Let people delete their account from Settings - #146
Conversation
The delete-account Edge Function already removes the user's files, rows and auth user, but nothing in the web app called it. Settings now has a Delete account section at the bottom. It asks for DELETE to be typed before the button works, so it takes more than a single tap. The dialog cannot be closed while the request runs. On success it signs out through the existing signOut, which falls back to clearing the local session when the server rejects the now-dead token, then goes home. On failure it stays signed in and shows the function's own message, like "Could not delete your files. Nothing was deleted, try again." Fixes #134
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. So far, Strix has reviewed 14 pull requests across this workspace. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughSettings now includes an account-deletion confirmation dialog. The dialog calls a Supabase Edge Function through a new account service, handles success and error responses, and signs out after successful deletion. Avatar and cover uploads also show local previews while processing. ChangesAccount deletion
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Feature · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
actor User
participant DeleteAccountSection
participant account.deleteAccount
participant Supabase Edge Function
participant Auth
participant Router
User->>DeleteAccountSection: Enter DELETE and submit
DeleteAccountSection->>account.deleteAccount: Request account deletion
account.deleteAccount->>Supabase Edge Function: POST delete-account
Supabase Edge Function-->>account.deleteAccount: Return response
account.deleteAccount-->>DeleteAccountSection: Return error or null
alt Deletion error
DeleteAccountSection->>DeleteAccountSection: Show destructive toast
else Deletion succeeds
DeleteAccountSection->>Auth: Sign out
DeleteAccountSection->>DeleteAccountSection: Show success toast
DeleteAccountSection->>Router: Navigate to / with replacement
end
Merge Risk: ⚪ Minimal · up to The Settings deletion flow has no identified issue that needs to be fixed before merging. Normal checks still apply. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Deletion is limited to the signed-in account in the reviewed code, but a failed request can leave files deleted while the account remains active. The new Settings flow does not reliably distinguish that state from an unsuccessful deletion. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (3 warnings)
✅ Passed checks (2 passed)
Full details: Description checkExplanation The description explains what the change does, why it is needed, and references issue Full details: Out of Scope Changes checkExplanation The Settings changes also add local avatar and cover upload previews, restore previews after upload failure, and revoke object URLs. These changes do not support the account-deletion objective in [
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Settings, where Delete account now lives, was only reachable through the Edit Profile button on your own profile. Both the desktop and mobile account menus now link to it, right under Profile.
The delete-account Edge Function already removes the user's files, rows
and auth user, but nothing in the web app called it. Settings now has a
Delete account section at the bottom.
It asks for DELETE to be typed before the button works, so it takes more
than a single tap. The dialog cannot be closed while the request runs.
On success it signs out through the existing signOut, which falls back to
clearing the local session when the server rejects the now-dead token,
then goes home. On failure it stays signed in and shows the function's
own message, like "Could not delete your files. Nothing was deleted, try
again."
Fixes #134
Summary by CodeRabbit