Repository navigation
fix(auth): harden self-service account deletion - #339
Merged
Merged
Conversation
- notify the former address by email after a self-service deletion - require a recent sign-in when an account has neither a password nor MFA - limit the route per IP with the login IP budget, and charge failed step-ups to a per-account budget - check whether the account may be erased before spending the MFA code, and revoke sessions after the committed erase - audit a wrong current password against the user before returning 403 - document the 400/403/409 responses - show a loading state and field-level errors in the delete dialog - narrow the privacy and terms wording to what deletion erases
- pass the delete dialog state as one prop instead of eight - always send a JSON body from deleteAccount; JSON.stringify drops unset fields - default a missing deletion body server-side instead of checking it at every read
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
- show one deletion error below the inputs, described by both fields - keep the delete flow in deleteOwnAccount and drop the extra exit-session hook - replace the step-up refresh integration test with one case in the refresh tests - merge overlapping dialog, API and superuser tests
25 of 35 tasks
simonvanlierde
added a commit
that referenced
this pull request
Sep 28, 2026
* origin/main: fix(auth): harden self-service account deletion (#339) feat(auth): let users delete their own account (#336) chore(deps): lock file maintenance (#338) chore(deps): lock file maintenance (#337) feat(backend): rate-limit signed-in requests per user (#334) perf(backend): add a deploy-shaped capacity probe (#333) test: pin auth and upload guards that passing tests left unchecked (#330) fix(deps): update all non-major (#331) chore(deps): lock file maintenance (#332) # Conflicts: # app/src/types/openapi.json # backend/app/api/plugins/rpi_cam/routers/camera_interaction/images.py # backend/app/api/reference_data/routers/categorized_admin.py # backend/scripts/seed/factories/models.py # backend/tests/unit/core/test_image_processing.py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #336 from its review.