Files
indiekit-endpoint-activitypub/lib/mastodon/routes/timelines.js
Ricardo 2c0cfffd54 feat: add Mastodon Client API layer for Phanpy/Elk compatibility
Implement the Mastodon Client REST API (/api/v1/*, /api/v2/*) and OAuth2
server within the ActivityPub plugin, enabling Mastodon-compatible clients
to connect to the Fedify-based server.

Core features:
- OAuth2 with PKCE (S256) — app registration, authorization, token exchange
- Instance info + nodeinfo for client discovery
- Account lookup, verification, relationships, follow/unfollow/mute/block
- Home/public/hashtag timelines with cursor-based pagination
- Status viewing, creation, deletion, thread context
- Favourite, boost, bookmark interactions with AP federation
- Notifications with type filtering and pagination
- Search across accounts, statuses, and hashtags
- Markers for read position tracking
- Bookmarks and favourites collection lists
- 25+ stub endpoints preventing client errors on unimplemented features

Architecture:
- 24 new files under lib/mastodon/ (entities, helpers, middleware, routes)
- Virtual endpoint at "/" via Indiekit.addEndpoint() for domain-root access
- CORS + JSON error handling for browser-based clients
- Six-layer mute/block filtering reusing existing moderation infrastructure

BREAKING CHANGE: bumps to v3.0.0 — adds new MongoDB collections
(ap_oauth_apps, ap_oauth_tokens, ap_markers) and new route registrations

Confab-Link: http://localhost:8080/sessions/5360e3f5-b3cc-4bf3-8c31-5448e2b23947
2026-03-18 12:50:52 +01:00

