Skip to content

Add FEP-6757 content license metadata - #1241

Open
dahlia wants to merge 1 commit into
fedify-dev:mainfrom
dahlia:vocab/fep-6757
Open

dahlia wants to merge 1 commit into
fedify-dev:mainfrom
dahlia:vocab/fep-6757

Conversation

@dahlia

@dahlia dahlia commented Oct 5, 2026

Copy link
Copy Markdown
Member

Adds FEP-6757 licenses to Object and Link, and preferredLicense to the five actor types. Uses the non-functional redundantProperties from #1215 and the bundled context from #1216.

Fixes #1212.

Value type

Values use a new fedify:absoluteIri range instead of xsd:anyURI. The stock decoder resolves values against the object's ID, so an SPDX identifier like "CC-BY-4.0" would become https://social.example/note/CC-BY-4.0. It also rejects literals, and the FEP's own schema:license example expands to a literal, so the whole Note failed to parse. Like xsd:anyURI, the new range writes @id. It also reads string literals, never resolves against a base, and skips values that are not absolute.

Synonyms

https://schema.org/license and cc:license are read as fallbacks when license is absent; their values are never merged or written. http://schema.org/license is excluded because PeerTube uses it for non-URI licence objects, and reading those would drop the cached input of each affected video.

Context detection

Every activity's default context includes identity/v1. Without the FEP context, its dc prefix made license inside Create compact to dc:license. extraContext detection now also runs before compaction, scanning expanded keys and child @context values, with the post-compaction scan kept as a fallback. The usual case now needs one compaction instead of two.

Known limits

A cached child that defines license through a prefix in its own inline context can still compact to dc:license. Skipping a signed object's license value, or re-serializing it inside a new activity, drops the generic JSON-LD cache, so its proof no longer verifies. Tests pin down both signature cases; changing the cache is out of scope.

Give ActivityStreams objects and links an explicit copyright license, as
proposed by the FEP-6757 draft, so that publishers can state what they
allow and consumers can tell what they may do with received content.

Object and Link gain non-functional licenses written as the Dublin Core
license property.  The Schema.org and Creative Commons license
properties are read as synonyms when it is absent, but never merged
with it or written.  The five actor types gain a functional
preferredLicense, which is a default for new objects and not a
fallback for unlicensed ones.  Fedify does not synthesize a default
license and never fetches a license URI.

http://schema.org/license is deliberately not a synonym: PeerTube uses
it for licence descriptions that are not URIs, and reading them would
drop the cached input of every PeerTube video that has one.

License values use a new fedify:absoluteIri range.  It writes IRI
references like xsd:anyURI, but also reads string literals, which the
FEP's own schema:license example produces, and never resolves a value
against the object's ID, so license names and SPDX identifiers are
skipped instead of becoming URLs on the publisher's server.

The extraContext detection now also scans the values before compaction.
Activity contexts include https://w3id.org/identity/v1, whose dc prefix
otherwise compacted license to dc:license in every Create without the
FEP context, which plain JSON consumers would not recognize.  This also
avoids compacting a licensed object twice in the common case.

Fixes fedify-dev#1212

Assisted-by: Claude Code:claude-opus-5-5
Assisted-by: Codex:gpt-6-astra
Assisted-by: Claude Code:claude-fable-5-1
@dahlia dahlia added this to the Fedify 2.5 milestone Oct 5, 2026
@dahlia dahlia self-assigned this Oct 5, 2026
@dahlia dahlia added the component/vocab Activity Vocabulary related label Oct 5, 2026
@dahlia dahlia added the activitypub/compliance Specification compliance label Oct 5, 2026
@netlify

netlify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for fedify-json-schema canceled.

Name Link
🔨 Latest commit 1ee24c3
🔍 Latest deploy log https://app.netlify.com/projects/fedify-json-schema/deploys/6ac39a8e00d7be0008dd20e0

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
CONTRIBUTING.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 911fa4f1-0721-4668-bffd-6bb454a6ed8d
📥 Commits

Reviewing files that changed from the base of the PR and between 3a7ba49 and 1ee24c3.

⛔ Files ignored due to path filters (4)
  • packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap is excluded by !**/*.snap
  • packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap is excluded by !**/*.snap
  • packages/vocab-tools/src/__snapshots__/class.test.ts.snap is excluded by !**/*.snap
  • packages/vocab/src/__snapshots__/vocab.test.ts.snap is excluded by !**/*.snap
📒 Files selected for processing (22)
  • .agents/skills/add-vocab/SKILL.md
  • CHANGES.md
  • FEDERATION.md
  • changes.d/vocab-tools/absolute-iri.md
  • changes.d/vocab/content-license.md
  • docs/manual/pragmatics.md
  • packages/fedify/src/sig/proof.test.ts
  • packages/fixture/src/fixtures/w3id.org/fep/6757.json
  • packages/vocab-tools/README.md
  • packages/vocab-tools/src/class.ts
  • packages/vocab-tools/src/codec.test.ts
  • packages/vocab-tools/src/codec.ts
  • packages/vocab-tools/src/type.ts
  • packages/vocab/src/application.yaml
  • packages/vocab/src/group.yaml
  • packages/vocab/src/license.test.ts
  • packages/vocab/src/link.yaml
  • packages/vocab/src/object.yaml
  • packages/vocab/src/organization.yaml
  • packages/vocab/src/person.yaml
  • packages/vocab/src/service.yaml
  • packages/vocab/src/vocab.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The change adds FEP-6757 license metadata to vocabulary objects, links, and actor types. It adds absolute-IRI encoding and reading support, updates extra-context handling, and adds related tests and documentation.

Changes

FEP-6757 license metadata

Layer / File(s) Summary
Absolute-IRI and context handling
.agents/skills/add-vocab/SKILL.md, packages/vocab-tools/src/*, packages/vocab-tools/README.md, packages/vocab-tools/src/codec.test.ts, packages/vocab/src/vocab.test.ts, changes.d/vocab-tools/absolute-iri.md, CHANGES.md
fedify:absoluteIri maps URL values to @id and reads absolute IRIs from node IDs or eligible string literals. It skips invalid or relative values instead of resolving them against an object ID. Extra contexts are detected from populated values and serialized child contexts.
License vocabulary properties
packages/fixture/src/fixtures/w3id.org/fep/6757.json, packages/vocab/src/object.yaml, packages/vocab/src/link.yaml, packages/vocab/src/{application,group,organization,person,service}.yaml
Objects and links gain licenses properties that write the canonical Dublin Core term and read configured synonyms. Five actor types gain preferredLicense.
License parsing, serialization, and proof tests
packages/vocab/src/license.test.ts, packages/fedify/src/sig/proof.test.ts
Tests cover license round-trips, synonym precedence, invalid values, context behavior, no license-URI dereferencing, and signed-note verification when license data changes or its representation changes.
License guidance and release notes
docs/manual/pragmatics.md, CHANGES.md, FEDERATION.md, changes.d/vocab/content-license.md
Documentation describes license scope and input rules, preferred-license behavior, and the absence of synthesized default licenses or license-URI fetching. The supported-FEP list adds FEP-6757.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 1ee24

No actionable issue remains from these comments; the change is ready to merge after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1ee24

License metadata does not introduce automatic fetching of license URLs or weaken signature verification. However, discarding unsupported license values can make previously signed content fail verification after serialization, which matters when forwarding content signed by another author.

Retained concerns

  • Low · reliability · inferred: Recognizing license metadata extends existing cache invalidation to incoming license values. If any value is skipped, the cached signed representation is discarded; subsequent serialization can fail verification even though the original input verified successfully. This can prevent proof-preserving forwarding of affected foreign-authored objects. Verification fails closed, but a relay cannot replace the original author's proof without that author's signing authority.
Security review details

Security Blast Radius

  • inferred — The supported new failure scope is the signed object whose representation changes during parsing or serialization, and downstream consumers requiring its original proof. No license-value path to network fetching or additional signing authority was established. Remote context fetching retains its pre-existing exposure.

Security Findings and Attack Paths

  • observed — The tested license transformations fail verification rather than authorizing modified content. Original mixed-value input verifies, while its rewritten serialization returns null. These observations support a proof-preservation concern, not a verified signature bypass.

Trust Boundaries and Controls

  • observed — License values remain data rather than fetch instructions. Separate remote context requests use the existing loader's public-URL validation, redirect limits, timeout, and fetch controls. The full-base comparison does not change those controls or the proof verifier.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Issue #1212 requirements for licenses on Object and Link, preferredLicense on the five actor types, read-only synonyms, no default fallback, and related documentation are covered by the report… Use the xsd:anyURI range for the issue’s license properties. Provide reviewable evidence that the Deno, Node.js, and Bun snapshots were regenerated; the excluded snapshot paths are `packages/vocab-tools/src/snapshots/class.test.ts.den…
Docstring Coverage ⚠️ Warning Docstring coverage is 12.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 7 files. (15 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: adding FEP-6757 content license metadata.
Description check ✅ Passed The description explains the license properties, value handling, synonym rules, context detection, and known limits covered by the changeset.
Out of Scope Changes check ✅ Passed The vocabulary, absolute-IRI codec, extra-context handling, documentation, changelog, and proof tests support FEP-6757 implementation or its stated serialization and signature constraints. No unrelate…
Full details: Linked Issues check

Explanation

Issue #1212 requirements for licenses on Object and Link, preferredLicense on the five actor types, read-only synonyms, no default fallback, and related documentation are covered by the reported changes and tests. The issue explicitly requires xsd:anyURI, but the new properties use fedify:absoluteIri. The summary does not establish whether the required Deno, Node.js, and Bun snapshots were regenerated; the relevant snapshot files were excluded from review.

Resolution

Use the xsd:anyURI range for the issue’s license properties. Provide reviewable evidence that the Deno, Node.js, and Bun snapshots were regenerated; the excluded snapshot paths are packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap, packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap, packages/vocab-tools/src/__snapshots__/class.test.ts.snap, and packages/vocab/src/__snapshots__/vocab.test.ts.snap.

Full details: Docstring Coverage

Explanation

Docstring coverage is 12.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 7 files. (15 skipped: 15 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

Files with missing lines Coverage Δ
packages/vocab-tools/src/class.ts 99.19% <100.00%> (+1.72%) ⬆️
packages/vocab-tools/src/codec.ts 98.02% <100.00%> (-1.60%) ⬇️
packages/vocab-tools/src/type.ts 85.23% <100.00%> (-0.09%) ⬇️

... and 313 files with indirect coverage changes

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

activitypub/compliance Specification compliance component/vocab Activity Vocabulary related

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add FEP-6757 content license metadata to @fedify/vocab

1 participant