Resolved. A compromised admin token could previously promote accounts
or approve/reject moderation flags with no durable record. backend/src/admin-audit
now provides an append-only admin_audit_events table (actor, action, target,
a SHA-256 payload hash, correlation id, timestamp). A row is written on every
role change (UsersController#updateUserRole, admin-only) and every
moderation decision (ModerationService#reviewFlag). The log is readable via
GET /v1/admin/audit-log (admin-only, 403 otherwise, paginated); there is no
update or delete endpoint for audit rows.
Resolved. The canonical runtime stack is backend/src/auth-module with
backend/src/users. The deprecated src/auth, src/users-module, and
src/refresh-module trees were removed. The global throttler lives under
src/common/guards, and historical schema migrations live under
src/database/migrations, so deleting deprecated code no longer removes
production controls or migration history.