Skip to content

Add platform administration, abuse reporting, and moderation operations #249

Description

@Vinosaamaa

Parent

#107 (identified by #238)

What to build

Give Chanter operators a least-privilege platform administration and moderation workflow. Users must be able to block/report abuse, and authorized operators must be able to investigate and act without direct database access, hidden superuser headers, or unaudited destructive changes.

Acceptance criteria

  • Platform roles are distinct from Study Server Owner/Instructor roles and are granted/revoked through a controlled, audited process.
  • Users can block/unblock peers and report a user, Direct Message, Course/Study Server message, resource, or Study Server with a reason and evidence reference.
  • Blocking immediately prevents new friend requests, DMs, calls, and relevant presence exposure while preserving evidence according to policy.
  • Operators can search users/Study Servers/reports, review scoped evidence, assign/resolve/escalate reports, and record internal notes.
  • Operators can suspend/reactivate accounts, quarantine content, and restrict a Study Server with confirmation, reason, duration, notifications, and appeal/support path.
  • Every privileged read and mutation is immutable-audited with actor, target, reason, timestamp, request correlation, and before/after state where appropriate.
  • Admin routes/APIs are denied to all product roles, protected by MFA-ready policy, rate limited, and excluded from ordinary navigation.
  • Tests cover role escalation attempts, cross-tenant evidence access, blocked-user behavior, suspension enforcement across services, and audit completeness.

Blocked by

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendBackend servicesfrontendFrontend applicationopsProject operationspost-launchAfter Public Launch #86–#104; see post-launch-ui-backlog.mdready-for-agentReady for agent implementationsecuritySecurity and permissionsstoryVertical-slice story

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions