Preserve bot follows when an account moves - #56
Conversation
Follow an alias-verified destination when a followed account sends a push-mode Move, then unfollow the origin and notify onFolloweeMove handlers. Route migrations to all following bots, including dynamic groups, and retry transient document failures without trusting embeds. Allow Follow, Accept, Reject, and Undo delivery between sibling bots so migrations to a local actor complete through real HTTP inboxes. Cover validation, retries, duplicates, callbacks, and delivery in both runtimes, and document the event's request and acceptance semantics. Design and implementation were AI-assisted, with independent design and code reviews. Validated with mise run test and mise run docs:build. Fixes fedify-dev#49 Assisted-by: OpenCode:deepseek-flash Assisted-by: Codex:gpt-6.1-sol Assisted-by: Claude Code:claude-fable-5-1 Assisted-by: Claude Code:claude-opus-5-5
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (14)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughBotKit now processes verified account moves for followed actors, migrates follows to verified target accounts, and provides an ChangesFollowee move handling
Same-instance follow delivery
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant InboxListener
participant InstanceImpl
participant DocumentLoader
participant SessionImpl
participant Bot
InboxListener->>InstanceImpl: Dispatch Move to onMoved
InstanceImpl->>DocumentLoader: Resolve old and destination actors
DocumentLoader-->>InstanceImpl: Return actor documents
InstanceImpl->>SessionImpl: Follow destination when needed
InstanceImpl->>SessionImpl: Unfollow old actor
InstanceImpl->>Bot: Invoke onFolloweeMove
Merge Risk: ⚪ Minimal · up to This change lets bots move their follows to an account's verified new address and allows follow-related activities between bots on the same instance. The review found no concrete defect that should block merging. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Destination verification and bot-specific ownership checks constrain migration. However, failed cleanup can leave local and remote follow relationships inconsistent without automatic recovery. Authorization of the original sender and coordination across multiple running instances remain incompletely established. Retained concerns
Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 9 files. (5 skipped: 5 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
🚀 New features to boost your workflow:
|
For a push-mode
Move, check the destination's own actor document for an alias back to the origin before following the destination and unfollowing the old account. Fetch remote destinations with a bot's signed loader instead of trusting embedded actors. Transient lookup failures can still be retried.Use the follow reverse index to migrate every affected bot, even for personal inbox delivery, because Fedify deduplicates queued activities across recipients. Allow
Follow/Accept/Reject/Undobetween sibling bots to support local destinations.onFolloweeMovereports the change; a new follow request may still await acceptance.Fixes #49.
Summary by CodeRabbit