A community based topic aggregation platform built on atproto

feat(moderation): add removal core with comment removeContent/restoreContent master

Task 03 of the admin moderation PRD: land the moderation mutation core with its first subject type. Comments can be removed and restored by instance admins, and a successful mutation is fully enforced on every comment surface. Post subjects are rejected with InvalidSubject until chunk 04. - Migration 049 adds the moderation state tables: moderation_actions, moderation_subjects, moderation_decisions, moderation_idempotency_keys and moderation_media_blocks (no FKs to posts/comments). - removeContent/restoreContent for comments, with fingerprint-bound idempotency keys scoped to (actor, authority), a subject version token with StateConflict on mismatch, ContentChanged on CID drift, the per-actor live-key cap, and an hourly expiry sweep. - Removed comments render as the overlay-only placeholder (deletionReason: moderator, moderation.state: removed, record absent, zero votes, preserved replyCount) and are excluded from actor.getComments. - Media blocks keyed by (owner DID, blob CID), plus ownerless CID blocks for illegal-content removals; restore deactivates only that action's blocks. - The image proxy enforces blocks against the canonical CID, publishes blocks synchronously through striped locks, and purges cached bytes with a restart-safe purge sweep. - A tolerant embeds.CommentImageCIDs enumerator that also covers legacy cid blobs. - The comment consumer reconciles media blocks when it updates or recreates a subject with an active removal. - T0/T1/T2 contracts for validation, idempotency, concurrency, media enforcement and the end-to-end remove/restore arc. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>


+8084 -166
79 changed files