account delete: self-service deletion with a ghost author and a grace period #322

closed cmc opened this on 2026-10-02 15:05 UTC · milestone hosting

Discussion

cmc 2026-10-02 15:05 UTC

An account can delete itself. Today only admin user delete exists, and it refuses an account that anchors anything (store.DeleteUser's blocker list).

Decided:

  • Authored content stays, reassigned to a ghost. Issues, MRs, comments, diff comments and reviews on repositories the account does not own move to a reserved ghost account rendered as "deleted user". The name goes in internal/policy/names.go; the account cannot sign in, own anything, or be deleted.
  • Owned content goes. The account's repositories, snippets, keys, emails, tokens, sessions, grants and watches are deleted. An org where it is the only admin blocks the deletion until another admin exists or the org is deleted.
  • Stronger confirmation than any other action:
    1. Type the username (the confirmfield partial on the web, --confirm <username> over SSH).
    2. A link mailed to the primary verified address confirms the request. Over SSH this is the only way to do step 2.
    3. The account is disabled for 7 days, then purged. Signing in during the grace period (web login or an SSH command) cancels the deletion and re-enables the account. The mail says so and gives the purge date.
  • The purge runs from the same reaper that drops pending accounts (ReapPendingUsers). It is audited, and it frees the username only after the purge.
  • Suggest account export in the confirmation screen and the mail.
  • Command: account delete (a write, every surface; a read-scoped token or runner key is refused). Web: a section at the bottom of the account settings page.

Parity row, Users wiki page, /privacy text ("deleted on request" becomes how).

closed by cmc in commit 161f585ca2: control: self-service account deletion

2026-10-02 15:41 UTC

referenced in commit ba9c084ef9 by cmc: changelog: v1.43.0

2026-10-02 16:13 UTC