diff options
| author | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 17:05:05 +0200 |
|---|---|---|
| committer | erdgeist <erdgeist@erdgeist.org> | 2026-07-31 17:05:05 +0200 |
| commit | 8c6a6516e1dc5c1b4f12740a6f7b32765b530bb7 (patch) | |
| tree | e40a1da656bedef0662f0e984b4e3b00b374bc1d /app/models/node_action.rb | |
| parent | 464dd4266bdc433805010b5dca428f4cb75c2a81 (diff) | |
Replace user deletion with deactivation
Deactivation adds the alumni role and leaves the others in place, so
reactivation is lossless and nobody has to remember what an account held.
login_from_session checks alumni? on every request, so a signed-in user is
locked out on their next one without any session invalidation. Guards
prevent deactivating yourself or the last active admin, and both verbs are
witnessed in the action log.
Diffstat (limited to 'app/models/node_action.rb')
| -rw-r--r-- | app/models/node_action.rb | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/app/models/node_action.rb b/app/models/node_action.rb index fec5a062..d619aac5 100644 --- a/app/models/node_action.rb +++ b/app/models/node_action.rb | |||
| @@ -98,8 +98,9 @@ class NodeAction < ApplicationRecord | |||
| 98 | # "detached_from" -- array of unique_names, only when any | 98 | # "detached_from" -- array of unique_names, only when any |
| 99 | # "headline_removed_from" -- array of unique_names, only when any | 99 | # "headline_removed_from" -- array of unique_names, only when any |
| 100 | # | 100 | # |
| 101 | # "otp_enroll" / "otp_disable" / "otp_reset" (second-factor lifecycle; | 101 | # "otp_enroll" / "otp_disable" / "otp_reset" / "user_deactivate" / |
| 102 | # node column nil; participants: the affected User -- the table's first | 102 | # "user_reactivate" (second-factor lifecycle; node column nil; |
| 103 | # participants: the affected User | ||
| 103 | # User-typed subject. otp_disable is self-service; otp_reset is an | 104 | # User-typed subject. otp_disable is self-service; otp_reset is an |
| 104 | # administrator clearing someone else's factor, where actor and | 105 | # administrator clearing someone else's factor, where actor and |
| 105 | # participant differ): | 106 | # participant differ): |
