Add self-service account deletion
Settings → Delete account removes the signed-in account and everything it owns. DELETE /api/me re-checks the password (guarding an unattended session), then wipes the user's events, config, sessions and user row in one transaction and removes their photos/<user_id>/ directory. The client clears the account's local cache and returns to the login screen. Bumps the service-worker cache so clients pick up the new UI. Verified: wrong password is rejected (401, data intact); correct password returns 204, invalidates the session, drops all rows to zero and removes the photo dir; the email can be re-registered afterwards. Confirmed end to end in a headless-browser run of the Settings → delete flow.
This commit is contained in:
@@ -599,3 +599,18 @@ button.linklike {
|
||||
cursor: pointer;
|
||||
}
|
||||
button.linklike:hover { text-decoration: underline; filter: none; }
|
||||
|
||||
/* ---------- delete account ---------- */
|
||||
.settings-sep {
|
||||
border: none;
|
||||
border-top: 1px solid var(--border);
|
||||
margin: 18px 0 12px;
|
||||
}
|
||||
.danger-block { width: 100%; }
|
||||
.danger-text {
|
||||
font-size: 0.9rem;
|
||||
color: var(--muted);
|
||||
margin: 0 0 14px;
|
||||
line-height: 1.4;
|
||||
}
|
||||
.danger-text strong { color: var(--danger); }
|
||||
|
||||
Reference in New Issue
Block a user