Skip to content
74 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Merge account deletion: soft delete for 30 days, staff restore and purge, ghost for what remains (identity 0037)1/**
2 * Deleting an account. Mirrors `crates/contracts/src/account_deletion.rs`;
3 * identity's `account_deletion.rs` does it.
4 *
5 * A person deletes their own account from Settings, typing their username
6 * and proving it is them; g1t's staff can delete one from sudo with a
7 * reason. Neither works while the account is the only owner of a live
8 * workspace, or for a protected account. It is soft first: everything it
9 * could sign in with ends at once and it leaves every workspace, and it is
10 * kept for `ACCOUNT_RESTORE_DAYS` for staff to restore. Then it is purged,
11 * its username is never given to anyone again, and what it wrote shows as
12 * `GHOST_USERNAME`. There is no API route for it: the site and sudo only.
13 */
14
15/** How long a deleted account is kept, for g1t's staff to restore, before it is purged. */
16export const ACCOUNT_RESTORE_DAYS = 30;
17
18/** Who wrote what a purged account wrote. Reserved: nobody may register it. */
19export const GHOST_USERNAME = "ghost";
20
21/** `ghost`'s account id. */
22export const GHOST_ID = "usr_ghost";
23
24/** A live workspace the account is the only owner of: in the way until it has another owner or is deleted. */
25export type SoleOwnedWorkspace = {
26 slug: string;
27 name: string;
28 /** Everyone in it, the account included. */
29 members: number;
30 /** What billing needs before the workspace itself can be deleted; null when nothing. Never asked for staff. */
31 billing: string | null;
32};
33
34/** What deleting an account takes with it, and what stands in the way. */
35export type AccountDeletion = {
36 username: string;
37 /** Live workspaces it is in, which it leaves. */
38 workspaces: number;
39 /** Personal access tokens, classic and fine-grained. */
40 tokens: number;
41 ssh_keys: number;
42 /** Applications signed in as it. */
43 applications: number;
44 /** Repositories it has a role on directly. */
45 repositories: number;
46 sole_owner_of: SoleOwnedWorkspace[];
47 /** It can never be deleted, by anyone. */
48 protected: boolean;
49};
50
51/** What went with a deleted account, counted when it was deleted, and who deleted it when it was staff. */
52export type AccountWent = {
53 workspaces: number;
54 teams: number;
55 repositories: number;
56 tokens: number;
57 sshKeys: number;
58 /** The staff member who deleted it; null when the person did. */
59 staff: string | null;
60 reason: string | null;
61};
62
63/** An account deleted and kept until `purgeAfter` for staff to restore. */
64export type DeletedAccount = {
65 userId: string;
66 username: string;
67 /** RFC 3339. */
68 deletedAt: string;
69 /** RFC 3339: when it is purged unless restored first. */
70 purgeAfter: string;
71 went: AccountWent;
72 /** Whether staff can still restore it. */
73 restorable: boolean;
74};

This file's history is long; its oldest lines are credited to the oldest commit read.