No DELETE FROM audit_log|events|webhook_deliveries|notifications anywhere in internal/store. Expired web_sessions, login_tokens and email_tokens are filtered on read but never swept. The audit log stores full argv, so --body text lands there verbatim (control.go:116).
Remedy: an hourly sweep of expired tokens and sessions; configurable retention for deliveries, events and audit rows; record only path and positional arguments in the audit entry.
closed by commit d51efc8bb8 by cmc: store: expired rows are swept, and the audit log stops copying prose
2026-09-04 15:58 UTC