Skip to content

Let people delete their account from Settings - #146

Merged
aashu2006 merged 2 commits into
mainfrom
feat/delete-account
Sep 29, 2026
Merged

aashu2006 merged 2 commits into
mainfrom
feat/delete-account

Conversation

@aashu2006

@aashu2006 aashu2006 commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

The delete-account Edge Function already removes the user's files, rows
and auth user, but nothing in the web app called it. Settings now has a
Delete account section at the bottom.

It asks for DELETE to be typed before the button works, so it takes more
than a single tap. The dialog cannot be closed while the request runs.
On success it signs out through the existing signOut, which falls back to
clearing the local session when the server rejects the now-dead token,
then goes home. On failure it stays signed in and shows the function's
own message, like "Could not delete your files. Nothing was deleted, try
again."

Fixes #134

Summary by CodeRabbit

  • New Features
    • Added an account deletion option in Settings. Deletion requires typing “DELETE”; successful deletion signs you out and returns you to the home page.
    • Avatar and cover images now show a preview while they upload and update your profile.
    • Added a Settings link to the authenticated-user menus on desktop and mobile.
  • Bug Fixes
    • If account deletion fails, an error message appears and the confirmation dialog stays open so you can try again.

The delete-account Edge Function already removes the user's files, rows
and auth user, but nothing in the web app called it. Settings now has a
Delete account section at the bottom.

It asks for DELETE to be typed before the button works, so it takes more
than a single tap. The dialog cannot be closed while the request runs.
On success it signs out through the existing signOut, which falls back to
clearing the local session when the server rejects the now-dead token,
then goes home. On failure it stays signed in and shows the function's
own message, like "Could not delete your files. Nothing was deleted, try
again."

Fixes #134
@strix-security

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

So far, Strix has reviewed 14 pull requests across this workspace.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 844db425-53cf-4225-8b9b-1b52cd1a87a0

📥 Commits

Reviewing files that changed from the base of the PR and between 26a767b and e17df15.

📒 Files selected for processing (2)
  • src/components/layout/Navbar.test.tsx
  • src/components/layout/Navbar.tsx
 _____________________________________________________________
< Oompa Loompa doompadee doo, I've got a code review for you. >
 -------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 4c491bc7-d424-47da-a595-8578b93b35f1

📥 Commits

Reviewing files that changed from the base of the PR and between 3583d07 and 26a767b.

📒 Files selected for processing (5)
  • src/components/profile/DeleteAccountSection.test.tsx
  • src/components/profile/DeleteAccountSection.tsx
  • src/pages/Settings.tsx
  • src/services/supabase/account.test.ts
  • src/services/supabase/account.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

Settings now includes an account-deletion confirmation dialog. The dialog calls a Supabase Edge Function through a new account service, handles success and error responses, and signs out after successful deletion. Avatar and cover uploads also show local previews while processing.

Changes

Account deletion

Layer / File(s) Summary
Account deletion service
src/services/supabase/account.ts, src/services/supabase/account.test.ts
Adds a POST request to the delete-account Edge Function. Tests cover successful responses, server error messages, and the fallback error message.
Confirmation dialog and Settings integration
src/components/profile/DeleteAccountSection.tsx, src/components/profile/DeleteAccountSection.test.tsx, src/pages/Settings.tsx
Adds a confirmation dialog that requires trimmed input to equal DELETE. On success, the component signs out, shows a success toast, and navigates home. On error, it shows a destructive toast and keeps the dialog open. Settings renders the dialog below the profile form. Avatar and cover uploads show a local preview while processing and restore the previous preview on failure.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  actor User
  participant DeleteAccountSection
  participant account.deleteAccount
  participant Supabase Edge Function
  participant Auth
  participant Router
  User->>DeleteAccountSection: Enter DELETE and submit
  DeleteAccountSection->>account.deleteAccount: Request account deletion
  account.deleteAccount->>Supabase Edge Function: POST delete-account
  Supabase Edge Function-->>account.deleteAccount: Return response
  account.deleteAccount-->>DeleteAccountSection: Return error or null
  alt Deletion error
    DeleteAccountSection->>DeleteAccountSection: Show destructive toast
  else Deletion succeeds
    DeleteAccountSection->>Auth: Sign out
    DeleteAccountSection->>DeleteAccountSection: Show success toast
    DeleteAccountSection->>Router: Navigate to / with replacement
  end
Loading

