facebook posts: fb_posts table, ingest with hash-verified images, gated image, cancel

Open item 12, designed 2026-08-26, built today. scout-publisher reports
every post it drafts, schedules, holds or cancels by POSTing here; it
never opens the database. id is <unit>/<queue-stem>, stable across body
edits, so a redrafted post is one row and cancel is an indexed lookup on
fb_post_id. The image is copied, content-addressed at
/data/post-images/<sha256>.<ext>, and the sha256 is recomputed on arrival
- a mismatch is refused, so a row never claims a version nobody sent.
image_ref keeps the NAS path as provenance. The image route runs the same
capability check as the list on every request. Cancel goes through the
publisher's own signed per-post link stored on the row; the site never
holds the publisher's secret. fbposts:read for leaders, fbposts:ingest
for admins and scopable so the publisher's key carries exactly that.

tests/smoke_admin.py 147 -> 157.
This commit is contained in:
2026-09-04 19:46:44 -04:00
parent 7f04d57665
commit 55e4c67b9a
4 changed files with 270 additions and 0 deletions
+3
View File
@@ -78,6 +78,7 @@ CAPS = {
"calendar:write",
"unit:write_own",
"roster:write",
"fbposts:read",
"apikeys:own",
"api:docs",
"email:draft",
@@ -91,6 +92,8 @@ CAPS = {
"calendar:write",
"unit:write_own",
"roster:write",
"fbposts:read",
"fbposts:ingest",
"units:write",
"settings:write",
"apikeys:own",