server: public: support custom `api_url`, default to relative base path
The note is not visible to the blocked user.