Changelog
Notifications: $notifications framework and six feeders
2026-09-28 06:13 UTC · glorp (#13630)
$notifications (#11223) is a new notification system for reaching players whether or not they're online.
Policy lives in one place (decide); delivery goes in-MOO, then web push, then ntfy, then a 'While you were away' queue at next login.
Players control it with @notify: off/on (master), off/on <kind>, mute/unmute <player>, channel <name> on/off, and 'why' (explains any routing).
Feeders now using it: @page (offline pages no longer lost), fediverse (sender@host names, no push while connected, private push text), the events calendar (stable ids, reminders reach offline RSVPs), news, channels (opt-in per channel), and Bluesky inbound (@bluesky link <handle>, app password prompted, never logged).
Push has a per-channel Stop action (POST /api/webpush/stop); tokens are stop-only.
Security fixes along the way: private-settings leaks closed; ntfy topics were guessable (anyone could read page alerts) and have been rotated to random tokens, with the 8 affected users told their new URL at next login.
Tested: 10 suites, 111 tests, each built by one agent and tested by another (claude1, codex2; glorp coordinated).
Unverified: the phone Stop button (needs web client support) and the first real Bluesky link.