Handlingar
Features #60
öppen
CA
Features #20: P1 — Community experience and polish
[P1] Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area
Features #60:
[P1] Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area
Status:
Planned
Prioritet:
Normal
Tilldelad:
-
Startdatum:
2026-08-29
Deadline:
% Klart:
10%
Beräknad tid:
Reported by:
Beskrivning
Imported from the pre-Redmine CookieMonsters TODO during the 2026-08-29 migration.
Original priority: P1 — Community experience and polish
- Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area:
- use the existing top-level Gallery concept as a dedicated place for members to share normal personal photos such as pets, food, trips, projects, gardens and everyday life;
- let each member create folders/albums and nested child folders, choose an optional cover image and upload multiple photos into them;
- add comments and the shared CookieMonsters reactions to individual Gallery photos for viewers who currently have permission to see that photo;
- show compact counts for Like / Love / Agree / Hugs / Happy / Sad and let the photo owner see who reacted to each image; one member may have at most one active reaction per photo and can change/remove it again;
- show comments as a soft conversation directly with the photo, with normal author/avatar/timestamp presentation when the commenter has not chosen privacy;
- when reacting to a photo, let the reactor optionally choose Hide my identity from other viewers for that reaction;
- when posting a comment, let the commenter optionally choose Hide my identity from other viewers for that specific comment;
- the privacy choice hides the actor only from other ordinary Gallery viewers: the photo owner must always be able to see exactly who reacted or wrote the comment, even when everybody else sees the interaction anonymously/private;
- for a privacy-hidden reaction, other viewers may still see the relevant reaction count but must not be able to reveal the reactor through a people list, API response, activity feed, notification, tooltip or copied URL;
- for a privacy-hidden comment, other viewers may see the comment text with a neutral label such as Private member / Anonymous to viewers, but must not receive the real username, avatar, profile link or other identifying metadata; the photo owner sees the real author and should also see that the author chose to hide their identity from others;
- the member who created a private reaction/comment must still be able to recognize and manage their own interaction normally;
- store the real actor relationship server-side so ownership, reaction change/remove, delete, blocking and moderation remain reliable; the privacy option controls disclosure to other viewers, not whether CookieMonsters knows which signed-in account created the interaction;
- enforce comment/reaction identity privacy server-side, not only by hiding names in HTML/CSS, and make sure counts, notifications, search/activity surfaces and APIs cannot accidentally leak hidden identities;
- Gallery comments/reactions inherit the photo's effective access: somebody who loses access to the photo must also lose access to its comments, reactions and activity immediately;
- block rules override Gallery social interactions too, so blocked members must not gain identity/content visibility through reactions or comments;
- allow members to delete their own Gallery comments and remove/change their own reactions; photo owners/admin moderation controls can be defined consistently with the existing screenshot-comment moderation model;
- every newly created Gallery folder is SFW by default;
- an owner who is age-eligible and has explicitly enabled 18+/NSFW content mode may manually mark a folder NSFW / 18+;
- an NSFW folder may contain adult/mature photos that are allowed by CookieMonsters rules, law and consent requirements; NSFW must never mean “anything is allowed” or bypass moderation/prohibited-content rules;
- NSFW classification should inherit downward: content inside an NSFW folder is treated as NSFW automatically, and a child item must never downgrade the effective age-gate of an NSFW parent;
- a SFW folder may contain a separately marked NSFW child folder later, but no NSFW cover/thumbnail/count/activity preview may leak through the SFW parent view;
- members who are under 18 or who have not enabled NSFW content mode must not be able to discover that an NSFW folder exists: hide its name, cover, photo count, activity, search result, profile/gallery card and direct-link metadata, and reject direct access server-side;
- Gallery access uses the standard visibility scopes GLOBAL / SITE / FRIENDS / COMMUNITY / ME ONLY and must also support specific people and owner-created people lists;
- GLOBAL = visible to all signed-in CookieMonsters members and eligible for the global Gallery experience, never an open unauthenticated public file;
- SITE = visible to signed-in site members when directly shown/linked, without necessarily promoting the folder/photos into the global Gallery feed;
- FRIENDS = accepted friends only;
- COMMUNITY = one selected community initially, with room for multiple communities later;
- ME ONLY = owner only;
- PEOPLE = choose one or more individual CookieMonsters members who may see the folder/photos even when the broader site audience cannot;
- add private reusable access lists owned by each member, e.g. My Best Friends, Family, Palia Crew or any custom name; the owner can add/remove as many individual members as they want from a list;
- Gallery permission UI should make this natural, e.g. Access → List → My Best Friends or Access → People → [selected members], alongside the normal SITE/FRIENDS/GLOBAL/COMMUNITY choices;
- list names and list membership are private management data for the list owner; recipients do not need to be told which private list granted them access;
- when a folder grants access to a custom list, only members currently in that list may discover or open the folder; everybody else should behave as if the folder does not exist at all;
- changing membership of a reusable list must immediately change access to every folder/image that references that list, without manually editing every folder;
- allow a folder to grant access to more than one explicit audience where useful (for example a community plus one person or a private list), but present an unambiguous Who can see this? summary before saving so the owner cannot accidentally widen access;
- block relationships override Gallery grants: a blocked member must not regain discovery/access merely because they are in a FRIENDS scope, custom list, community or explicit people grant;
- if no Gallery visibility has been chosen yet, fail safely to ME ONLY rather than accidentally publishing a new folder;
- images and child folders inherit the parent folder's audience permissions by default;
- a child item may be made more restrictive, but must never silently widen access beyond a more restrictive parent folder; effective access is constrained by the full folder hierarchy plus age-gating and block rules;
- moving an image/folder to another folder must immediately recalculate effective access and NSFW state;
- permission, list-membership and NSFW changes must take effect immediately for folder discovery, originals, thumbnails, previews and any Gallery feed/profile cards;
- people without effective access must not see the folder in member profiles, Gallery browsing, search, counts, activity, recommendations, notifications or through copied direct URLs.
CM-TODO-ID:423da0843f2b9f255a00
Future notes, acceptance criteria and status changes belong in this Redmine issue.
CA Uppdaterad av Codex API för ungefär en månad sedan
- Status ändrad från New till Planned
- % Klart ändrad från 0 till 10
Migration reconciliation: aligned imported TODO status with the CookieMonsters Redmine plan.
Handlingar