Updates
Platform Updates
Public-facing release notes for meaningful changes across Furries PH operational systems.
First created Last updated
Release Notes
Social clarifies the shared-account privacy boundary
Repositories: social.furries.ph
Status: Settings clarity released; existing account, event, and retention policies are unchanged
What’s Changed
- Social Settings now explains that account setup needs only e-mail, profile name, username, and password.
- It makes clear that Rego asks for extra details only when a member selects a feature that needs them, with shared details shown as reviewable prefill.
- It also states that planned and past event activity is private until an eligible disclosure is chosen, and that registrations, payments, check-ins, and event answers are not copied into a Social profile.
Impact
- Members can understand the shared login without confusing it for a merged Social and event profile. This is an explanatory Settings improvement only; it creates no new data transfer, sharing setting, browser request, API runtime, or federation path.
Upgrade Notes
- Event disclosure remains optional and subject to existing member, organizer, audience, and safety rules. Broader retention/policy and human-release evidence remain separate controlled-alpha gates.
Social readiness exercises are repeatable
Repositories: partners-api, social.furries.ph
Status: Controlled alpha evidence refreshed; public-scale and federation boundaries remain unchanged
What’s Changed
- Re-ran the Social account export/deactivation, moderation role/RLS, bounded request-capacity, restricted retention, held-media, and encrypted recovery exercises from a clean API release worktree.
- Added a guarded mail/support transport check. It sends one controlled message only when an explicit local certification gate is set and verifies the configured support reply path plus provider acceptance.
Impact
- Staff can repeat the mail/support readiness check without adding a runtime, direct database client, Pages Function, Queue, KV store, or AI moderation path. The existing restricted-alpha safeguards remain fail closed.
Upgrade Notes
- Provider acceptance does not prove inbox placement or a human support reply. The bounded capacity check is not a claim of unlimited traffic, and ActivityPub federation, appeal outcomes, and destructive retention remain disabled.
Social account-link concurrency is certified
Repositories: partners-api, social.furries.ph
Status: Hosted identity-link race proof completed; retention and broader human-release evidence remain separate
What’s Changed
- The Social-to-Regosite optional account-link certificate now races two rightful-owner confirmation requests for one fragment-only continuation.
- The deployed API accepted exactly one request and rejected the concurrent duplicate, proving its one-time database lock under an actual race rather than only a sequential retry.
- Existing cross-user denial, expiry, revocation, relink, and direct-table RLS checks remain part of the self-cleaning hosted exercise.
Impact
- Members retain the same explicit, optional account-link flow. The change adds no cross-domain session, additional Worker, credential transfer, signing key, direct database access, or data sharing.
Upgrade Notes
- The opaque continuation is randomly generated and stored only as a SHA-256 digest; ActivityPub/federation signing keys remain deferred. Retention/ deletion policy and broader human release evidence are still tracked separately.
Social restricted-alpha readiness is certified
Repositories: social.furries.ph, partners-api
Status: Certified for the limited local alpha; federation and destructive moderation remain disabled
What’s Changed
- Completed controlled readiness exercises for role/RLS isolation, staff grant expiry and revocation, held-media review/release, deterministic non-AI triage, configured mail-provider acceptance, bounded Worker request budget, encrypted logical export/recovery, and restricted retention handling.
- Furries PH Staff remains the collective moderation owner. The current launch profile rejects appeal-reviewer grants and retention-purge requests, so routine staff actions remain reversible and attributable.
- The operational certificate records what was proved and its limits, including cleanup of all temporary identities, content, logs, and encrypted drill artifacts.
Impact
- Support and moderation teams have a documented, tested restricted-alpha operating baseline without adding a Worker, Pages Function, Queue, KV store, direct database access, or AI moderation decision path.
Upgrade Notes
- This is not a broad public-scale capacity claim, a mailbox-delivery promise, an independent-reviewer workflow, or ActivityPub approval. Those changes require separate evidence and an approved operating decision.
Social moderation policy v1.0 is published for restricted alpha
Repository: social.furries.ph
Status: Policy baseline recorded; tabletop and controlled-alpha operating evidence remain required
What’s Changed
- Published the first Furries PH Social moderation policy for the restricted alpha. It sets clear rules for safety, harassment, privacy, consent, fraud, creator rights, sensitive-content warnings, reports, and staff recusal.
- The policy makes Furries PH Staff the collective policy owner, sets a 1 December 2026 review date, and defines a privacy-minimised retention target for moderation records and audit receipts.
- It confirms the current safety boundary: deterministic anti-abuse controls may prepare review work, but cannot decide subjective cases, remove content automatically, restrict accounts automatically, or use AI image/text triage.
- The restricted no-independent-reviewer profile remains in force. Appeal intake is available, while final appeal outcomes and retention purges remain disabled until their required separation-of-duties safeguard exists.
Impact
- Members have one readable Social-specific policy and can understand the available report, notice, correction, and comfort-control boundaries.
- Moderators have a documented proportional-enforcement and evidence-minimised operating baseline. The policy does not enable federation, a new runtime, direct data access, or automatic moderation.
Upgrade Notes
- Before a broader launch, Furries PH Staff must complete the documented moderator tabletop, evidence-access review, recovery exercise, and controlled-alpha operating approval. Any material policy change will receive a new version and effective date.
Validation
- Policy research reviewed current BARQ, Bluesky, Mastodon, and Community/IWAG public guidance and adapted it to the Furries PH local-alpha architecture.
- Social documentation whitespace validation passed locally.
