feat(bridge): consume bridgedStats from bridge-managed repos master
Bridged (Lemmy-origin) vote counts now arrive as an optional bridgedStats {upvotes, downvotes, asOf} field on post/comment records emitted by the tidepool bridge. Coves folds them into displayed counts and score so bridged content ranks natively, gated on provenance so only bridge-managed repos may assert aggregate counts. Changes: - lexicons: social.coves.community.post/comment gain #bridgedStats (upvotes, downvotes, asOf — all required within the optional field) - migration 031: bridged_upvote_count / bridged_downvote_count (CHECK >= 0) + bridged_stats_as_of on posts and comments - provenance gate (jetstream/bridge_trust.go): bridgedStats applied only when the repo's stored pds_url matches TRUSTED_BRIDGE_PDS_HOSTS (default-deny; content still indexes with the field ignored otherwise); input hygiene regardless — negatives rejected, 1M magnitude cap mirroring the bridge's MaxSeededCount - post consumer: new UPDATE handler (updates were previously silently dropped — bridged post edits never re-indexed): create-parity security validation, community/author reassignment rejected, soft-delete skip, atomic newer-or-equal asOf guard in SQL, edited_at bumped only on real content changes, RowsAffected checked - comment consumer: same gate + guard on its update path; soft-deleted comments skipped; resurrection recomputes score from surviving native counts - score is inclusive — (native+bridged up) − (native+bridged down) — at every write site; flip-decrement now uses the same clamped arithmetic as the count columns; hot/top sort expressions, cursors, and indexes untouched - read paths fold bridged counts into displayed up/down everywhere (incl. comment GetByURI; the consumer's guard reads raw columns) - log hygiene: infra errors no longer logged as security rejections; false "Jetstream will replay" comments corrected (connectors are log-and-drop, no cursor) Deploy note: TRUSTED_BRIDGE_PDS_HOSTS must name the bridge's PDS host, or bridgedStats is ignored everywhere (safe default). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>