Skip to content

feat: archive users instead of deleting, and save the user page with one button - #1593

Merged
joshunrau merged 6 commits into
mainfrom
feat/rename-delete-to-archive-user
Oct 2, 2026
Merged

joshunrau merged 6 commits into
mainfrom
feat/rename-delete-to-archive-user

Conversation

@thomasbeaudry

Copy link
Copy Markdown
Collaborator

Summary

Depends on DouglasNeuroInformatics/libui#121. The account Status field's ? help only opens its description on hover once that PR is merged, released, and the @douglasneuroinformatics/libui catalog version here is bumped (mind the 7-day minimumReleaseAge). Until then it still works, but on click only. Nothing else in this PR depends on it.

Archive replaces delete

  • Delete User is gone. Admins Archive a user (with confirmation) or Unarchive them, from the user page or the users table's row actions. An admin cannot archive themselves.
  • Archiving sets a new archivedAt date instead of reusing disabled, which keeps its own meaning (an account never meant to log in, exempt from needing a group). Both actions are written to the audit log.
  • The users table gains sortable headers, an Enabled / Disabled column, and a Status column showing Active or Archived on .
  • Login tells an archived or disabled user why they cannot sign in, but only once their password is verified, so a wrong guess cannot reveal whether a username exists or what state it is in.

One Save button on the user page

  • The permissions table no longer saves on every change. A single Save Changes button below it saves the account details and permissions together; the account form's own button is removed.
  • The plus icon only adds a permission row. A filled-in row is saved by Save without pressing plus; a half-filled row blocks the save and is highlighted, rather than being silently dropped.
  • The account Status field now reads Status ? with Enabled / Disabled on one line, Enabled first and preselected, and clearer help text.

Also merges main and adds Spanish to every string on the rewritten user page.

Test plan

  • pnpm lint passes
  • pnpm test: 1566 unit tests pass, including new ones for archive/unarchive, login status ordering, the single-save mutation, incomplete permission rows and the users table columns
  • pnpm test:e2e: the admin-management and authorization specs pass (75 tests) after the single-save change
  • pnpm test:e2e full suite on the final branch. Not run locally since the incomplete-row, login-ordering and Status-field changes and the merge with main; relying on CI
  • Manually check the user page: archive/unarchive, save with a half-filled permission row, Status field layout

🤖 Generated with Claude Code

thomasbeaudry and others added 5 commits October 1, 2026 00:30
The backend now sets `disabled: true` instead of permanently deleting
the user record. The frontend renames all "Delete User" UI to
"Archive User" and adds an archive action to the users table dropdown.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Archived users now see a specific error on login asking them to
contact an administrator. The users table shows a status column
(active in green, archived with date in red). Both the table
dropdown and the user detail page offer archive/unarchive depending
on the user's current state.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Archiving reused the `disabled` flag, which already means "never meant to
log in" and exempts an account from needing a group. Archiving now sets its
own `archivedAt` date, is recorded in the audit log, and is shown in the
users table's Status column alongside an Enabled / Disabled column.

Login names an archived or disabled account only after the password is
verified, so a wrong guess cannot reveal whether a username exists or what
state it is in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The permissions table saved each change the moment it was made, while the
rest of the user page waited for Save. One Save Changes button below the
permissions now saves both. The plus icon only adds a row; a filled-in row
is saved by Save, and a half-filled one blocks the save and is highlighted
rather than being silently dropped. The account Status field now offers
Enabled / Disabled, with Enabled first.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-archive-user

Conflicts were main's new Spanish translations against this branch's
rewrite of the user page; kept the rewrite and added `es` to every string.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-archive-user

Conflicts were main's libnest v9 upgrade and `$`-prefixed request-body
types against this branch's archive routes and combined account and
permissions save; kept both, and the per-row permissions hook stays
deleted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@joshunrau
joshunrau merged commit e98cc8a into main Oct 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants