feat(gdpr): purge expired email-change requests and invite codes #275
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!275
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/256-gdpr-purge"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Purge expired personal-data rows. Version 1.15.0.
scripts/purge-expired.mjs: deletesemail_change_requestsandinvite_codesrows more than 7 days pastexpires_ator pastconsumed_at/used_at. Invite codes with neither timestamp are kept. Batched 500 rows per delete, looped until a short batch. Idempotent. Logs counts only.scripts/server.mjsruns it on boot and hourly whenDATABASE_URLis set. No infra timer needed.signupsis not purged: it is the per-account consent record with no expiry, covered by account-data retention.Privacy policy (please read before merge)
New line in the Retention section, both languages:
Verification
scripts/purge-expired.db.test.mjs) skip withoutTEST_DATABASE_URL; this repo's CI has no Postgres yet.pnpm test407 passed, 3 skipped. Lint,astro check,lang-check, build and e2e pass.Closes #256
fb9947facaff5c18c4de