Private Posts #
A new work-in-progress private post technology for third-party clients utilizing a brand new alpha in-development ATProto feature called "permissioned data" (aka atproto spaces) to viewgate posts to mutuals.
This is experimental and has a lot of work left to make it functional: make an API/AppView, make a client integration, etc. Currently they're supported in tenna.party.
These lexicons will intentionally not support the display and use of embeds such as images and links, as their implementation could be tricky client-side and because of moderation risks factors (e.g. unlabeled content, copyright infringment). Facets are supported, though!
Implementation guide #
All XRPC queries and procedures sent to the AppView (did:web:party.tenna#private or privateposts-api.tenna.party) must be authenticated and include a service auth token minted for the corresponding AppView's DID & XRPC method!
Users can be banned from making private posts, therefore the client must check status with party.tenna.private.getModStatus while private posts are still in beta.
OAuth clients must include:party.tenna.private.permissions or allow write access to the party.tenna.private.space space for making private posts.
If a client needs to implement private posts, it must parse the external URL on an app.bsky.embed.external embeds. The uri and cid parameters must be extracted from a URL starting with https://private-post.tenna.party? (e.g. like on this record) and the uri and cid queried into party.tenna.private.getPost with service auth.
Clients must register the AppView to be notified of changed made to the user's party.tenna.private.space space using com.atproto.space.registerNotify on a spaces-supported PDS.