Projekt

Allmänt

Profil

Handlingar

Features #60

öppen
CA

Features #20: P1 — Community experience and polish

[P1] Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area

Features #60: [P1] Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area

Tillagd av Codex API för ungefär en månad sedan. Uppdaterad för ungefär en månad sedan.

Status:
Planned
Prioritet:
Normal
Tilldelad:
-
Startdatum:
2026-08-29
Deadline:
% Klart:

10%

Beräknad tid:
Reported by:

Beskrivning

Imported from the pre-Redmine CookieMonsters TODO during the 2026-08-29 migration.

Original priority: P1 — Community experience and polish

  • Build a real member Gallery section for general photo sharing, separate from the game-focused Screenshots area:
    • use the existing top-level Gallery concept as a dedicated place for members to share normal personal photos such as pets, food, trips, projects, gardens and everyday life;
    • let each member create folders/albums and nested child folders, choose an optional cover image and upload multiple photos into them;
    • add comments and the shared CookieMonsters reactions to individual Gallery photos for viewers who currently have permission to see that photo;
    • show compact counts for Like / Love / Agree / Hugs / Happy / Sad and let the photo owner see who reacted to each image; one member may have at most one active reaction per photo and can change/remove it again;
    • show comments as a soft conversation directly with the photo, with normal author/avatar/timestamp presentation when the commenter has not chosen privacy;
    • when reacting to a photo, let the reactor optionally choose Hide my identity from other viewers for that reaction;
    • when posting a comment, let the commenter optionally choose Hide my identity from other viewers for that specific comment;
    • the privacy choice hides the actor only from other ordinary Gallery viewers: the photo owner must always be able to see exactly who reacted or wrote the comment, even when everybody else sees the interaction anonymously/private;
    • for a privacy-hidden reaction, other viewers may still see the relevant reaction count but must not be able to reveal the reactor through a people list, API response, activity feed, notification, tooltip or copied URL;
    • for a privacy-hidden comment, other viewers may see the comment text with a neutral label such as Private member / Anonymous to viewers, but must not receive the real username, avatar, profile link or other identifying metadata; the photo owner sees the real author and should also see that the author chose to hide their identity from others;
    • the member who created a private reaction/comment must still be able to recognize and manage their own interaction normally;
    • store the real actor relationship server-side so ownership, reaction change/remove, delete, blocking and moderation remain reliable; the privacy option controls disclosure to other viewers, not whether CookieMonsters knows which signed-in account created the interaction;
    • enforce comment/reaction identity privacy server-side, not only by hiding names in HTML/CSS, and make sure counts, notifications, search/activity surfaces and APIs cannot accidentally leak hidden identities;
    • Gallery comments/reactions inherit the photo's effective access: somebody who loses access to the photo must also lose access to its comments, reactions and activity immediately;
    • block rules override Gallery social interactions too, so blocked members must not gain identity/content visibility through reactions or comments;
    • allow members to delete their own Gallery comments and remove/change their own reactions; photo owners/admin moderation controls can be defined consistently with the existing screenshot-comment moderation model;
    • every newly created Gallery folder is SFW by default;
    • an owner who is age-eligible and has explicitly enabled 18+/NSFW content mode may manually mark a folder NSFW / 18+;
    • an NSFW folder may contain adult/mature photos that are allowed by CookieMonsters rules, law and consent requirements; NSFW must never mean “anything is allowed” or bypass moderation/prohibited-content rules;
    • NSFW classification should inherit downward: content inside an NSFW folder is treated as NSFW automatically, and a child item must never downgrade the effective age-gate of an NSFW parent;
    • a SFW folder may contain a separately marked NSFW child folder later, but no NSFW cover/thumbnail/count/activity preview may leak through the SFW parent view;
    • members who are under 18 or who have not enabled NSFW content mode must not be able to discover that an NSFW folder exists: hide its name, cover, photo count, activity, search result, profile/gallery card and direct-link metadata, and reject direct access server-side;
    • Gallery access uses the standard visibility scopes GLOBAL / SITE / FRIENDS / COMMUNITY / ME ONLY and must also support specific people and owner-created people lists;
    • GLOBAL = visible to all signed-in CookieMonsters members and eligible for the global Gallery experience, never an open unauthenticated public file;
    • SITE = visible to signed-in site members when directly shown/linked, without necessarily promoting the folder/photos into the global Gallery feed;
    • FRIENDS = accepted friends only;
    • COMMUNITY = one selected community initially, with room for multiple communities later;
    • ME ONLY = owner only;
    • PEOPLE = choose one or more individual CookieMonsters members who may see the folder/photos even when the broader site audience cannot;
    • add private reusable access lists owned by each member, e.g. My Best Friends, Family, Palia Crew or any custom name; the owner can add/remove as many individual members as they want from a list;
    • Gallery permission UI should make this natural, e.g. Access → List → My Best Friends or Access → People → [selected members], alongside the normal SITE/FRIENDS/GLOBAL/COMMUNITY choices;
    • list names and list membership are private management data for the list owner; recipients do not need to be told which private list granted them access;
    • when a folder grants access to a custom list, only members currently in that list may discover or open the folder; everybody else should behave as if the folder does not exist at all;
    • changing membership of a reusable list must immediately change access to every folder/image that references that list, without manually editing every folder;
    • allow a folder to grant access to more than one explicit audience where useful (for example a community plus one person or a private list), but present an unambiguous Who can see this? summary before saving so the owner cannot accidentally widen access;
    • block relationships override Gallery grants: a blocked member must not regain discovery/access merely because they are in a FRIENDS scope, custom list, community or explicit people grant;
    • if no Gallery visibility has been chosen yet, fail safely to ME ONLY rather than accidentally publishing a new folder;
    • images and child folders inherit the parent folder's audience permissions by default;
    • a child item may be made more restrictive, but must never silently widen access beyond a more restrictive parent folder; effective access is constrained by the full folder hierarchy plus age-gating and block rules;
    • moving an image/folder to another folder must immediately recalculate effective access and NSFW state;
    • permission, list-membership and NSFW changes must take effect immediately for folder discovery, originals, thumbnails, previews and any Gallery feed/profile cards;
    • people without effective access must not see the folder in member profiles, Gallery browsing, search, counts, activity, recommendations, notifications or through copied direct URLs.

CM-TODO-ID:423da0843f2b9f255a00

Future notes, acceptance criteria and status changes belong in this Redmine issue.

Handlingar

Finns även som: PDF Atom