Repository navigation
3.2.6-sr94.45: Transactional moderation
Transactional administrative moderation
- Commit a selected user/link/domain/destination-IP ban and all selected related changes atomically. Invalid DNS or a protected administrator leaves no partial bans or audit entries.
- Add administrator-only moderation/recovery pages, explicit per-record unban and a bounded private audit. Independent related bans are never silently restored.
- Permanently revoke sessions/recovery tokens/API credentials on user ban/unban, with fresh locked authorization and token-race protection.
- Preserve claimed-domain ownership/homepage; protect self-administrative deletion/ban and the final active administrator under concurrency.
- Use SQL-authoritative ban reads and awaited, retryable cache invalidation. Preserve legacy full-key and JSON/form compatibility while rejecting malformed cascade values.
- Add documented UI/API/recovery behavior, native keyboard/mobile workflows and real SQLite/MySQL/PostgreSQL concurrency coverage.
Migration adds mutation-lock and audit tables without changing existing bans or credentials. Do not downgrade populated audit tables; prefer explicit unban and fresh sign-in instead of restoring old credentials. No WAF/SSO/public-redirect relaxation.
Source validation and publication/deployment are separate gates, tracked in docs/COMMUNITY-FEATURE-ROADMAP.md. This release does not claim completion of the remaining community roadmap or localization work.