Axismundi Object Projections turns a WordPress object — a post, an attachment, an
archive, a folder — or an Axismundi Actor into an ActivityStreams 2.0 object or
collection, so that the URL it already has can answer with JSON-LD when something asks
for it.
It owns representation and nothing else: a transformer registry, the URIs objects and
collections are named by, and the single renderer that writes the JSON. What a thing is
stays with the plugin that stores it; this decides how it is described to a reader that
speaks ActivityStreams.
This plugin needs Axismundi Actors. It resolves the identities an object names — its
author, the accounts it mentions, the Actor documents it serves — and without that registry
there is nobody for any of them to refer to.
Axismundi Activities is optional, and adds four things. Without it a published post is
public and is projected as such, which is this plugin’s own default. With it, the four
authored visibility levels decide who a post is addressed to, an Actor’s outbox and follow
collections have contents rather than being empty, an object states who may quote it, and an
object says who published it. Nothing here breaks when it is absent; less is said.
That last one is worth stating plainly: who an object is attributed to is decided by whatever
recorded its publication, not derived here from the WordPress author. An object nobody has
published has no attributedTo — it is readable, it simply was not published by anyone.
There is no Activity ledger, no inbox write handling, no Follow/Like/Announce state, no
HTTP signatures, and no delivery. Those belong to Axismundi Activities and to the
ActivityPub transport boundary. Nothing here signs or sends an Activity.
Both plugins negotiate the same canonical URLs, and two answers for one address is worse
than either answer alone. So when the official ActivityPub plugin is active, this plugin’s
standalone negotiator turns itself off and leaves those URLs to it, while the registry
and renderer stay available. Nothing here overrides or replaces that plugin’s object ids.
An observation of a remote object is a cache, not a record: it is keyed by the remote
URI, which stays canonical, and it can be rebuilt by fetching again. Observations expire,
and a scheduled daily task deletes the expired ones along with anything left pointing at
them.
Remote media is never downloaded and never hotlinked. A cached object’s attachments are
described — type, size, the text the author wrote about them — and not fetched. Where a
cached object is shown locally at all, it is shown noindex, only for objects that were
addressed publicly, and only as a courtesy view beside the remote original.
This plugin reads documents from other websites. Every request is a GET made through
wp_safe_remote_get(): redirects are not followed automatically, the response size is
capped, and any address inside your own network is refused. Nothing about your site’s
content or your users is sent as data. As with any outgoing HTTP request the server being
contacted receives your site’s IP address, and a User-Agent header naming this
plugin, its version, and your site’s home URL.
Requests happen for two reasons, and the second is worth being clear about.
Because an administrator asked.
Because something arrived here naming an address.
Announce reaches this site’s inbox carrying onlyhttps addresses are considered. Turning the setting offWhich servers are contacted therefore depends on which addresses your administrators enter
and which sites send things to your inbox. This plugin has no service of its own and sends
nothing to its author. Each server contacted is somebody else’s, run under its own terms of
service and privacy policy.