Social staff-owned restricted moderation launch
Repositories: partners.furries.ph, partners-api, moderation.furries.ph, social.furries.ph
Status: Locally validated; Git-connected release pending
What’s Changed
- Furries PH Staff is now recorded as the collective operational owner for the initial Social alpha.
- Because no independent reviewer is appointed, the existing
partners-apiservice now fails closed for appeal-reviewer grants, final appeal outcomes, and retention-purge request/approval actions. - Routine reversible moderation, policy/media review, legal-preservation holds, and actor-audited staff work continue through the existing scoped service capabilities.
- The static moderation dashboard shows the restricted profile and does not offer the unavailable appeal-reviewer grant. It adds no Pages Function, browser database client, new Worker, or background request path.
Impact
- Members may still submit an appeal, but staff cannot issue an appeal outcome until an independent reviewer is formally appointed.
- Retention review remains read-only; destructive retention purges are not available under this launch profile.
Upgrade Notes
- No member action is required. To enable the restricted functions later, record the independent reviewer, policy version, and review date, then make the deliberate deployment-owned change documented in the moderation launch register.
Validation
- API launch-profile and retention source contracts, API TypeScript checks, dashboard typecheck, 17 dashboard tests, production build, and local rendered restricted-launch evidence passed.
Social custom-emoji moderation activity
Repositories: partners.furries.ph, partners-api, moderation.furries.ph
Status: Released and hosted-certified
What’s Changed
- Staff-curated Social custom emoji now have a deliberately narrow moderation activity contract: publish and archive lifecycle changes create one normal-priority catalogue update, with reactivation recorded as publish.
- Authorized staff can review only the catalogue shortcode, display name, lifecycle, revision, and update time. The review does not open a member report or case and does not expose an uploaded asset, Sanity location, uploader identity, member content, report, or enforcement controls.
- The design continues to use the existing
partners-apiWorker and static Pages dashboard. It adds no Pages Function, second Worker, queue, scheduler, direct browser database access, or AI moderation process. - The deployed API certificate confirms a
media.managestaff role can publish and archive a catalogue emoji without gaining broader case access. It also verifies the revisioned cursor, safe review, direct-table denial, and removal of disposable test identities, operational records, and the test image.
What To Do
- Record the named moderation owner and independent reviewer before enabling this staff workflow for the community.
Private Social Event RSVP is released
Repositories: social.furries.ph, partners-api, partners.furries.ph
Status: Published through Git-connected deployments
What’s Changed
- Social members can deliberately review and set a private Going or Interested RSVP for a currently public Event without registering, buying a ticket, checking in, or joining an attendee list.
- RSVP reuses the existing member account and Event identities. It does not create a Social-only profile, copied Event, registration, payment, or attendance record.
- A future Going card can appear on a public Social profile only when the member separately enables Event activity and the Event organizer allows the disclosure. Interested RSVPs and past-event history stay private.
- A small follow-up migration repaired the public Event URL validator so valid
furries.phEvent links can enter the service-owned discovery projection.
Impact
- Members gain a lightweight way to track public Events while registration and admission continue to be owned by the normal Event and Rego workflows.
- The Social Pages app still sends dynamic requests only to the existing
partners-apiWorker. The RSVP data has no direct browser database access, no Pages Function, and no additional Worker.
Upgrade Notes
- No member or Event-operator action is needed. Members can use Social RSVP only as a private planning signal; the normal Event and Rego workflows remain the source of truth for registration and admission.
Validation
- The focused API/schema contract passed 21 assertions and the Worker TypeScript check passed locally.
- The Social SPA passed type checking, 186 tests, its local route-browser certificate, and the production build.
- The applied migrations are present in the remote migration ledger. The opt-in hosted two-account lifecycle certificate passed owner-only access, direct Data API denial, privacy-gated Going disclosure, and fixture cleanup.
Safer live friendship-withdrawal certification
Repositories: partners-api, social.furries.ph, rego.furries.ph
Status: Git release ready; no member-facing workflow changed
What’s Changed
- The opt-in three-account friendship-withdrawal check now creates, withdraws, verifies, and cleans up its disposable identities through the existing guarded API test-run facility.
- The checker no longer needs a database service credential on the computer that runs it. Its verification response is limited to the test run’s own relationship states, deactivation markers, receipt counts, and Friends / discovery settings.
Impact
- The database service credential remains Worker-only while operators retain a repeatable live check for account withdrawal, cross-surface friend removal, public-profile withdrawal, and an unaffected counterparty-owned block.
Upgrade Notes
- Run the opt-in check only with the separately managed test-control credential. It can operate only on fixtures created by that exact test run and performs its normal cleanup before reporting success.
Validation
- The focused contract now passes 18 assertions, and the Worker type check and certificate syntax check pass locally.
Canonical friendship withdrawal certificate hardening
Repositories: partners-api, partners.furries.ph, social.furries.ph, rego.furries.ph
Status: Production API validation update; no member-facing workflow changed
What’s Changed
- The canonical friendship withdrawal certificate now verifies the surviving member’s everywhere-block rule by its SQL meaning rather than a specific indentation layout.
- The validated withdrawal path still removes active relationships for an Auth identity that is removed, preserves a block owned by the other member, and suppresses the withdrawn Social identity from both Social and Regosite.
Impact
- Operators receive a reliable source-level release check when the migration is reformatted. No existing friend, block, account, event, or public profile data changed as part of this validation update.
Upgrade Notes
- No action is required. The later Worker-owned fixture update removes the caller-held database service-credential requirement.