-
-
Notifications
You must be signed in to change notification settings - Fork 35
Releases: opencoredev/social-sdk
Release list
@opencoredev/social-sdk@0.5.0
4da0487 Minor Changes
- 59fd2f7: Add a PostFast managed backend at
@opencoredev/social-sdk/cloud/postfast. It lists connected accounts, uploads media, schedules posts, reads delivery state, cancels scheduled posts, deletes failed records, reads post analytics, and creates connect links throughnative.createConnectLink. PostFast only accepts scheduled posts, so every target needs a futureschedule. The offline CLI diagnostics recognize thepostfastadapter andPOSTFAST_API_KEY.
Assets 2
@opencoredev/social-sdk@0.4.0
04bdca2 Minor Changes
-
01971d4: Add AT Protocol OAuth for Bluesky to
@opencoredev/social-sdk/server.blueskyOAuthworks withConnectionManagerand handles handle and DID resolution, PDS and authorization server discovery, pushed authorization requests, PKCE, DPoP-bound tokens, theisscallback check, and identity verification. If the token response fails validation or identity verification fails after tokens are issued, it makes one best-effort request to revoke them when the authorization server advertises a revocation endpoint. Every request is checked against an HTTPS-only egress guard that rejectslocalhostand non-public IP-literal hosts, handle redirects are followed manually for at most three hops, and an optionalassertEgressAllowedhook lets servers add DNS-aware checks. Authorization server responses without aDPoP-Nonceheader are rejected.blueskyOAuthClientMetadatapublishes only EC P-256 public keys and rejects private or symmetric key material.blueskyOAuthTransportturns a stored session into the Bluesky adapter'ssession, andrefreshBlueskyOAuthSessionrefreshes it with rotated refresh tokens.blueskyOAuthClientMetadata,blueskyOAuthPublicJwk,blueskyLoopbackClientId, andparseBlueskyOAuthSessioncover client metadata and stored sessions. No runtime dependencies are added.ConnectionManager.beginandConnectionProvider.startaccept an optionalloginHint. A provider can setproviderStateSecret: trueon itsstartresult to keepproviderStateout of the attempt thatbeginreturns. The Bluesky provider does this because its state holds the DPoP private key. Other providers still returnproviderStateas before. -
e711a88: Add Bluesky video publishing.
media.uploadsends an MP4 to the Bluesky video service and returns a media reference that holds the processing job ID. The newnative.getVideoJobStatusandnative.getVideoUploadLimitsoperations read job state and daily limits, so the caller controls polling.posts.publishwith the video reference reads the job once and writes anapp.bsky.embed.videorecord when processing is complete. If the job is still processing, the target fails withmedia_errorand no post is created. The newpdsDidandvideoServiceoptions set the upload token audience and the video service origin. -
bcc36a3: Add native
deleteCommentand acomments.deletecapability to the YouTube, Threads, Bluesky, X, and LinkedIn adapters. X, Threads, and Bluesky can only delete the authenticated account's own replies. YouTube and LinkedIn follow each platform's permission checks. -
bcc36a3: Add native reply hiding for X and Bluesky, and declare
comments.moderatefor LinkedIn.- X:
native.hideReply({ account, replyId, hidden, context })callsPUT /2/tweets/{id}/hiddenwith a user-context token and returns the hidden state X reports. - Bluesky:
native.hideReply({ account, replyUri, hidden, context })adds or removes the reply in the root post's threadgatehiddenReplieslist. It creates a threadgate without reply rules when none exists and updates an existing one withswapRecord. - LinkedIn:
comments.moderateis declaredunsupported-by-platformbecause the Comments API has no hide operation.
- X:
-
bd91f18: Verify and decode webhooks sent directly by Instagram, Threads, X, YouTube, TikTok, and LinkedIn.
