A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)

mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket,
mailu disables the mailbox, gitea prohibits the login instead of purging the user and their
repositories, umami keeps the website. Each provider's create already enables what this locks.
This commit is contained in:
2026-10-05 00:34:40 +02:00
parent 190d711a2a
commit 1fb7ca3d72
10 changed files with 51 additions and 18 deletions
+10
View File
@@ -564,6 +564,16 @@ export class GiteaAdmin {
GiteaAdmin.fail(`/teams/${found.id}/members/${username}`, member);
}
/** Withdraw a user and keep everything they own: login prohibited, which ensureUser undoes. */
async prohibitLogin(username: string): Promise<void> {
const res = await this.request(`/admin/users/${encodeURIComponent(username)}`, {
method: "PATCH",
body: JSON.stringify({ login_name: username, prohibit_login: true }),
});
if (res.status === 200 || res.status === 404) return;
GiteaAdmin.fail(`/admin/users/${username}`, res);
}
/** Delete a user, purging what they own. A 404 means the mesh already withdrew them — success, not
* an error, so a re-run of remove is safe. */
async deleteUser(username: string): Promise<void> {
+2 -1
View File
@@ -54,7 +54,8 @@ runProvisioner("npm-package-registry", {
},
async remove(p: { as: string }): Promise<void> {
await gitea.deleteUser(p.as);
// Login prohibited, never deleted (novox/hq issue 241: a withdrawal never destroys a consumer's data — on 2026-10-04 a misread grants file withdrew every consumer at once): deleting purges every repository the user owns.
await gitea.prohibitLogin(p.as);
},
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).