Conversation
Give ActivityStreams objects and links an explicit copyright license, as proposed by the FEP-6757 draft, so that publishers can state what they allow and consumers can tell what they may do with received content. Object and Link gain non-functional licenses written as the Dublin Core license property. The Schema.org and Creative Commons license properties are read as synonyms when it is absent, but never merged with it or written. The five actor types gain a functional preferredLicense, which is a default for new objects and not a fallback for unlicensed ones. Fedify does not synthesize a default license and never fetches a license URI. http://schema.org/license is deliberately not a synonym: PeerTube uses it for licence descriptions that are not URIs, and reading them would drop the cached input of every PeerTube video that has one. License values use a new fedify:absoluteIri range. It writes IRI references like xsd:anyURI, but also reads string literals, which the FEP's own schema:license example produces, and never resolves a value against the object's ID, so license names and SPDX identifiers are skipped instead of becoming URLs on the publisher's server. The extraContext detection now also scans the values before compaction. Activity contexts include https://w3id.org/identity/v1, whose dc prefix otherwise compacted license to dc:license in every Create without the FEP context, which plain JSON consumers would not recognize. This also avoids compacting a licensed object twice in the common case. Fixes fedify-dev#1212 Assisted-by: Claude Code:claude-opus-5-5 Assisted-by: Codex:gpt-6-astra Assisted-by: Claude Code:claude-fable-5-1
✅ Deploy Preview for fedify-json-schema canceled.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (4)
📒 Files selected for processing (22)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe change adds FEP-6757 license metadata to vocabulary objects, links, and actor types. It adds absolute-IRI encoding and reading support, updates extra-context handling, and adds related tests and documentation. ChangesFEP-6757 license metadata
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Merge Risk: ⚪ Minimal · up to No actionable issue remains from these comments; the change is ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to License metadata does not introduce automatic fetching of license URLs or weaken signature verification. However, discarding unsupported license values can make previously signed content fail verification after serialization, which matters when forwarding content signed by another author. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Linked Issues checkExplanation Issue Resolution Use the Full details: Docstring CoverageExplanation Docstring coverage is 12.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 7 files. (15 skipped: 15 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests.
... and 313 files with indirect coverage changes 🚀 New features to boost your workflow:
|
Adds FEP-6757
licensestoObjectandLink, andpreferredLicenseto the five actor types. Uses the non-functionalredundantPropertiesfrom #1215 and the bundled context from #1216.Fixes #1212.
Value type
Values use a new
fedify:absoluteIrirange instead ofxsd:anyURI. The stock decoder resolves values against the object's ID, so an SPDX identifier like"CC-BY-4.0"would becomehttps://social.example/note/CC-BY-4.0. It also rejects literals, and the FEP's ownschema:licenseexample expands to a literal, so the wholeNotefailed to parse. Likexsd:anyURI, the new range writes@id. It also reads string literals, never resolves against a base, and skips values that are not absolute.Synonyms
https://schema.org/licenseandcc:licenseare read as fallbacks whenlicenseis absent; their values are never merged or written.http://schema.org/licenseis excluded because PeerTube uses it for non-URI licence objects, and reading those would drop the cached input of each affected video.Context detection
Every activity's default context includes identity/v1. Without the FEP context, its
dcprefix madelicenseinsideCreatecompact todc:license.extraContextdetection now also runs before compaction, scanning expanded keys and child@contextvalues, with the post-compaction scan kept as a fallback. The usual case now needs one compaction instead of two.Known limits
A cached child that defines
licensethrough a prefix in its own inline context can still compact todc:license. Skipping a signed object's license value, or re-serializing it inside a new activity, drops the generic JSON-LD cache, so its proof no longer verifies. Tests pin down both signature cases; changing the cache is out of scope.