282 lines
8.2 KiB
JavaScript

/**
* Timeline endpoints for Mastodon Client API.
*
* GET /api/v1/timelines/home — home timeline (authenticated)
* GET /api/v1/timelines/public — public/federated timeline
* GET /api/v1/timelines/tag/:hashtag — hashtag timeline
*/
import express from "express";
import { serializeStatus } from "../entities/status.js";
import { buildPaginationQuery, parseLimit, setPaginationHeaders } from "../helpers/pagination.js";
import { loadModerationData, applyModerationFilters } from "../../item-processing.js";
const router = express.Router(); // eslint-disable-line new-cap
// ─── GET /api/v1/timelines/home ─────────────────────────────────────────────
router.get("/api/v1/timelines/home", async (req, res, next) => {
try {
const token = req.mastodonToken;
if (!token) {
return res.status(401).json({ error: "The access token is invalid" });
}
const collections = req.app.locals.mastodonCollections;
const baseUrl = `${req.protocol}://${req.get("host")}`;
const limit = parseLimit(req.query.limit);
// Base filter: exclude context-only items and private/direct posts
const baseFilter = {
isContext: { $ne: true },
visibility: { $nin: ["direct"] },
};
// Apply cursor-based pagination
const { filter, sort, reverse } = buildPaginationQuery(baseFilter, {
max_id: req.query.max_id,
min_id: req.query.min_id,
since_id: req.query.since_id,
});
// Fetch items from timeline
let items = await collections.ap_timeline
.find(filter)
.sort(sort)
.limit(limit)
.toArray();
// Reverse if min_id was used (ascending sort → need descending order)
if (reverse) {
items.reverse();
}
// Apply mute/block filtering
const modCollections = {
ap_muted: collections.ap_muted,
ap_blocked: collections.ap_blocked,
ap_profile: collections.ap_profile,
};
const moderation = await loadModerationData(modCollections);
items = applyModerationFilters(items, moderation);
// Load interaction state (likes, boosts, bookmarks) for the authenticated user
const { favouritedIds, rebloggedIds, bookmarkedIds } = await loadInteractionState(
collections,
items,
);
// Serialize to Mastodon Status entities
const statuses = items.map((item) =>
serializeStatus(item, {
baseUrl,
favouritedIds,
rebloggedIds,
bookmarkedIds,
pinnedIds: new Set(),
}),
);
// Set pagination Link headers
setPaginationHeaders(res, req, items, limit);
res.json(statuses);
} catch (error) {
next(error);
}
});
// ─── GET /api/v1/timelines/public ───────────────────────────────────────────
router.get("/api/v1/timelines/public", async (req, res, next) => {
try {
const collections = req.app.locals.mastodonCollections;
const baseUrl = `${req.protocol}://${req.get("host")}`;
const limit = parseLimit(req.query.limit);
// Public timeline: only public visibility, no context items
const baseFilter = {
isContext: { $ne: true },
visibility: "public",
};
// Only original posts (exclude boosts from public timeline unless local=true)
if (req.query.only_media === "true") {
baseFilter.$or = [
{ "photo.0": { $exists: true } },
{ "video.0": { $exists: true } },
{ "audio.0": { $exists: true } },
];
}
const { filter, sort, reverse } = buildPaginationQuery(baseFilter, {
max_id: req.query.max_id,
min_id: req.query.min_id,
since_id: req.query.since_id,
});
let items = await collections.ap_timeline
.find(filter)
.sort(sort)
.limit(limit)
.toArray();
if (reverse) {
items.reverse();
}
// Apply mute/block filtering
const modCollections = {
ap_muted: collections.ap_muted,
ap_blocked: collections.ap_blocked,
ap_profile: collections.ap_profile,
};
const moderation = await loadModerationData(modCollections);
items = applyModerationFilters(items, moderation);
// Load interaction state if authenticated
let favouritedIds = new Set();
let rebloggedIds = new Set();
let bookmarkedIds = new Set();
if (req.mastodonToken) {
({ favouritedIds, rebloggedIds, bookmarkedIds } = await loadInteractionState(
collections,
items,
));
}
const statuses = items.map((item) =>
serializeStatus(item, {
baseUrl,
favouritedIds,
rebloggedIds,
bookmarkedIds,
pinnedIds: new Set(),
}),
);
setPaginationHeaders(res, req, items, limit);
res.json(statuses);
} catch (error) {
next(error);
}
});
// ─── GET /api/v1/timelines/tag/:hashtag ─────────────────────────────────────
router.get("/api/v1/timelines/tag/:hashtag", async (req, res, next) => {
try {
const collections = req.app.locals.mastodonCollections;
const baseUrl = `${req.protocol}://${req.get("host")}`;
const limit = parseLimit(req.query.limit);
const hashtag = req.params.hashtag;
const baseFilter = {
isContext: { $ne: true },
visibility: { $in: ["public", "unlisted"] },
category: hashtag,
};
const { filter, sort, reverse } = buildPaginationQuery(baseFilter, {
max_id: req.query.max_id,
min_id: req.query.min_id,
since_id: req.query.since_id,
});
let items = await collections.ap_timeline
.find(filter)
.sort(sort)
.limit(limit)
.toArray();
if (reverse) {
items.reverse();
}
// Load interaction state if authenticated
let favouritedIds = new Set();
let rebloggedIds = new Set();
let bookmarkedIds = new Set();
if (req.mastodonToken) {
({ favouritedIds, rebloggedIds, bookmarkedIds } = await loadInteractionState(
collections,
items,
));
}
const statuses = items.map((item) =>
serializeStatus(item, {
baseUrl,
favouritedIds,
rebloggedIds,
bookmarkedIds,
pinnedIds: new Set(),
}),
);
setPaginationHeaders(res, req, items, limit);
res.json(statuses);
} catch (error) {
next(error);
}
});
// ─── Helpers ─────────────────────────────────────────────────────────────────
/**
* Load interaction state (favourited, reblogged, bookmarked) for a set of timeline items.
*
* Queries ap_interactions for likes and boosts matching the items' UIDs.
*
* @param {object} collections - MongoDB collections
* @param {Array} items - Timeline items
* @returns {Promise<{ favouritedIds: Set<string>, rebloggedIds: Set<string>, bookmarkedIds: Set<string> }>}
*/
async function loadInteractionState(collections, items) {
const favouritedIds = new Set();
const rebloggedIds = new Set();
const bookmarkedIds = new Set();
if (!items.length || !collections.ap_interactions) {
return { favouritedIds, rebloggedIds, bookmarkedIds };
}
// Collect all UIDs and URLs to look up
const lookupUrls = new Set();
const urlToUid = new Map();
for (const item of items) {
if (item.uid) {
lookupUrls.add(item.uid);
urlToUid.set(item.uid, item.uid);
}
if (item.url && item.url !== item.uid) {
lookupUrls.add(item.url);
urlToUid.set(item.url, item.uid || item.url);
}
}
if (lookupUrls.size === 0) {
return { favouritedIds, rebloggedIds, bookmarkedIds };
}
const interactions = await collections.ap_interactions
.find({ objectUrl: { $in: [...lookupUrls] } })
.toArray();
for (const interaction of interactions) {
const uid = urlToUid.get(interaction.objectUrl) || interaction.objectUrl;
if (interaction.type === "like") {
favouritedIds.add(uid);
} else if (interaction.type === "boost") {
rebloggedIds.add(uid);
} else if (interaction.type === "bookmark") {
bookmarkedIds.add(uid);
}
}
return { favouritedIds, rebloggedIds, bookmarkedIds };
}
export default router;