feat(safety): show every safety category, and warn before a raise goes public - #77
Merged
Merged
Conversation
…s public The System Safety screen knew nine of the server's fifteen categories. The other six (notifications, reminders, polls, messages, relationships and archive) came back from the server and were dropped on parse, so they could be neither seen nor changed from the phone. profile_visibility was missing with them, and it is the one category that gates making things more visible rather than deleting them. All fifteen are now on the screen, worded as on the web card. Turning any of them off is a loosening, so it asks for re-auth like the others already did. The toggle list now takes the draft and one callback instead of a lambda per category, which at fifteen would have been unreadable. A field an older instance does not send parses to the server's own default. **Pending exposures.** GET /system/safety carries pending_exposures: raises to public that are waiting out the grace window. They get a read-only section on the safety screen and a banner on Home beside the pending-delete ones, in the web banner's wording. Read-only on purpose, since un-publishing happens where the thing was published, not here. Also names the seven pending-action types that were showing as raw snake_case.
This was referenced Sep 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The System Safety screen only knew nine of the server's fifteen categories, and it had no idea that raises to public can be waiting out the grace window.
Every category
notifications,reminders,polls,messages,relationshipsandarchivecame back fromGET /system/safetyand were dropped on parse, so they could be neither seen nor changed from the phone.profile_visibilitywas missing with them, and it is the one category that gates making things more visible rather than deleting them.All fifteen are now on the screen, worded as on the web card. Turning any of them off is a loosening, so it asks for re-auth like the others already did. A field an older instance does not send parses to the server's own default (
profile_visibilityon, the rest off).The toggle list now takes the draft and one callback, rather than one lambda per category, which at fifteen would have been unreadable.
Pending exposures
GET /system/safetycarriespending_exposures: raises to public that are waiting out the grace window. They now show up in two places:Also names the seven pending-action types that were showing up as raw snake_case (
watch_token_revoke,message_thread_deleteand so on).Checked
pending_exposuresparses and defaults to empty when absent, and disarming each of the seven newly shown categories is treated as a loosening while arming one is not.assembleOpenDebugon this branch alone.