Skip to content

feat(safety): show every safety category, and warn before a raise goes public - #77

Merged
fullynocturnal merged 1 commit into
mainfrom
feat/safety-categories
Sep 19, 2026
Merged

fullynocturnal merged 1 commit into
mainfrom
feat/safety-categories

Conversation

@fullynocturnal

Copy link
Copy Markdown
Collaborator

The System Safety screen only knew nine of the server's fifteen categories, and it had no idea that raises to public can be waiting out the grace window.

Every category

notifications, reminders, polls, messages, relationships and archive came back from GET /system/safety and were dropped on parse, so they could be neither seen nor changed from the phone. profile_visibility was missing with them, and it is the one category that gates making things more visible rather than deleting them.

All fifteen are now on the screen, worded as on the web card. Turning any of them off is a loosening, so it asks for re-auth like the others already did. A field an older instance does not send parses to the server's own default (profile_visibility on, the rest off).

The toggle list now takes the draft and one callback, rather than one lambda per category, which at fifteen would have been unreadable.

Pending exposures

GET /system/safety carries pending_exposures: raises to public that are waiting out the grace window. They now show up in two places:

  • A read-only section on the safety screen, one row per staged raise with when it takes effect. Read-only on purpose: un-publishing happens where the thing was published (the share view, the member, the edge), not here.
  • A banner on Home, beside the pending-delete and pending-settings ones, in the web banner's wording, going critical inside the last 24 hours like its neighbours.

Also names the seven pending-action types that were showing up as raw snake_case (watch_token_revoke, message_thread_delete and so on).

Checked

  • Unit tests: all fifteen fields parse, pending_exposures parses and defaults to empty when absent, and disarming each of the seven newly shown categories is treated as a loosening while arming one is not.
  • Full unit suite and assembleOpenDebug on this branch alone.

…s public

The System Safety screen knew nine of the server's fifteen categories. The
other six (notifications, reminders, polls, messages, relationships and
archive) came back from the server and were dropped on parse, so they could
be neither seen nor changed from the phone. profile_visibility was missing
with them, and it is the one category that gates making things more visible
rather than deleting them.

All fifteen are now on the screen, worded as on the web card. Turning any of
them off is a loosening, so it asks for re-auth like the others already did.
The toggle list now takes the draft and one callback instead of a lambda per
category, which at fifteen would have been unreadable. A field an older
instance does not send parses to the server's own default.

**Pending exposures.** GET /system/safety carries pending_exposures: raises to
public that are waiting out the grace window. They get a read-only section on
the safety screen and a banner on Home beside the pending-delete ones, in the
web banner's wording. Read-only on purpose, since un-publishing happens where
the thing was published, not here.

Also names the seven pending-action types that were showing as raw
snake_case.
@fullynocturnal
fullynocturnal merged commit 7330e16 into main Sep 19, 2026
1 check passed
@fullynocturnal
fullynocturnal deleted the feat/safety-categories branch September 19, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant