- Fedify already verifies signatures and signer/actor match. Also require the object to be attributed to the actor and to be of a supported type.
- Ensure remote
instances/actors rows; promote the object to resources and store Create in activities.
- Add a nullable
activity_deliveries.activity_id referencing activities.id, and expose an Activity.deliveries connection.
- Link the deliveries of each persisted remote activity to it. Deliveries keep the payload as observed; those without a valid activity ID stay unlinked.
- Unverified input claiming an existing IRI must never overwrite a stored activity.
- Test with a signed
Create, an unverified request claiming a stored activity's IRI, and a request without an activity ID.
Tracks the FIXME in the inbox listener in packages/graphql/src/federation.ts.
The scope above was agreed in the #101 review thread.
AI disclosure
The user asked Claude Code (claude-fable-5-1) to survey every FIXME comment in the codebase and draft an issue for each, and Claude Code (claude-opus-5-5) to draft a revision based on the review discussion on #101. The user read and edited the drafts, then directed Claude Code to file them through the GitHub CLI.
instances/actorsrows; promote the object toresourcesand storeCreateinactivities.activity_deliveries.activity_idreferencingactivities.id, and expose anActivity.deliveriesconnection.Create, an unverified request claiming a stored activity's IRI, and a request without an activity ID.Tracks the
FIXMEin the inbox listener in packages/graphql/src/federation.ts.The scope above was agreed in the #101 review thread.
AI disclosure
The user asked Claude Code (claude-fable-5-1) to survey every
FIXMEcomment in the codebase and draft an issue for each, and Claude Code (claude-opus-5-5) to draft a revision based on the review discussion on #101. The user read and edited the drafts, then directed Claude Code to file them through the GitHub CLI.