A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)

mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket,
mailu disables the mailbox, gitea prohibits the login instead of purging the user and their
repositories, umami keeps the website. Each provider's create already enables what this locks.
This commit is contained in:
2026-10-05 00:34:40 +02:00
parent 190d711a2a
commit 1fb7ca3d72
10 changed files with 51 additions and 18 deletions
+12
View File
@@ -125,6 +125,18 @@ export class MongoClient {
/** Drop a database and its owning user, idempotently. Dropping the database evicts its data; the
* user is removed first so a re-grant of the same login starts clean. */
/** Withdraw a consumer and keep its database: the user keeps its name and loses every role. */
async lockUser(database: string, user: string): Promise<void> {
await this.admin(async (client) => {
const target = client.db(database);
try {
await target.command({ updateUser: user, roles: [] });
} catch (err) {
if (!(err instanceof MongoServerError && err.code === 11)) throw err; // 11: UserNotFound
}
});
}
async dropDatabaseAndUser(database: string, user: string): Promise<void> {
await this.admin(async (client) => {
const target = client.db(database);