At the bottom of the "settings" tab, add a "Danger Zone" #39

Closed
opened 2026-09-04 16:50:32 +00:00 by crueber · 3 comments
Owner

image

At the bottom of the settings page that I have copied above, I want you to add a section called the "Danger Zone"

The first entry for this zone is going to be "Delete Repository"

Everything in the danger zone needs confirmation by typing the repository name and then clicking a confirm button.

![image](/attachments/d6c7edbc-f592-4ad3-9b04-b0b8ea53856d) At the bottom of the settings page that I have copied above, I want you to add a section called the "Danger Zone" The first entry for this zone is going to be "Delete Repository" Everything in the danger zone needs confirmation by typing the repository name and then clicking a confirm button.
114 KiB
Author
Owner

Fixed by #56 (branch fix/issue-39): Danger Zone at the bottom of Settings with Delete Repository behind an exact owner/name typed confirm; reuses the existing admin-only DELETE …/api. Browser-verified dark+light, zero console errors.

Fixed by #56 (branch fix/issue-39): Danger Zone at the bottom of Settings with Delete Repository behind an exact owner/name typed confirm; reuses the existing admin-only DELETE …/api. Browser-verified dark+light, zero console errors.
Author
Owner

Review of PR #56 (fix/issue-39, commit a9fde1d). Scope as expected: UI+docs only, 5 files, no package.json / no new deps (law 1 clean).

DangerConfirm semantics — all correct:

  • web/src/lib/danger.js:10-13 strict === match, case-sensitive, untrimmed; expected==='' never arms (safe while ctx.full loads).
  • web/src/pages/Settings.jsx DangerConfirm: button disabled={!armed()} (Settings.jsx: armed def), busy flag set before await with early-return in confirm() = double-submit guard; input disabled while busy; catch renders plain-text .err-line, and deleteRepo deliberately skips reportError so no tray+inline double-report.
  • deleteRepo awaits repo.delete() then navigate('/') — no stranded UI on the dead repo; busy-stuck-on-success is moot (unmounts).
  • DangerZone renders below tab content in the shell (Settings.jsx:765), visible on every tab; dark: variants on all red/zinc classes, shared .card/.input/.muted/.err-line from ui.css.

Admin-gating (checked, not a defect): Settings page itself is NOT admin-gated and DangerZone renders for non-admins — consistent with perms.jsx P6 (server authoritative, client gating cosmetic) and the 08 doc line 'server is the admin gate'. A non-admin attempt 403s and the text lands in the entry's inline error line. Intentional; noting so it's on record.

Backend claims — spot-checked, all true:

  • DELETE exists on both lanes: internal/api/routes.go:91 (Sub '', AuthAdmin) + Dispatch strips api|api-browser before the same table (routes.go lane block). Gate enforced twice (dispatch + repoDelete).
  • Admin-only with plain-text body: summary.go:88-101; anon DELETE -> 403 (anonRead on) / 401 (off) covered by gaps3_test.go TestGateAnonymousWriteArms.
  • Manifest-first + prefix sweep + local removal: wal/registry.go:271 Delete (manifest delete first as linearization point, then paged prefix LIST+delete, then os.RemoveAll; NotFound-tolerant = idempotent). Re-DELETE -> 204 covered by gaps_test.go:52-58.
  • repo.delete() SDK mirror pre-exists (web/sdk/src/admin.js:22); PR adds no SDK/backend code — 'predates it' claim true.
  • Fork/GC sentence is prescriptive (MUST on readers), not yet executable: no non-test code reads meta/forks.json today, and 03 §7 + 03:401-403 say GC-liveness enforcement 'lands with the executor'. So miss-tolerance (conditional-GET miss = skip) is a forward constraint, consistent with the 03 spec — verified as specified, not as implemented. Stale-forks.json + separate-prefix children claims match merge.go/ForksKey/StorePrefix design.

Tests: danger.test.js 3/3 pass; full web/test/unit 227 pass / 2 fail, and both failures (data-guard, reaction-cache) reproduce identically on origin/main scratch worktree — pre-existing, unrelated. vite build clean (105 modules, 1.46s). No browser drive (node tests + reasoning only, per instructions); no Go tests needed (no backend files touched). Main worktree untouched (read-only; all work in /tmp scratch worktrees, removed after).

MERGE RECOMMENDATION: ready to merge.

Review of PR #56 (fix/issue-39, commit a9fde1d). Scope as expected: UI+docs only, 5 files, no package.json / no new deps (law 1 clean). DangerConfirm semantics — all correct: - web/src/lib/danger.js:10-13 strict === match, case-sensitive, untrimmed; expected==='' never arms (safe while ctx.full loads). - web/src/pages/Settings.jsx DangerConfirm: button disabled={!armed()} (Settings.jsx: armed def), busy flag set before await with early-return in confirm() = double-submit guard; input disabled while busy; catch renders plain-text .err-line, and deleteRepo deliberately skips reportError so no tray+inline double-report. - deleteRepo awaits repo.delete() then navigate('/') — no stranded UI on the dead repo; busy-stuck-on-success is moot (unmounts). - DangerZone renders below tab content in the shell (Settings.jsx:765), visible on every tab; dark: variants on all red/zinc classes, shared .card/.input/.muted/.err-line from ui.css. Admin-gating (checked, not a defect): Settings page itself is NOT admin-gated and DangerZone renders for non-admins — consistent with perms.jsx P6 (server authoritative, client gating cosmetic) and the 08 doc line 'server is the admin gate'. A non-admin attempt 403s and the text lands in the entry's inline error line. Intentional; noting so it's on record. Backend claims — spot-checked, all true: - DELETE exists on both lanes: internal/api/routes.go:91 (Sub '', AuthAdmin) + Dispatch strips api|api-browser before the same table (routes.go lane block). Gate enforced twice (dispatch + repoDelete). - Admin-only with plain-text body: summary.go:88-101; anon DELETE -> 403 (anonRead on) / 401 (off) covered by gaps3_test.go TestGateAnonymousWriteArms. - Manifest-first + prefix sweep + local removal: wal/registry.go:271 Delete (manifest delete first as linearization point, then paged prefix LIST+delete, then os.RemoveAll; NotFound-tolerant = idempotent). Re-DELETE -> 204 covered by gaps_test.go:52-58. - repo.delete() SDK mirror pre-exists (web/sdk/src/admin.js:22); PR adds no SDK/backend code — 'predates it' claim true. - Fork/GC sentence is prescriptive (MUST on readers), not yet executable: no non-test code reads meta/forks.json today, and 03 §7 + 03:401-403 say GC-liveness enforcement 'lands with the executor'. So miss-tolerance (conditional-GET miss = skip) is a forward constraint, consistent with the 03 spec — verified as specified, not as implemented. Stale-forks.json + separate-prefix children claims match merge.go/ForksKey/StorePrefix design. Tests: danger.test.js 3/3 pass; full web/test/unit 227 pass / 2 fail, and both failures (data-guard, reaction-cache) reproduce identically on origin/main scratch worktree — pre-existing, unrelated. vite build clean (105 modules, 1.46s). No browser drive (node tests + reasoning only, per instructions); no Go tests needed (no backend files touched). Main worktree untouched (read-only; all work in /tmp scratch worktrees, removed after). MERGE RECOMMENDATION: ready to merge.
Author
Owner

Fixed by PR #56 (review clean; danger matcher tests green), merged. Closing.

Fixed by PR #56 (review clean; danger matcher tests green), merged. Closing.
crueber added this to the v1 milestone 2026-09-10 22:27:22 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
crueber/walhub#39
No description provided.