A community based topic aggregation platform built on atproto

feat(moderation): admin NSFW label apply and retract master

Lets admins apply and retract a URI-scoped nsfw classification on posts (PRD_ADMIN_MODERATION §1, §5.5, §6, §14.2-§14.4). NSFW is blur/reveal only: feed membership, ranking and the author's record are untouched, and removal stays a separate decision that takes precedence. - Endpoints: social.coves.moderation.labelContent and retractContentLabel are admin procedures behind RequireInstanceAdmin, built on the shared idempotent mutation core (expectedVersion, idempotency keys, stored results). The idempotency fingerprint includes the label value, so the same key with another value is IdempotencyConflict. labelContent accepts post subjects only (InvalidSubject for comments) and only the value nsfw (UnsupportedLabel otherwise, !takedown included); a redundant apply is unchanged. retractContentLabel reverses only the active local label action; removals, restores, foreign or superseded actions are InvalidDecision. reviewedSubject follows the restore rules, and an author-deleted post retracts without it and stays unavailable. - Post views: postView.moderation.contentLabels is filled from one SQL aggregate over active label decisions on every post surface (post.get, actor.getPosts, community, all, timeline and Discover feeds, searchPosts, the getComments thread header). Labels persist across CID-changing edits, record.labels is never rewritten, and removed posts are served as #moderatedPost without labels. - Modlog: NSFW label applies and retractions are left out of the public listActions log, while listAdminActions keeps them (user decision 2026-09-30). - Reasons: doxing and illegal-content are Remove-only reasons and are rejected with UnsupportedReason on label and retract (user decision 2026-09-30). - getSubjectState lists localLabels and reads them in a read-only repeatable-read snapshot without row locks, so a concurrent retraction no longer returns 503. - Golden pins cover the persisted idempotency fingerprints and stored result JSON. - No migration. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>