Skip to content

fix(auth): harden self-service account deletion - #339

Merged
simonvanlierde merged 3 commits into
mainfrom
fix/account-deletion-review
Sep 28, 2026
Merged

simonvanlierde merged 3 commits into
mainfrom
fix/account-deletion-review

Conversation

@simonvanlierde

Copy link
Copy Markdown
Contributor

Follow-up to #336 from its review.

  • Email the former address after a self-service deletion, and require a recent sign-in when an account has neither a password nor MFA.
  • Limit the route per IP with the login IP budget and charge failed step-ups to a per-account budget; check erasability before spending the MFA code; revoke sessions after the committed erase.
  • Audit a wrong current password against the user, and document the 400/403/409 responses.
  • Delete dialog: loading state and field-level errors. Privacy and terms wording now matches what deletion erases.
  • Trim the deletion code: one dialog prop instead of eight, a simpler request body, a server-side body default.

- notify the former address by email after a self-service deletion
- require a recent sign-in when an account has neither a password nor MFA
- limit the route per IP with the login IP budget, and charge failed step-ups to a per-account budget
- check whether the account may be erased before spending the MFA code, and revoke sessions after the committed erase
- audit a wrong current password against the user before returning 403
- document the 400/403/409 responses
- show a loading state and field-level errors in the delete dialog
- narrow the privacy and terms wording to what deletion erases
- pass the delete dialog state as one prop instead of eight
- always send a JSON body from deleteAccount; JSON.stringify drops unset fields
- default a missing deletion body server-side instead of checking it at every read
@codecov

codecov Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

- show one deletion error below the inputs, described by both fields
- keep the delete flow in deleteOwnAccount and drop the extra exit-session hook
- replace the step-up refresh integration test with one case in the refresh tests
- merge overlapping dialog, API and superuser tests
@simonvanlierde
simonvanlierde merged commit b59a285 into main Sep 28, 2026
24 checks passed
@simonvanlierde
simonvanlierde deleted the fix/account-deletion-review branch September 28, 2026 09:31
@simonvanlierde simonvanlierde mentioned this pull request Sep 28, 2026
25 of 35 tasks
simonvanlierde added a commit that referenced this pull request Sep 28, 2026
* origin/main:
  fix(auth): harden self-service account deletion (#339)
  feat(auth): let users delete their own account (#336)
  chore(deps): lock file maintenance (#338)
  chore(deps): lock file maintenance (#337)
  feat(backend): rate-limit signed-in requests per user (#334)
  perf(backend): add a deploy-shaped capacity probe (#333)
  test: pin auth and upload guards that passing tests left unchecked (#330)
  fix(deps): update all non-major (#331)
  chore(deps): lock file maintenance (#332)

# Conflicts:
#	app/src/types/openapi.json
#	backend/app/api/plugins/rpi_cam/routers/camera_interaction/images.py
#	backend/app/api/reference_data/routers/categorized_admin.py
#	backend/scripts/seed/factories/models.py
#	backend/tests/unit/core/test_image_processing.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant