Feature: C2S owner can read own followers/following (klonkt-demo-6kc)
The followers and following collections stay count-only for the public
(privacy), but a request carrying a C2S bearer scoped to that site (the account
owner) now returns the real actor URIs, so a client (Shaer) can build a friends
list. This was the one gap keeping the Shaer app's orbit empty against a real
Klonkt (it worked against the shaer-daemon, which serves the full lists).
- buildFollowers/buildFollowing take an optional items array: when present,
orderedItems carries the URIs and totalItems reflects them; otherwise
count-only as before.
- The two GET routes verify a bearer (OAuth.verifyBearer) and, when it is scoped
to the requested slug, return the full list from ap_followers.actor_uri /
ap_following.actor_uri (status=accepted); everyone else gets count-only. A
private site's owner can read it even when it is not publicly listed.
3 new builder tests (count-only vs owner items vs empty owner list); 83 green.
Live-verified: owner bearer -> real URIs (alice/bob) in orderedItems; no bearer
-> orderedItems empty with the count intact; a token for another slug does not
unlock it.
Co-Authored-By: Claude Opus 4.8 <noreply@…>