Commit graph

170 commits

Author SHA1 Message Date
c736a269a8
Bump version: 0.3.10 → 0.3.11
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.11
2026-10-03 01:41:36 +02:00
ca4f22010f
feat(cache): add document cache with single-flight + adapter integration
- Add DocumentCache/DocumentStore (+ in-memory LRU and Redis backends)
- Add CachedResponse + ETag/Cache-Control helpers for dereference routes
- Wire cache + invalidation into handler, inbox/outbox, and web follow flows
- Add rate_limit_key and propagate bind_activitypub cache to handler
- Add DB storage memoization helpers and optional create_tables flag
2026-10-03 01:40:57 +02:00
96630660b2
Bump version: 0.3.9 → 0.3.10
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.10
2026-09-24 01:30:11 +02:00
cd818b4d13
fix: removed dead JSON-LD spec
Some ActivityPub implementations (e.g. Funkwhale) JSON-LD-expand every
fetched document and fetch remote contexts.

AP_CONTEXT included https://w3id.org/fep/0449, which returns 404 — so
/ap/actor was unparseable by some instances.
2026-09-24 01:29:57 +02:00
5a9d7984e7
Bump version: 0.3.8 → 0.3.9
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.9
2026-09-17 02:21:24 +02:00
d9f2bf1c1a
feat: add manual follow approvals with follow requests
- Add FollowPolicy + FollowRequest and inbox follow_policy callback
- Store pending follow requests in DB/file adapters; clear on Undo(Follow)
- Add follow resolution helpers to send Accept/Reject for pending requests
- Update docs and add tests for policies, storage, and follow helpers
2026-09-17 02:20:51 +02:00
f2f7512e94
perf(file-storage): optimize get_followers_of_targets lookups
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
- Read only target-prefixed follower files and verify target after parse
- Document file adapter behavior and add coverage for mixed targets
2026-09-15 01:05:56 +02:00
2571f92bd0
Bump version: 0.3.7 → 0.3.8
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.8
2026-09-15 00:23:37 +02:00
da27395c87
feat: support followable objects and bulk follower lookup
- Store Follow for local objects; drop non-local targets without Accept
- Add get_followers_of_targets() (DB IN query; base fallback)
- Update docs and tests for object-scoped follows and retrieval
2026-09-15 00:22:35 +02:00
40064b1e88
fix: default NodeInfo version and User-Agent to package __version__
- Make `software_version` and `user_agent` resolve to pubby.__version__
  by default
- Update docs and discovery tests to match new defaults
2026-09-14 23:53:49 +02:00
717aa5e721
Bump version: 0.3.6 → 0.3.7
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.7
2026-09-14 18:10:32 +02:00
1a40dc92bf
feat: add quote helpers and FEP-044f quote request/authorization builders
- Recognize quoteUri inbound and centralize quote target parsing
- Add pubby.quotes module for quote fields and public quote policy
- Add build_quote_request_activity and build_quote_authorization helpers
- Update docs and tests for the new quote utilities and flows
2026-09-14 18:10:07 +02:00
a17b3dff6f
Bump version: 0.3.5 → 0.3.6
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.6
2026-09-13 23:26:38 +02:00
86c3b7e93b
fix(inbox): bind verified signer to activity.actor, require headers
- reject activities whose HTTP signature keyId resolves to a different
  actor than activity.actor, unless the claimed actor's document lists
  the key in publicKey
- raise SignatureVerificationError when headers are missing instead of
  silently skipping verification; skip_verification=True remains the
  explicit opt-out
- document the relay limitation: forwarded bodies signed by a relay are
  rejected since pubby does not verify LD signatures
2026-09-13 23:26:11 +02:00
9bfab03fe3
Bump version: 0.3.4 → 0.3.5
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.5
2026-09-13 22:58:06 +02:00
8359f7089c
feat(inbox): retract followers on actor delete, add audience helpers
- remove the remote actor's follow record for the bound local actor
  when a Delete targets the actor's own document
- add pubby.audience with addressees, is_public and mentioned_actors
  covering to/cc/bto/bcc and all public aliases
- add opt-in strict_attribution on InboxProcessor and
  ActivityPubHandler to drop spoofed Create/Update objects before
  fetch, callback and storage
2026-09-13 22:57:50 +02:00
6c1dff08b9
Bump version: 0.3.3 → 0.3.4
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.4
2026-09-08 02:45:11 +02:00
149e3bdfe9
fix(content): preserve newlines as <br> in rendered HTML
- Normalize \r\n and \r to \n before escaping
- Update docs/changelog and add newline coverage tests
2026-09-08 02:44:48 +02:00
c3ba2b2bfd
Bump version: 0.3.2 → 0.3.3
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.3
2026-09-08 02:11:17 +02:00
61c8c9c0d9
feat: add module-level build_update_activity helper
- Add free-function Update builder that syncs audience and stamps updated
- Delegate OutboxProcessor.build_update_activity to the new helper
- Export helper and document usage; extend tests for behavior and delegation
2026-09-08 02:10:59 +02:00
34f7cec7c6
Bump version: 0.3.1 → 0.3.2
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.2
2026-09-07 23:29:41 +02:00
1eeb65ed0a
feat(outbox): add build_delete_activity function
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
- Export builder from pubby; make OutboxProcessor delegate to it
- Update docs and add tests for defaults, audiences, and delegation
2026-09-07 23:29:03 +02:00
29ac566c4a
Bump version: 0.3.0 → 0.3.1
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.1
2026-09-07 18:10:37 +02:00
2e6e29bb19
feat: add client inbox resolver and module activity builders
- add pubby.client with extract_actor_inbox/resolve_actor_inbox
- re-export resolver and new builders from top-level package
- refactor OutboxProcessor builders to wrap module-level helpers
- update docs and add tests for resolver and builders
2026-09-07 18:09:51 +02:00
b1acc72b81
Bump version: 0.2.23 → 0.3.0
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.3.0
2026-09-07 13:28:13 +02:00
78612fe3f4
feat: add pluggable delivery seam and inbox helpers
- deliver callable on OutboxProcessor/ActivityPubHandler replaces
 ThreadPoolExecutor fan-out for queue-based delivery
- collect_inboxes() exposes shared-inbox-preferred dedup collection
- deliver_activity() performs one signed POST, returns HTTP status
- publish_actor_update(document=...) accepts a prebuilt actor document
2026-09-07 13:27:49 +02:00
dcece6f7ba
feat: support federated media object fields and helpers
- Allow Object.url Link lists, attributed_to lists, and duration serialization
- Add content helpers: format_duration and set_object_content
- Prefer HTML Link when mapping object.url to Mastodon status url
- Update docs and tests for new media object shapes
2026-09-07 13:05:04 +02:00
2da4f3212a
feat: add key file bootstrap and async→sync DB URL conversion
- Add ensure_private_key_file helper and tests
- Add to_sync_url/DEFAULT_ASYNC_DRIVER_MAP; init_db_storage converts async URLs
- Document new helpers in README, ARCHITECTURE, and CHANGELOG
2026-09-07 12:43:59 +02:00
07eb436cdb
feat: add instance allow/block lists for federation
- add pubby.moderation helpers for domain normalization and policy checks
- enforce policy for inbound before signature verification and outbound delivery
- document new handler params and add moderation tests
2026-09-07 03:23:01 +02:00
4219409c58
Bump version: 0.2.22 → 0.2.23
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.2.23
2026-09-07 00:33:43 +02:00
a92706795e
feat(content): add pubby.content plain-text to ActivityPub HTML renderer
- Add RenderedContent, is_linkable_url, display_url, render_link_anchor,
  render_bio_html, render_post_html, build_hashtag_tags,
  render_verified_link, and property_value_attachment.
- Linkify http(s) URLs with trailing-punctuation/balanced-bracket handling.
- Render #hashtags as rel="tag" anchors via caller-provided hashtag_url.
- Provide PropertyValue attachment helper for verified profile links.
- Add tests/test_content.py with full behavior coverage.
- Document module in README, ARCHITECTURE.md, and CHANGELOG.md.
- Add .isort.cfg with black profile so isort and black agree on imports.
2026-09-07 00:33:10 +02:00
a079c629ff
Bump version: 0.2.21 → 0.2.22
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.2.22
2026-08-23 15:05:57 +02:00
ad1e9e042c
feat: multi-actor per-actor follower isolation
- Add target_actor_id to Follower/DbFollower for per-actor follower tracking.
- Filter get_followers(), remove_follower(), and get_followers_collection() by
 target actor.
- InboxProcessor extracts target actor from Follow.object; OutboxProcessor fans
 out to the publishing actor's followers only.
- Bump file storage schema to v4; follower paths include target_actor_id.
- Warn when remove_follower() is called without target_actor_id.
