A withdrawn consumer keeps its data, in every provider that holds some (hq issue 241)

mssql disables the login, mongodb takes the user's roles, minio revokes the key and keeps the bucket,
mailu disables the mailbox, gitea prohibits the login instead of purging the user and their
repositories, umami keeps the website. Each provider's create already enables what this locks.
This commit is contained in:
2026-10-05 00:34:40 +02:00
parent 190d711a2a
commit 1fb7ca3d72
10 changed files with 51 additions and 18 deletions
+2 -4
View File
@@ -31,9 +31,7 @@ runProvisioner("analytics", {
},
async remove(p: { as: string }): Promise<void> {
const token = await umami.getToken();
// Keyed on the mesh-derived login, the one identity the harness carries into removal.
const site = await umami.findWebsite(token, p.as);
if (site) await umami.deleteWebsite(token, site.id);
// The website and its analytics are kept (novox/hq issue 241: a withdrawal never destroys a consumer's data — on 2026-10-04 a misread grants file withdrew every consumer at once); a person deletes a site, never this loop.
console.error(`[umami] ${p.as} withdrawn: website and its analytics kept`);
},
});