289 <body style="font-family:sans-serif;max-width:420px;margin:40px auto">
290 <h2>Become a guardian</h2>
291 <p>Watch over someone you care about. Pick a name and a password; that is all.</p>
292 ${error ? `<p style="color:#b00">${error}</p>` : ''}
293 <form method="post" action="/guardian2/join/${token}">
294 <p><input name="name" placeholder="your name (grandma)" required pattern="[a-z0-9_-]{1,32}"
295 style="width:100%;padding:10px" autocapitalize="none"></p>
296 <p><input name="password" type="password" placeholder="password" required minlength="8"
297 style="width:100%;padding:10px"></p>
298 <p><button style="width:100%;padding:12px">Create my guardian account</button></p>
299 </form></body>`;
300}
301
302router.get('/join/:token', (req, res) => {
303 const inv = db.prepare('SELECT * FROM ap_guardian_invites WHERE token = ? AND used_at IS NULL')
304 .get(req.params.token);
305 if (!inv) return res.status(404).send('This invite is no longer valid.');
306 res.send(joinForm(req.params.token));
307});
308
309router.post('/join/:token', express.urlencoded({ extended: false }), (req, res) => {
310 const inv = db.prepare('SELECT * FROM ap_guardian_invites WHERE token = ? AND used_at IS NULL')
311 .get(req.params.token);
312 if (!inv) return res.status(404).send('This invite is no longer valid.');
313 const name = String(req.body.name || '').trim().toLowerCase();
314 const password = String(req.body.password || '');
315 if (!/^[a-z0-9_-]{1,32}$/.test(name)) return res.status(400).send(joinForm(req.params.token, 'Only lowercase letters, digits, - and _.'));
316 if (password.length < 8) return res.status(400).send(joinForm(req.params.token, 'Password: at least 8 characters.'));
317 if (db.prepare('SELECT 1 FROM sites WHERE slug = ?').get(name) || db.prepare('SELECT 1 FROM users WHERE username = ?').get(name)) {
318 return res.status(409).send(joinForm(req.params.token, 'That name is taken, pick another.'));
319 }
320 const userId = crypto.randomUUID();
321 db.prepare('INSERT INTO users (id, username, email, password_hash, role) VALUES (?,?,?,?,?)')
322 .run(userId, name, `${name}@guardian.invalid`, bcrypt.hashSync(password, 10), 'member');
323 db.prepare('INSERT INTO sites (id, slug, title, owner_id, is_primary, guardian_only) VALUES (?,?,?,?,0,1)')
324 .run(crypto.randomUUID(), name, name, userId);
325 db.prepare('UPDATE ap_guardian_invites SET used_by = ?, used_at = CURRENT_TIMESTAMP WHERE token = ?')
326 .run(userId, req.params.token);
327 req.session.user = { id: userId, username: name, role: 'member' };
328 res.redirect('/guardian2');
329});
330
[c1f5c23]331export default router;
Note: See TracBrowser for help on using the repository browser.