A community based topic aggregation platform built on atproto

feat(moderation): add instance-admin authority and getSubjectState master

Introduce the internal/core/moderation domain with an operator-managed admin DID allowlist, DID-verified admin authorization, and the getSubjectState read over content the AppView already indexes. No mutation storage in this chunk. - MODERATION_ADMINS allowlist config (comma-separated DIDs; empty grants nobody; a non-DID entry fails Load naming the variable), added to the test clear list, with prod compose and .env.prod.example entries. - RequireInstanceAdmin middleware accepting OAuth sealed sessions and indigo-validated PDS service JWTs (aud INSTANCE_DID, lxm bound to the request NSID). Answers 401/403/503 without logging tokens or IPs; caller-supplied actor/authority fields are never read. - Shared authenticateSealedSession helper that fails closed. - moderation.Service.GetSubjectState and the SubjectReader over the existing post and comment repos (present/deleted/unavailable record state, opaque v0 version token). - Sentinels for every §14.5 error code and their HTTP mapping; authorization precedes subject errors. - social.coves.moderation.getSubjectState route, registered as authRequired; moderation NSIDs stay AppView-served and out of the PDS OAuth scope list. - CI bootstrap of two moderation admin PDS accounts whose DIDs are passed to the AppView as MODERATION_ADMINS. - T2 subject-state contract, excluded from test-e2e-dev. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>