Changeset 4407c67 in Klonkt for CHANGELOG.de.md


Ignore:
Timestamp:
07/19/2026 03:53:49 PM (7 weeks ago)
Author:
Robin <roboburr@…>
Branches:
main
Children:
2d66d66
Parents:
bf72108
git-author:
Robin <roboburr@…> (07/19/2026 03:53:33 PM)
git-committer:
Robin <roboburr@…> (07/19/2026 03:53:49 PM)
Message:

Feature: C2S owner can read own followers/following (klonkt-demo-6kc)

The followers and following collections stay count-only for the public
(privacy), but a request carrying a C2S bearer scoped to that site (the account
owner) now returns the real actor URIs, so a client (Shaer) can build a friends
list. This was the one gap keeping the Shaer app's orbit empty against a real
Klonkt (it worked against the shaer-daemon, which serves the full lists).

  • buildFollowers/buildFollowing take an optional items array: when present, orderedItems carries the URIs and totalItems reflects them; otherwise count-only as before.
  • The two GET routes verify a bearer (OAuth.verifyBearer) and, when it is scoped to the requested slug, return the full list from ap_followers.actor_uri / ap_following.actor_uri (status=accepted); everyone else gets count-only. A private site's owner can read it even when it is not publicly listed.

3 new builder tests (count-only vs owner items vs empty owner list); 83 green.
Live-verified: owner bearer -> real URIs (alice/bob) in orderedItems; no bearer
-> orderedItems empty with the count intact; a token for another slug does not
unlock it.

Co-Authored-By: Claude Opus 4.8 <noreply@…>

File:
1 edited

Legend:

Unmodified
Added
Removed
  • CHANGELOG.de.md

    rbf72108 r4407c67  
    77
    88### Hinzugefügt
     9- **Der Kontoinhaber kann seine eigenen Follower und Gefolgten über C2S lesen.**
     10  Die `followers`- und `following`-Sammlungen bleiben für die Öffentlichkeit
     11  count-only (Datenschutz), aber eine Anfrage mit einem auf diese Seite
     12  begrenzten C2S-Bearer liefert jetzt die echten Actor-URIs, damit eine App
     13  (Shaer) eine Freundesliste bauen kann. Für anonyme Aufrufer ändert sich
     14  nichts.
    915- **App-Zugriff über OAuth 2.0 (ActivityPub Client-to-Server, Phase 1).** Klonkt
    1016  spricht jetzt den standardmäßigen AP-C2S-Auth-Handshake, damit native und
Note: See TracChangeset for help on using the changeset viewer.