feat(comments) : filter abusive language and prevent spam
CI / Verify (push) Successful in 1m41s
CI / Build immutable images and deploy (push) Successful in 2m30s

This commit is contained in:
2026-10-08 04:45:45 +07:00 Unverified
parent 0f0e983bcb
commit 20c52fac04
8 changed files with 235 additions and 44 deletions
+10
View File
@@ -208,6 +208,16 @@ selected guide (or all guides) read for that admin. Hiding a root also hides its
are recorded in the activity log. Comment reads and legacy attachment redirects
are not cached; guide content caches are independent of discussions.
Comment writes (including replies and edits) are limited per account across all
guides to one every 5 seconds, 5 per minute, and 30 per hour using shared Redis.
New text comments cannot repeat the same normalized text within 5 minutes;
failed uploads or saves release that duplicate reservation. Edits and image-only
comments still use the write limits. Before uploading images or saving, the server
rejects a focused Thai/English abusive-term list, common English spelling
obfuscations, more than 3 links, 20 identical consecutive characters, and a word
or short phrase repeated 8 times. The rules live in `lib/comments/moderation.ts`;
they are heuristic text filters, not image moderation or an automated review queue.
The comment migration must run before deploying these pages. For PostgreSQL
integration verification, point `DATABASE_INTEGRATION_URL` at a migrated test or
development database and run `bun run test tests/comments.integration.test.ts`.