- Add DocumentCache/DocumentStore (+ in-memory LRU and Redis backends)
- Add CachedResponse + ETag/Cache-Control helpers for dereference routes
- Wire cache + invalidation into handler, inbox/outbox, and web follow flows
- Add rate_limit_key and propagate bind_activitypub cache to handler
- Add DB storage memoization helpers and optional create_tables flag
Some ActivityPub implementations (e.g. Funkwhale) JSON-LD-expand every
fetched document and fetch remote contexts.
AP_CONTEXT included https://w3id.org/fep/0449, which returns 404 — so
/ap/actor was unparseable by some instances.
- Add FollowPolicy + FollowRequest and inbox follow_policy callback
- Store pending follow requests in DB/file adapters; clear on Undo(Follow)
- Add follow resolution helpers to send Accept/Reject for pending requests
- Update docs and add tests for policies, storage, and follow helpers
- Store Follow for local objects; drop non-local targets without Accept
- Add get_followers_of_targets() (DB IN query; base fallback)
- Update docs and tests for object-scoped follows and retrieval
- Recognize quoteUri inbound and centralize quote target parsing
- Add pubby.quotes module for quote fields and public quote policy
- Add build_quote_request_activity and build_quote_authorization helpers
- Update docs and tests for the new quote utilities and flows
- reject activities whose HTTP signature keyId resolves to a different
actor than activity.actor, unless the claimed actor's document lists
the key in publicKey
- raise SignatureVerificationError when headers are missing instead of
silently skipping verification; skip_verification=True remains the
explicit opt-out
- document the relay limitation: forwarded bodies signed by a relay are
rejected since pubby does not verify LD signatures
- remove the remote actor's follow record for the bound local actor
when a Delete targets the actor's own document
- add pubby.audience with addressees, is_public and mentioned_actors
covering to/cc/bto/bcc and all public aliases
- add opt-in strict_attribution on InboxProcessor and
ActivityPubHandler to drop spoofed Create/Update objects before
fetch, callback and storage
- Add free-function Update builder that syncs audience and stamps updated
- Delegate OutboxProcessor.build_update_activity to the new helper
- Export helper and document usage; extend tests for behavior and delegation
- add pubby.client with extract_actor_inbox/resolve_actor_inbox
- re-export resolver and new builders from top-level package
- refactor OutboxProcessor builders to wrap module-level helpers
- update docs and add tests for resolver and builders
- deliver callable on OutboxProcessor/ActivityPubHandler replaces
ThreadPoolExecutor fan-out for queue-based delivery
- collect_inboxes() exposes shared-inbox-preferred dedup collection
- deliver_activity() performs one signed POST, returns HTTP status
- publish_actor_update(document=...) accepts a prebuilt actor document
- Allow Object.url Link lists, attributed_to lists, and duration serialization
- Add content helpers: format_duration and set_object_content
- Prefer HTML Link when mapping object.url to Mastodon status url
- Update docs and tests for new media object shapes
- add pubby.moderation helpers for domain normalization and policy checks
- enforce policy for inbound before signature verification and outbound delivery
- document new handler params and add moderation tests
- Add RenderedContent, is_linkable_url, display_url, render_link_anchor,
render_bio_html, render_post_html, build_hashtag_tags,
render_verified_link, and property_value_attachment.
- Linkify http(s) URLs with trailing-punctuation/balanced-bracket handling.
- Render #hashtags as rel="tag" anchors via caller-provided hashtag_url.
- Provide PropertyValue attachment helper for verified profile links.
- Add tests/test_content.py with full behavior coverage.
- Document module in README, ARCHITECTURE.md, and CHANGELOG.md.
- Add .isort.cfg with black profile so isort and black agree on imports.
- Add target_actor_id to Follower/DbFollower for per-actor follower tracking.
- Filter get_followers(), remove_follower(), and get_followers_collection() by
target actor.
- InboxProcessor extracts target actor from Follow.object; OutboxProcessor fans
out to the publishing actor's followers only.
- Bump file storage schema to v4; follower paths include target_actor_id.
- Warn when remove_follower() is called without target_actor_id.
- Make FileActivityPubStorage.remove_follower() without target remove all
matching follower files (matching DB behavior).
- Remove redundant target_actor_id from DB follower upsert update_columns.
- Document legacy-follower backfill in README and storage docstrings.
- Add tests for Undo/Follow isolation, v3->v4 migration, unassigned legacy
inclusion, remove-all behavior, and _sanitize collision resistance.
FastAPI >= 0.115 stores included routers as _IncludedRouter objects in
app.routes (no .path attribute) instead of flattening them. Collect
paths from both direct routes and original_router.routes.
- File adapter keys reply/quote files by object_id; add v3 migration to rename/write
- DB unique constraint and upsert keys now include object_id
- Update mention index entries to include object_id
- Preserve empty cc when to/cc provided; default only when unaddressed
- Fan out to follower inboxes only when activity targets followers/public
- Add tests for direct message and unlisted delivery behavior
- Add _is_publicly_addressed check before storing Create interactions
- Private mentions/replies (no Public in to/cc) are not stored
- Unlisted posts (Public in cc) are still stored
- Callback still fires for all interactions (enables notifications)
- Document behavior in README under Interaction Callbacks
Fixes fetch issues (401) with instances that enforce signed requests.
- Add HTTP Signature headers via sign_request for actor fetch requests
- Add tests asserting signing and signed headers are included