Skip to content

Like object embedding - #322

Merged
aaronjae22 merged 2 commits into
mainfrom
like-object-embedding
Oct 9, 2026
Merged

aaronjae22 merged 2 commits into
mainfrom
like-object-embedding

Conversation

@aaronjae22

Copy link
Copy Markdown
Collaborator

A few things left to solve on the like object and its collection.

  1. A Like was publishing another account's private Note. Basically when an actor likes a Note on this server, the Like activity embeds the whole Note, withouht taking into consideration that Note's visibility.

The outbox decides what an anonymous caller sees from the Like's visibility, not the Note's. So a public Like of someone else's private Note hands that Note to anyone who asks.

Tihs is an example. Bob writes a private Note, Alice likes it publicly. This is Alice's outbox providing Bob's private Note, fetched with no token:

{
  "type": "Note",
  "id": "<http://testserver/api/notes/1/>",
  "attributedTo": "<http://testserver/api/actors/2/>",
  "content": "BOB PRIVATE",
  "visibility": "private",
  "summary": "CW: a copied note",
  "to": ["<https://lemongrove.example/followers>"],
  "cc": ["<https://oakfrost.example/brock>"],
  "inReplyTo": "<https://lemongrove.example/notes/parent>",
  "url": "<https://lemongrove.example/@aurora/1>",
  "source": {
              "content": "copied",
              "mediaType": "text/markdown"
  },
 "previously": [
                  {
                    "actor": "<https://lemongrove.example/>",
                    "id": "<https://lemongrove.example/notes/1>"
                  }
              ]
}

Bob's own outbox correctly hides this Note. Alice's publishes all of it (the content, who it was sent to, its original markup and its history). The liked collection does the same for Alice's token.

This breaks LOLA §5's MUST that a grant reaches only its own account.

  1. When I first implementing the liked collection a while ago I wasn't sure which fields should be served but pretty much serves its own made-up version of a Note.

This is Alice's liked collection currently:

{
  "id": "<http://testserver/api/notes/1/>",
  "type": "Note",
  "attributedTo": "<http://testserver/api/actors/2/>",
  "summary": "CW: a copied note",
  "content": "BOB PRIVATE",
  "inReplyTo": null,
  "audience": {
                "public": false
              },
  "attachment": [],
  "canonicalUrl": "<http://testserver/api/notes/1/>",
  "objectHash": null
}

A few thing that were wrong

  • Content is cut to 280 characters.**
  • It serves keys that aren't AS2 such as canonicalUrl and objectHash. (Don't know where I got these two hahah they probably had a purpose but not anymore)

ActivityPub defines the liked collection as "a list of every object from all of the actor's Like activities". So a liked item and a Like's object are the same thing, and this PR gives them one builder build_like_object_json_ld.

@aaronjae22
aaronjae22 requested a review from lisad October 5, 2026 20:46
@aaronjae22 aaronjae22 self-assigned this Oct 5, 2026
@aaronjae22
aaronjae22 added this pull request to stack #321 October 5, 2026 20:46
@aaronjae22
aaronjae22 marked this pull request as ready for review October 5, 2026 20:46
@aaronjae22
aaronjae22 force-pushed the like-object-embedding branch from 674290e to 727e69c Compare October 9, 2026 16:07
Base automatically changed from object-metadata-serialization to main October 9, 2026 16:15
@aaronjae22
aaronjae22 merged commit dd33ea1 into main Oct 9, 2026
3 checks passed
@aaronjae22
aaronjae22 deleted the like-object-embedding branch October 9, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants