Skip to content
76 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)1import { Link, redirect } from "react-router";
2
3import type { Route } from "./+types/account";
4import { DeleteAccountAction } from "../../components/delete-account";
5import { DangerZone } from "../../components/danger-zone";
6import { githubSignIn } from "../../lib/github.server";
7import { page } from "../../lib/meta";
8import { accounts } from "../../lib/services.server";
9import { assertSameOrigin, clientOf, endSession, requireUser, sessionTokenOf } from "../../lib/session.server";
10
11export function meta(args: Route.MetaArgs) {
12 return page(args, { title: "Account · Settings · g1t" });
13}
14
15export async function loader({ request, context }: Route.LoaderArgs) {
16 const user = requireUser(context, request);
17 // What deleting it would take, and anything in the way, shown before
18 // anyone types: workspaces you own alone, each with what billing needs.
19 const [deletion, github] = await Promise.all([
20 accounts.checkAccountDeletion(user).catch(() => null),
21 githubSignIn.account(user).catch(() => null),
22 ]);
23 return {
24 username: user.username,
25 deletion: deletion?.ok ? deletion.value : null,
26 hasPassword: github?.hasPassword ?? true,
27 };
28}
29
30/**
31 * Deleting the account: identity checks the person, the typed username,
32 * the proof that it is them, protection and the workspaces they own alone.
33 * Once it is deleted, this browser is signed out and sent home.
34 */
35export async function action({ request, context }: Route.ActionArgs) {
36 assertSameOrigin(request);
37 const user = requireUser(context, request);
38 const form = await request.formData();
39 if (form.get("intent") !== "delete-account") return null;
40 const password = String(form.get("password") ?? "");
41 const result = await accounts.deleteAccount(user, String(form.get("confirm") ?? ""), {
42 sessionToken: sessionTokenOf(request),
43 password: password || null,
44 client: clientOf(request),
45 });
46 if (!result.ok) return { deleteError: result.error.message, reauth: result.error.code === "reauth_required" };
47 throw redirect("/", { headers: { "set-cookie": await endSession(request) } });
48}
49
50export default function AccountSettings({ loaderData, actionData }: Route.ComponentProps) {
51 const { username, deletion, hasPassword } = loaderData;
52 return (
53 <div className="space-y-8">
54 <section aria-labelledby="username-heading">
55 <h2 id="username-heading" className="font-medium">
56 Username
57 </h2>
58 <p className="mt-1 text-sm text-muted">
59 You are <span className="font-mono text-fg">{username}</span>. Your profile is at{" "}
60 <Link to={`/${username}`} className="text-accent underline-offset-4 hover:underline">
61 g1t.sh/{username}
62 </Link>
63 .
64 </p>
65 </section>
66 <DangerZone>
67 <DeleteAccountAction
68 username={username}
69 deletion={deletion}
70 hasPassword={hasPassword}
71 error={actionData?.deleteError}
72 />
73 </DangerZone>
74 </div>
75 );
76}

This file's history is long; its oldest lines are credited to the oldest commit read.