Skip to content

Make account deletion cover user storage inventory - #614

Merged
kody-bot merged 4 commits into
mainfrom
cursor/account-deletion-completeness-audit-a3c2
Jul 5, 2026
Merged

kody-bot merged 4 commits into
mainfrom
cursor/account-deletion-completeness-audit-a3c2

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Jul 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Rebuilt account deletion around a pre-delete inventory so D1 rows, Vectorize ids, KV keys, Artifacts repos, and user-enumerable Durable Objects are cleaned up before the user row is removed.
  • Removed the stale chat_threads deletion target and added coverage for package runtime debug tables, community ownership/reference tables, source snapshots, retriever cache keys, archived/runtime/app/service storage ids, and DO purge entrypoints.
  • Added a schema guardrail test that applies the live migrations and fails if any user_id / *_user_id column is missing from account deletion coverage or if deletion references stale schema.
  • Updated docs/contributing/architecture/data-storage.md with the account deletion inventory and current Durable Object storage model.

Validation

  • npm run validate (green: format, lint, typecheck, unit, Playwright E2E, MCP E2E)
System recap — extends existing primitives (medium risk)

Mode: recap · Base: main @ cf8c22e · Head: 01693a6

Classification: extends — this PR changes deletion behavior and purge contracts for existing storage/runtime primitives; it does not add a new primitive.

Primitives touched

Primitive Group Impact
d1-app-db storage extends — schema-derived deletion guardrail and broader D1 cascade/update coverage
bundle-artifacts-kv storage extends — account deletion removes bundle, source snapshot, community snapshot, and retriever cache keys
artifacts-repos storage composes — account deletion continues using existing Artifacts REST cleanup
vectorize-search storage composes — account deletion deletes memory/job/package vector ids by D1 inventory
durable-storage assistant extends — deletion clears job/archive/runtime/app/service storage buckets
jobs assistant extends — JobManager gets a purge RPC for account deletion and reports missing bindings
repo-sessions runtime extends — RepoSession gets a hard purge RPC for account deletion
remote-connectors assistant extends — RemoteConnectorSession gets a purge RPC for account deletion
realtime-sessions assistant extends — PackageRealtimeSession gets a purge endpoint for account deletion
package-services assistant extends — PackageServiceInstance gets a purge endpoint for account deletion, including legacy service rows without source ids
community-listings assistant extends — account deletion removes owned/listing-related community rows/snapshots, clears resolver-only report references, and preserves bans made by deleted moderators with an anonymized moderator reference
mcp-oauth auth composes — account deletion continues revoking all OAuth grants
app-ui surfaces extends — /account/delete response reports expanded cleanup counts/warnings, including updated row counts

System map

flowchart LR
	appUi["app-ui"]:::extended --> d1["d1-app-db"]:::extended
	appUi --> oauth["mcp-oauth"]:::touched
	d1 --> vector["vectorize-search"]:::touched
	d1 --> kv["bundle-artifacts-kv"]:::extended
	d1 --> artifacts["artifacts-repos"]:::touched
	d1 --> durable["durable-storage"]:::extended
	d1 --> jobs["jobs"]:::extended
	d1 --> repos["repo-sessions"]:::extended
	d1 --> connectors["remote-connectors"]:::extended
	d1 --> realtime["realtime-sessions"]:::extended
	d1 --> services["package-services"]:::extended
	d1 --> community["community-listings"]:::extended
	classDef touched fill:#1a7f37,color:#fff
	classDef extended fill:#9a6700,color:#fff
	classDef added fill:#cf222e,color:#fff
	classDef untouched fill:#57606a,color:#fff
Loading

Change flow

sequenceDiagram
	participant Route as POST /account/delete
	participant Delete as deleteUserAccount
	participant D1 as APP_DB inventory
	participant Stores as Vectorize/KV/Artifacts/DOs
	participant OAuth as OAuth provider
	Route->>Delete: verified dbUserId + mcpUserId
	Delete->>D1: collect vectors, sources, packages, sessions, connectors, services, listings, storage ids
	Delete->>Stores: best-effort delete/purge with warnings per failure
	Delete->>D1: delete user-scoped rows or clear/anonymize user references in dependency-safe order
	Delete->>OAuth: revoke all grants
	Delete->>D1: delete users row last
	Delete-->>Route: exact deleted/updated counts + warnings
Loading

Invariants

  • Preserves the hard per-user isolation invariant: all inventory queries filter by mcpUserId/dbUserId, DO names are user-scoped where applicable, and cross-user rows/keys remain untouched in tests.
  • Adds a migration-backed guardrail so future user-owned D1 columns fail tests until account deletion explicitly covers them.
Open in Web Open in Cursor 

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@coderabbitai

coderabbitai Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@cursor[bot], you've reached your PR review limit, so we couldn't start this review.

Next review available in: 30 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 86f4ab53-7ff1-4037-af2a-5566688d225f

📥 Commits

Reviewing files that changed from the base of the PR and between cf8c22e and 01693a6.

📒 Files selected for processing (11)
  • docs/contributing/architecture/data-storage.md
  • packages/worker/src/app/account-deletion.node.test.ts
  • packages/worker/src/app/account-deletion.ts
  • packages/worker/src/jobs/manager-client.ts
  • packages/worker/src/jobs/manager-do.ts
  • packages/worker/src/package-retrievers/manifest-cache.ts
  • packages/worker/src/package-runtime/package-service.ts
  • packages/worker/src/package-runtime/realtime-session.ts
  • packages/worker/src/remote-connector/session.ts
  • packages/worker/src/repo/repo-session-do.ts
  • packages/worker/src/repo/repo-session-rpc.ts
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/account-deletion-completeness-audit-a3c2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 5, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Preview deployed: https://kody-pr-614.kentcdodds.workers.dev

Worker: kody-pr-614
D1: kody-pr-614-db
KV: kody-pr-614-oauth-kv

Mocks:

Comment thread packages/worker/src/app/account-deletion.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
Comment thread packages/worker/src/app/account-deletion.ts Outdated
Comment thread packages/worker/src/app/account-deletion.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1d3c4b9. Configure here.

Comment thread packages/worker/src/app/account-deletion.ts
Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kody-bot
kody-bot merged commit 4d6c168 into main Jul 5, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/account-deletion-completeness-audit-a3c2 branch July 5, 2026 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants