Documentation #
See the project README for an overview and CONTRIBUTING.md to work on the backend.
Development and reference #
- Test architecture — test tiers, fixtures, and CI.
- Project structure — packages and server startup.
- Lexicon schemas — API and record definitions.
- Schema fixtures — validation examples.
- SSRF security model — rules for outbound requests.
- Credential encryption — storage, keys, and recovery.
- Security policy — how to report a vulnerability.
Local development #
The setup guide needs updating. Check the Makefile, Compose file, and example environment for current configuration.
Development Postgres uses port 5435, and the AppView subscribes through
JETSTREAM_FEEDS. Replace the environment template's placeholder values before
using it. Keep OAUTH_SEAL_SECRET and ENCRYPTION_KEY stable across restarts.
make dev-up starts the supporting services; make run starts the AppView
and requires goose for migrations.
Aggregators #
Maintainer guides #
Design background #
Admin moderation PRD covers server-admin remove/restore, post NSFW labeling with existing blur/reveal, a public modlog, and opt-in federated moderation through signed labels (draft).
Author-owned posts explains why post content and community acceptance live in separate repositories. It also includes migration notes and proposed federation work.
Other PRDs, implementation reports, and dated audits remain in this directory for historical context. They may describe replaced code or unimplemented plans; use the source and tests to check current behavior.