feat: archive users instead of deleting, and save the user page with one button - #1593
Merged
Merged
Conversation
The backend now sets `disabled: true` instead of permanently deleting the user record. The frontend renames all "Delete User" UI to "Archive User" and adds an archive action to the users table dropdown. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Archived users now see a specific error on login asking them to contact an administrator. The users table shows a status column (active in green, archived with date in red). Both the table dropdown and the user detail page offer archive/unarchive depending on the user's current state. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Archiving reused the `disabled` flag, which already means "never meant to log in" and exempts an account from needing a group. Archiving now sets its own `archivedAt` date, is recorded in the audit log, and is shown in the users table's Status column alongside an Enabled / Disabled column. Login names an archived or disabled account only after the password is verified, so a wrong guess cannot reveal whether a username exists or what state it is in. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The permissions table saved each change the moment it was made, while the rest of the user page waited for Save. One Save Changes button below the permissions now saves both. The plus icon only adds a row; a filled-in row is saved by Save, and a half-filled one blocks the save and is highlighted rather than being silently dropped. The account Status field now offers Enabled / Disabled, with Enabled first. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-archive-user Conflicts were main's new Spanish translations against this branch's rewrite of the user page; kept the rewrite and added `es` to every string. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-archive-user Conflicts were main's libnest v9 upgrade and `$`-prefixed request-body types against this branch's archive routes and combined account and permissions save; kept both, and the per-row permissions hook stays deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joshunrau
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Archive replaces delete
Delete Useris gone. Admins Archive a user (with confirmation) or Unarchive them, from the user page or the users table's row actions. An admin cannot archive themselves.archivedAtdate instead of reusingdisabled, which keeps its own meaning (an account never meant to log in, exempt from needing a group). Both actions are written to the audit log.One Save button on the user page
Also merges
mainand adds Spanish to every string on the rewritten user page.Test plan
pnpm lintpassespnpm test: 1566 unit tests pass, including new ones for archive/unarchive, login status ordering, the single-save mutation, incomplete permission rows and the users table columnspnpm test:e2e: theadmin-managementandauthorizationspecs pass (75 tests) after the single-save changepnpm test:e2efull suite on the final branch. Not run locally since the incomplete-row, login-ordering and Status-field changes and the merge withmain; relying on CI🤖 Generated with Claude Code