feat(admin): add origin-verified delete sweep endpoint master
Deletes the bridge dropped are not self-healing: the activity is consumed, so nothing re-delivers it and the record stays live forever. The authorization fix stops new drops but cannot repair the backlog left by the old rule (~50 ids in prod logs, and only for as long as logs are retained). POST /admin/objects/sweep-deleted takes a list of ap_ids and applies a delete only where the ORIGIN says the content is gone — HTTP 410 or an ActivityPub Tombstone body, the shapes Lemmy serves. A plain 404 never deletes: ap.Client folds 404/401/403 together, so a 404 cannot distinguish "deleted" from "not visible to us" (secure-mode instances hide objects that way), and an origin outage must never cost bridged records. Because the fetch IS the authorization, it is authority-pinned: an open-redirecting origin would otherwise bounce the check to a host serving 410 and take live records with it. Changes: - SweepDeleted per ap_id with explicit typed outcomes; only a verified tombstone mutates. Unknown ids return before any fetch, so an admin token cannot turn the endpoint into a general fetch oracle; actor profiles are never swept (the Delete(Actor) scrub is terminal and deliberate). - Marker recorded before the record delete, matching handleDelete, on a context detached from the request: a client disconnect mid-batch would otherwise leave a record deleted with its mapping live and nothing logged. - Batch capped at 200 with the body read through decodeJSONBody; the response reports requested/swept/deleted/failed/truncated so a partial run is distinguishable from a complete one, and every failure is logged. - Endpoint documented in the README; Admin/AdminOptions docs corrected to list the endpoints that exist and the options that are actually required. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>