Moderation & anti-spam

Pipeline (every POST)

  1. Honeypot — filled fields get a fake success, nothing is stored.
  2. Signed time trap — the thread fetch issues an HMAC form token; posts faster than ~2s or with a stale token are rejected or flagged.
  3. Rate limits — per-site minimum interval + daily cap, enforced by a per (site, ip-hash) Durable Object token bucket.
  4. Turnstile — verified server-side when enabled.
  5. Word filters — keyword or regex; matched comments are blocked or held, with events logged for the health panel.
  6. Spam heuristics — link floods, URL shorteners, shouting, duplicates, author history.
  7. Moderation mode — manual / auto / trusted-auto decides approved, pending or spam.

Trusted members

Approvals raise a member's trust score; after the configurable threshold they are trusted and (in trusted-auto mode) post instantly. Spam verdicts raise the spam count; spam-heavy authors get flagged and always wait for review. Badge promotion pauses for flagged authors.

Queue

The moderation desk supports approve / spam / delete / pin, batch actions, reader reports with required reasons and per-reader dedup, plus a full audit trail of every action.

Notifications

Five events email out via the queue: pending approval, report filed, reply, approved and @mention. Templates are editable per site, recipients configurable, and every email carries a one-click opt-out (hash-only storage).