Skip to content

3.2.6-sr94.45: Transactional moderation

Choose a tag to compare

@RobinMJD RobinMJD released this 22 Sep 02:15
· 91 commits to main since this release

Transactional administrative moderation

  • Commit a selected user/link/domain/destination-IP ban and all selected related changes atomically. Invalid DNS or a protected administrator leaves no partial bans or audit entries.
  • Add administrator-only moderation/recovery pages, explicit per-record unban and a bounded private audit. Independent related bans are never silently restored.
  • Permanently revoke sessions/recovery tokens/API credentials on user ban/unban, with fresh locked authorization and token-race protection.
  • Preserve claimed-domain ownership/homepage; protect self-administrative deletion/ban and the final active administrator under concurrency.
  • Use SQL-authoritative ban reads and awaited, retryable cache invalidation. Preserve legacy full-key and JSON/form compatibility while rejecting malformed cascade values.
  • Add documented UI/API/recovery behavior, native keyboard/mobile workflows and real SQLite/MySQL/PostgreSQL concurrency coverage.

Migration adds mutation-lock and audit tables without changing existing bans or credentials. Do not downgrade populated audit tables; prefer explicit unban and fresh sign-in instead of restoring old credentials. No WAF/SSO/public-redirect relaxation.

Source validation and publication/deployment are separate gates, tracked in docs/COMMUNITY-FEATURE-ROADMAP.md. This release does not claim completion of the remaining community roadmap or localization work.