@opencoredev/social-sdk/serveraddsverifyMetaWebhook,verifyXWebhook,verifyYouTubeWebhook, andverifyTikTokWebhookfor signed POST deliveries,answerMetaWebhookChallenge,answerXWebhookChallenge, andanswerYouTubeWebhookChallengefor the GET handshakes, anddecodePlatformWebhookfor normalized events. The five direct adapters accept awebhookSecretoption and declarewebhooks.verify.VerifiedWebhook.signedTimestampis now abooleanand may includesignedAt, andSocialEvent.providerincludes the direct platform names. LinkedIn deliveries useverifyLinkedInWebhookandanswerLinkedInWebhookChallenge, the LinkedIn adapter acceptswebhookSecret, and it declareswebhooks.verifyasapproval-dependentbecause LinkedIn enables webhooks only for approved apps. The Bluesky adapter declareswebhooks.verifyasunsupported-by-platformbecause Bluesky has no webhooks. -
d567532: Instagram
mentions.readnow works with Instagram Login.listMentions,mentions, andlistTaggedMediareadGET /{ig-user-id}/tagsongraph.instagram.comwithinstagram_business_basicandinstagram_business_manage_comments, and the capability manifest declaresmentions.readas available for both login flavors.mentionedMediaandmentionedCommentstill require Facebook Login and now raise a clearerunsupported_capabilityerror with Instagram Login. -
7ea7d23: Add
accounts.listandaccounts.getto the direct LinkedIn adapter. A member author reads the OpenID Connectuserinfoendpoint (openidandprofilescopes) and must matchurn:li:person:{sub}. An organization author reads/rest/organizations/{id}, which needsrw_organization_adminand an approvedADMINISTRATORrole. A403reportsmissing_permissionwith the required scopes, and a mismatched identity reportsunauthorized. The native module addslistAdministeredOrganizations, which pages through the member's approved administrator roles fromorganizationAcls. -
f2137e6: Add LinkedIn document posts.
social.media.uploadnow accepts adocumentattachment (PDF, PPT, PPTX, DOC or DOCX, up to 100 MB) for the LinkedIn adapter and uploads it through the Documents API. A publish request with one uploaded document creates a document post after the adapter confirms the document is owned by the configured author andAVAILABLE. The title comes from the attachmentcaptionorfilename. The LinkedIn native module addsdocumentStatus, which returnsid,ownerandstatuswithout the signed download URL.posts.documentis nowavailablein the LinkedIn manifest.MediaAttachment.kindand the capabilityformatsunion gain"document". Code that switches exhaustively onMediaAttachment["kind"]needs adocumentbranch. Other adapters reject document attachments. -
f2137e6: Add LinkedIn multi-image posts to the direct adapter.
posts.publishnow accepts 2 to 20 uploaded image references and sends them as Posts APImultiImagecontent, with optional per-image alt text. Preparation rejects more than 20 images and multi-image alt text over 4,086 characters. Before the post is created, every image is checked for author ownership andAVAILABLEstatus, and no post is created if any check fails. A single image still usescontent.media. Theposts.multi-imagecapability is nowavailable, andposts.publishadvertises thecarouselformat. -
7ea7d23: Add
notifications.readfor LinkedIn organization accounts.social.notifications.listanditeratepull organization social-action notifications fromorganizationalEntityNotificationswith offset paging. Member accounts declare the capability asaccount-ineligible, andnotifications.seenisunsupported-by-platformbecause LinkedIn has no seen state.X, Threads, Instagram, YouTube, and TikTok now declare
notifications.readasunsupported-by-platformwith a reason, since none of their official APIs offers a notifications feed. Calls still raiseunsupported_capabilityas before. -
f2137e6: Add LinkedIn video posts.