Merge Risk: ⚪ Minimal · up to 26a76

The Settings deletion flow has no identified issue that needs to be fixed before merging. Normal checks still apply.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 26a76

Deletion is limited to the signed-in account in the reviewed code, but a failed request can leave files deleted while the account remains active. The new Settings flow does not reliably distinguish that state from an unsuccessful deletion.

Retained concerns

  • Medium · security · inferred: The new user-facing deletion flow treats a function error as “Account not deleted,” although the existing function can return an error after deleting some files. It has no compensating step or completion reconciliation, so a legitimate user can retain an active account with partially removed data and misleading failure feedback.
Security review details

Security Blast Radius

  • inferred — In the reviewed source, a valid caller can cause privileged removal of files under their token-derived user ID and deletion of that auth user. The new UI increases ordinary-user use of this self-account operation; the source does not show a caller-selected victim ID.

Security Findings and Attack Paths

  • inferred — The material adverse path is an authenticated deletion interrupted or failed after some storage removals: the account can remain active, while the new UI reports “Account not deleted.” This exposes a pre-existing backend partial-state condition through the new workflow; it is not evidence of cross-account access.

Trust Boundaries and Controls

  • observed — Bearer-token validation precedes privileged operations, and the server derives their target from the validated user. The client sends no account identifier or service-role credential.

Resilience and Maintainability Implications

  • inferred — Single-component duplicate submission is blocked and a confirmed success signs out and clears local auth state. Neither control resolves concurrent callers, partial server failure, or a response lost after auth deletion; in the last case the client cannot know to take its success-only sign-out path.

Hardening Proposals

  • proposed — Make deletion progress and retry outcomes reconcilable across storage and auth, and avoid assuring users that nothing was deleted after an ambiguous or partial failure. Verify row cascades and deployed authorization before relying on the complete-deletion promise.
🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (3 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains what the change does, why it is needed, and references issue #134. It does not include the required section headings, testing details, or checklist results, so it is largely i… Add the required “What does this change?”, “Why?”, “How was it tested?”, and “Checklist” sections. Document the tests or verification performed, and mark each checklist item accurately.
Out of Scope Changes check ⚠️ Warning The Settings changes also add local avatar and cover upload previews, restore previews after upload failure, and revoke object URLs. These changes do not support the account-deletion objective in [#13… Remove the unrelated avatar and cover preview changes from this pull request, or link them to a separate active issue and submit them separately.
Docstring Coverage ⚠️ Warning Docstring coverage is 20.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 5 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: adding account deletion from Settings.
Linked Issues check ✅ Passed The implementation meets the coding requirements in [#134]. DeleteAccountSection adds a Settings control with typed DELETE confirmation, blocks closing during deletion, calls deleteAccount, sign…
Full details: Description check

Explanation

The description explains what the change does, why it is needed, and references issue #134. It does not include the required section headings, testing details, or checklist results, so it is largely incomplete against the repository template.

Full details: Out of Scope Changes check

Explanation

The Settings changes also add local avatar and cover upload previews, restore previews after upload failure, and revoke object URLs. These changes do not support the account-deletion objective in [#134]. The delete-account component, service, Edge Function, and their tests are in scope.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

Settings, where Delete account now lives, was only reachable through
the Edit Profile button on your own profile. Both the desktop and mobile
account menus now link to it, right under Profile.
@aashu2006
aashu2006 merged commit 0e40fca into main Sep 29, 2026
11 of 12 checks passed
@aashu2006
aashu2006 deleted the feat/delete-account branch September 29, 2026 14:48

This branch was successfully deployed

1 active deployment
Preview — e17df154 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: let people delete their account

1 participant