- Make FileActivityPubStorage.remove_follower() without target remove all
 matching follower files (matching DB behavior).
- Remove redundant target_actor_id from DB follower upsert update_columns.
- Document legacy-follower backfill in README and storage docstrings.
- Add tests for Undo/Follow isolation, v3->v4 migration, unassigned legacy
 inclusion, remove-all behavior, and _sanitize collision resistance.
2026-08-23 15:05:25 +02:00
5357812660
Merge pull request #1 from blacklight/copilot/fix-failing-github-actions-job-build
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
fix(tests): handle FastAPI _IncludedRouter in adapter structure test
2026-07-23 19:35:03 +01:00
copilot-swe-agent[bot]
234635a602
chore: remove build/ from tracking and add to .gitignore 2026-07-23 18:16:53 +00:00
copilot-swe-agent[bot]
bc03915e95
fix(tests): handle _IncludedRouter in test_fastapi_adapter_structure
FastAPI >= 0.115 stores included routers as _IncludedRouter objects in
app.routes (no .path attribute) instead of flattening them. Collect
paths from both direct routes and original_router.routes.
2026-07-23 18:13:54 +00:00
copilot-swe-agent[bot]
9fe6d8eae2
chore: plan for fixing test_fastapi_adapter_structure 2026-07-23 18:12:15 +00:00
copilot-swe-agent[bot]
b97b608f0f
Initial plan 2026-07-23 18:09:46 +00:00
822c90836f
Bump version: 0.2.20 → 0.2.21
Some checks failed
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
publish-pypi / publish (push) Has been cancelled
v0.2.21
2026-07-23 19:58:49 +02:00
b2047e1f31
fix(storage): Allow multiple replies/quotes per actor via object_id
- File adapter keys reply/quote files by object_id; add v3 migration to rename/write
- DB unique constraint and upsert keys now include object_id
- Update mention index entries to include object_id
2026-07-23 19:58:21 +02:00
e82d53bc04
Bump version: 0.2.19 → 0.2.20
Some checks failed
publish-pypi / publish (push) Has been cancelled
build / build (push) Has been cancelled
coverage / coverage (push) Has been cancelled
v0.2.20
2026-03-20 14:02:42 +01:00
1fef6e6900
fix(inbox): Reject non-object activities
Raise ActivityPubError when activity data is not a dict
2026-03-20 14:02:29 +01:00
97a145fee2
Bump version: 0.2.18 → 0.2.19
Some checks failed
build / build (push) Waiting to run
coverage / coverage (push) Waiting to run
publish-pypi / publish (push) Has been cancelled
v0.2.19
2026-03-20 13:20:07 +01:00
84dca734ff
docs(changelog): Updated CHANGELOG 2026-03-20 13:20:04 +01:00
a76a8ada4b
fix(outbox): Respect explicit to/cc and avoid DM follower fanout
- Preserve empty cc when to/cc provided; default only when unaddressed
- Fan out to follower inboxes only when activity targets followers/public
- Add tests for direct message and unlisted delivery behavior
2026-03-20 13:18:48 +01:00
42cece9a34
Bump version: 0.2.17 → 0.2.18
Some checks failed
build / build (push) Waiting to run
coverage / coverage (push) Waiting to run
publish-pypi / publish (push) Has been cancelled
v0.2.18
2026-03-20 08:55:26 +01:00
c719363adf
fix(inbox): Skip storing private/direct AP interactions
Some checks are pending
build / build (push) Waiting to run
coverage / coverage (push) Waiting to run
- Add _is_publicly_addressed check before storing Create interactions
- Private mentions/replies (no Public in to/cc) are not stored
- Unlisted posts (Public in cc) are still stored
- Callback still fires for all interactions (enables notifications)
- Document behavior in README under Interaction Callbacks
2026-03-20 01:44:35 +01:00
b52001ba0a
Bump version: 0.2.16 → 0.2.17
Some checks failed
build / build (push) Waiting to run
coverage / coverage (push) Waiting to run
publish-pypi / publish (push) Has been cancelled
v0.2.17
2026-03-19 21:58:20 +01:00
4f1e8c3de0
docs(changelog): Updated CHANGELOG 2026-03-19 21:58:18 +01:00
9eae846f12
fix: Sign actor GET fetches in inbox/outbox processors
Fixes fetch issues (401) with instances that enforce signed requests.

- Add HTTP Signature headers via sign_request for actor fetch requests
- Add tests asserting signing and signed headers are included
2026-03-19 21:56:39 +01:00