Summary
Implement backend API services for a content moderation system that allows users to flag inappropriate content and prevents caching/serving of blocked CIDs in the Auto-Files Gateway. User interface components will be implemented separately in the Auto-Drive Gateway and the Auto-Drive frontend. See auto-drive issue 435 for more details on frontend.
Problem Description
Currently, the Auto-Files Gateway has no mechanism to handle inappropriate or illegal content. Once content is cached by the file-retriever service, it remains accessible until cache expires, with no immediate removal capability. This presents potential legal and operational risks.
Proposed Solution
Add a content flagging system with manual review workflow:
- Flagging API:
POST /files/:cid/flag endpoint to accept user reports
- Review Queue: Store flagged content for admin review
- Admin Review Interface: Endpoints for reviewing and approving/rejecting flags
- Blocklist Management: Maintain a list of admin-approved blocked CIDs
- Cache Integration: Check blocklist before serving/caching files
Technical Approach (Manual Review MVP)
Scope: Backend API Services Only
This implementation focuses on API endpoints only. The user interface for flagging content will be implemented separately in the Auto-Drive Gateway UI.
- Review Queue Storage: JSON file or database storing pending flagged content with metadata
- Blocklist Storage: Separate JSON file or database storing admin-approved blocked CIDs
- Integration: Check blocklist in
fileComposer.get() and file controller
- Error Response: HTTP 451 "Unavailable For Legal Reasons" for blocked content
New API Endpoints
// User flagging
POST /files/:cid/flag // Flag content for review (authenticated?)
// Admin review queue
GET /admin/flags/pending // List pending flagged content (admin)
POST /admin/flags/:reportId/approve // Approve flag → add to blocklist (admin)
POST /admin/flags/:reportId/reject // Reject flag → keep content active (admin)
// Admin blocklist management
GET /admin/blocklist // List blocked content (admin)
DELETE /admin/blocklist/:cid // Remove from blocklist (admin)
Configuration
ENABLE_CONTENT_FLAGGING=true
BLOCKLIST_PATH=./.cache/blocklist.json
FLAGGING_QUEUE_PATH=./.cache/flagging-queue.json
ADMIN_API_KEY=admin_secret_key
MAX_REPORTS_PER_IP=10
MAX_REVIEW_QUEUE_SIZE=1000
Integration Points
- Cache Layer: Modify
fileComposer.get() to check blocklist first
- File Controller: Add blocklist check before serving files
- Cache Eviction: Remove flagged content from existing cache
- Authentication: Reuse existing auth middleware + new admin auth
UI Integration with Auto-Drive
While this repository provides the backend API services only, the user-facing flagging interface will be implemented in the Auto-Drive Gateway which will provide:
- File Preview Interface: View files with integrated flagging controls
- Flagging Form: User-friendly form for reporting inappropriate content
- Admin Dashboard: Web interface for reviewing flagged content and managing blocklist
- Integration: JavaScript client to call the flagging APIs from this service
Manual Review Workflow
User Flags Content
- User calls
POST /files/:cid/flag with reason and description
- System validates CID exists and user hasn't exceeded rate limits
- Flag added to review queue (not immediately blocked)
- User receives confirmation with report ID and estimated review time
Admin Reviews Content
- Admin calls
GET /admin/flags/pending to see flagged content
- Admin examines content, reason, and any supporting information
- Admin makes decision: approve (block content) or reject (keep active)
- System logs decision with admin ID and reasoning
Content Blocked/Unblocked
- If approved: CID added to blocklist, removed from cache if present
- If rejected: Flag marked as resolved, content remains accessible
- Audit trail maintained for all decisions
Security Considerations
- Rate limiting on flagging endpoint (prevent spam flagging)
- Admin-only review and blocklist management
- IP-based abuse prevention
- Audit logging for all moderation actions
- Separate admin authentication key
Alternative Approaches Considered
- Immediate Blocking: Faster response but high abuse risk (rejected)
- Threshold-Based: Multiple flags required before action
- External Service: Better for multi-instance deployments but adds infrastructure
The manual review approach was selected to balance content safety with protection against abuse while maintaining simplicity for the MVP.
Summary
Implement backend API services for a content moderation system that allows users to flag inappropriate content and prevents caching/serving of blocked CIDs in the Auto-Files Gateway. User interface components will be implemented separately in the Auto-Drive Gateway and the Auto-Drive frontend. See auto-drive issue 435 for more details on frontend.
Problem Description
Currently, the Auto-Files Gateway has no mechanism to handle inappropriate or illegal content. Once content is cached by the file-retriever service, it remains accessible until cache expires, with no immediate removal capability. This presents potential legal and operational risks.
Proposed Solution
Add a content flagging system with manual review workflow:
POST /files/:cid/flagendpoint to accept user reportsTechnical Approach (Manual Review MVP)
Scope: Backend API Services Only
This implementation focuses on API endpoints only. The user interface for flagging content will be implemented separately in the Auto-Drive Gateway UI.
fileComposer.get()and file controllerNew API Endpoints
Configuration
Integration Points
fileComposer.get()to check blocklist firstUI Integration with Auto-Drive
While this repository provides the backend API services only, the user-facing flagging interface will be implemented in the Auto-Drive Gateway which will provide:
Manual Review Workflow
User Flags Content
POST /files/:cid/flagwith reason and descriptionAdmin Reviews Content
GET /admin/flags/pendingto see flagged contentContent Blocked/Unblocked
Security Considerations
Alternative Approaches Considered
The manual review approach was selected to balance content safety with protection against abuse while maintaining simplicity for the MVP.