Routes & Settings

What the express adapter mounts, and the settings the module takes.

Mounting

bxsnew bxModules.bxactivitypub.adapters.express().mount( app, ap, options )

Mount it before your own routes. Account and post routes answer ActivityPub requests (Accept: application/activity+json); a browser asking for the same path is redirected to the url from your host, and anything else passes through to your app.

The adapter reads its own settings (the last four in the settings table); options overrides them for one mount. inboxRateLimit keys on req.ip, so behind a proxy set trust proxy or trust proxy header first.

Routes

MethodPath
GET/.well-known/webfingeracct:name@host or an account URL
GET/.well-known/nodeinfo, /nodeinfo/2.1NodeInfo
GET/actorInstance account; signs outgoing requests
GET/u/{name}, /c/{name}Person and Group accounts
POST/u/{name}/inbox, /c/{name}/inbox, /inboxFollow, Like, Announce (boost) and their Undo; account deletions; with IRemoteReplies, replies (Create/Update/Delete of a Note)
GET/u/{name}/outbox, /c/{name}/outboxEmpty collection
GET/u/{name}/followers, /c/{name}/followersFollower count only
GET/post/{id}Posts
GET/comment/{id}Comments that went out
GET/activities/{type}/{uuid}Every activity that was sent

Ids are these stable paths, never slugs — slugs change, ids can't. Each object's url points at its human-facing page instead.

Settings

Every setting has a default in the module's ModuleConfig.bx. Override any of them in your app's boxlang.json; ${env.NAME:default} placeholders work too:

json{
	"modules": {
		"bxactivitypub": {
			"settings": {
				"datasource": "${env.AP_DATASOURCE:mydb}",
				"inboxRateLimit": 300
			}
		}
	}
}

Settings passed in code, to new ActivityPub( host, settings ) or mount( app, ap, options ), win over both. ap.getSettings() returns the settings in effect.

SettingDefault
datasourcerequiredWhere the Ap* tables live
maxAgeSeconds3600Oldest signed Date accepted on incoming requests
maxFutureSeconds300Furthest-ahead signed Date accepted
httpTimeoutSeconds10Outgoing connect and request timeout
userAgentbx-activitypub/{version} (+{baseUrl})Outgoing User-Agent
maxResponseBytes1048576Largest response read from another server
remoteActorTtlSeconds86400How long a fetched remote account (inbox, key) is used before refetching
remoteActorFailureSeconds300How long a remote account that couldn't be fetched isn't tried again
softwareName, softwareVersionbx-activitypub, module versionReported in NodeInfo
threadMaxPostAgeDays30Posts older than this aren't followed by fetchThreads()
threadMaxDepth3Levels below a delivered reply that fetchThreads() follows
threadMaxNewPerRun50New replies fetched per fetchThreads() run
threadWalkMinutes30How often each reply's replies are re-read
maxInboxBytes262144Largest inbox POST body accepted
inboxRateLimit120Inbox POSTs per client IP per minute; 0 for no limit
deliveryIntervalMs5000Delivery worker tick; 0 to run ap.processDeliveries() yourself
threadIntervalMs1800000How often whole threads are fetched; 0 to run ap.fetchThreads() yourself