media.uploadnow accepts one MP4 Blob (75 KB to 500 MB), uploads the parts LinkedIn returns, and finalizes the video without waiting for processing. The new nativevideoStatushelper reads the processing status once per call, and the opt-in nativewaitForVideohelper rereads it at a fixed interval, bounded by a check limit, the operation's elapsed budget, and its abort signal. Publishing reads the status once and creates a post only when the video isAVAILABLE; a video that is still processing returns afailedoutcome with anafter-delayretry disposition and no post. A non-blank attachmentcaptionis sent as the optional video title. The nativeregisterVideomethod is deprecated and still throwsunsupported_capability. -
e711a88: Add
updatePostto the X native module. It edits the text of a recent post throughPOST /2/tweetswithedit_options.previous_post_idand returns a reference to the new version, since X assigns each edit a new post ID. A response without a new ID, or a server failure after dispatch, raisesambiguous_outcomewithreconcile-first. The X manifest now declaresposts.updateas available. Threads, Bluesky, Instagram, and TikTok declareposts.updateasunsupported-by-platform, with the documented reason in each manifest entry. -
bcc36a3: Add
comments.listto the direct X adapter. It lists replies to a post through recent search withconversation_id:<postId>, pages with X'snext_token, and drops the root post. X recent search limits apply: replies from the last 7 days only, page limits from 10 through 100, and a user token withtweet.readandusers.reador an app bearer token. The X capability manifest now declarescomments.read. -
d567532: Add X filtered stream support. The X native module now exposes
stream, an async iterable overGET /2/tweets/search/streamthat opens one connection per iteration, stops onbreakorcontext.signal, raisestimeoutwhen no data or keep-alive arrives withinstallTimeoutMs, and never reconnects on its own.listStreamRules,addStreamRules, anddeleteStreamRulesmanage filtered-stream rules, withdryRunsupport and per-rule errors preserved. All four use the app-onlyappBearerToken. Thestreams.readcapability for X is nowavailable. -
c4cefa8: Add
posts.cancelScheduledto the direct YouTube adapter. It reads the video, confirms it is private with a futurestatus.publishAt, then callsvideos.updatewithpart=statusto clearpublishAtwhile resending the other status fields it read. The video ...
Assets 2
@opencoredev/social-sdk@0.3.0
887402b Minor Changes
- 55993cd: Add X video and GIF chunked upload to the direct adapter. MP4 video (up to 512 MiB) and GIF (up to 15 MiB) Blobs upload via 1 MiB INIT/APPEND/FINALIZE segments with a bounded STATUS poll honoring
check_after_secs. Chunk rejections (413) and failed processing surface as terminalmedia_error. Processing waits never outlast the operation budget, and cancellation reportscancelled. A 403 when attaching a video reportsmissing_permissionwith a message that names the possible duration limit.posts.publishaccepts a single video or GIF per post and advertises thevideoformat, and the native module addsuploadVideoanduploadGif.
Assets 2
@opencoredev/social-sdk@0.2.1
e322038 Patch Changes
- f4d5f8d: Check X's weighted post length with a built-in counter instead of
twitter-text. The package now has no runtime dependencies, so installs no longer pull in the deprecatedcore-js@2. Source maps and declaration maps are no longer published; they pointed at source files that were never in the package.
Assets 2
@opencoredev/social-sdk@0.2.0
504d4f4 Minor Changes
-
38d1a8f: Add the platform features that were missing for launch. X gains user lookup, follower and following lists, likes, mute and block, lists and pinned lists, timelines, mentions, app-only bearer tokens, and working direct messages through both
social.messagesand native access. Bluesky gains follower lists, likes, actor search, lists, moderation reports, unblock, and unmute. Threads gains normalized search, profile reads, and reply hiding. Instagram gains comment hiding and deletion. YouTube gains playlist management, thumbnails, video updates and deletes, captions, subscriptions, search, and comment moderation. LinkedIn gains follower, page, and share statistics.Every implemented operation is now declared
available, with tier, review, and enterprise requirements listed inrequiredScopesandnotes, so apps that hold the platform access can call it. Also fixes graph wiring, X search fields, empty result handling, the X DM endpoint, OAuth account persistence, webhook signature case handling,publishSequenceoutcomes, input validation, and the mock backend.posts.removeFromPlatformnow works on X, Bluesky, Threads, Instagram (Facebook Login), YouTube, and LinkedIn. YouTube videos can be scheduled withpublishAt. Webhook docs now useverifyZernioWebhookandverifyPostForMeWebhook.This release also fixes OAuth for X, TikTok, Instagram, and LinkedIn, Threads container publishing and replies, TikTok publishing states and video listing, YouTube chunked uploads and upload deadlines, Bluesky request headers and facets, X DM fields and follow authorization, Instagram delivery tracking and metrics, cloud backend pagination and analytics, rate-limit handling in the transport, and adapter error mapping in the client.
publishSequencenow checks every item before it starts, requires anidempotencyKey, reports thrown item errors with their index infailures, and stops areplyToPreviouschain when a parent was not published. Package builds now run onprepack, and the release workflow checks the built package before it publishes.Some features are now declared
not-implemented-by-adapterbecause the adapter could not do them correctly: Bluesky video, X video and GIF uploads and filtered streams, LinkedIn multi-image, video, and document posts, and deletion and mentions on Instagram Login.