Skip to content

Add admin endpoints and UI for deleting and expunging user accounts - #2158

Merged
ml-evs merged 9 commits into
mainfrom
ml-evs/tombstone-user-accounts
Oct 11, 2026
Merged

ml-evs merged 9 commits into
mainfrom
ml-evs/tombstone-user-accounts

Conversation

@ml-evs

@ml-evs ml-evs commented Sep 30, 2026

Copy link
Copy Markdown
Member

Closes #478 by:

  • adding a DELETE /users/<user_id> endpoint that lets admins delete an account
  • if the account is not verified and has no items related to it, the user entry is entirely deleted from the db
  • if the account is active/deactivated and has entries, the account is pseudonymised (given random name, connected accounts removed).

This PR also:

  • fixes up AGENTS.md with a reference to the correct pydantic version
  • orders the /users/ endpoint by date created with newest first by default

@ml-evs ml-evs added enhancement New feature or request API For issues/PRs pertaining to the API webapp For issues/PRs pertaining to the web interface labels Sep 30, 2026
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 95.55556% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.62%. Comparing base (5c9fab0) to head (82c4884).

Files with missing lines Patch % Lines
pydatalab/src/pydatalab/routes/v0_1/admin.py 94.11% 3 Missing ⚠️
pydatalab/src/pydatalab/login.py 50.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2158      +/-   ##
==========================================
+ Coverage   82.48%   82.62%   +0.14%     
==========================================
  Files          91       91              
  Lines        8782     8860      +78     
==========================================
+ Hits         7244     7321      +77     
- Misses       1538     1539       +1     
Files with missing lines Coverage Δ
pydatalab/src/pydatalab/models/people.py 92.64% <100.00%> (+1.65%) ⬆️
pydatalab/src/pydatalab/models/traits.py 94.57% <100.00%> (ø)
pydatalab/src/pydatalab/routes/v0_1/collections.py 79.16% <100.00%> (+0.09%) ⬆️
pydatalab/src/pydatalab/routes/v0_1/items.py 86.84% <100.00%> (+0.01%) ⬆️
pydatalab/src/pydatalab/routes/v0_1/users.py 79.80% <100.00%> (+0.80%) ⬆️
pydatalab/src/pydatalab/login.py 88.15% <50.00%> (+3.02%) ⬆️
pydatalab/src/pydatalab/routes/v0_1/admin.py 78.80% <94.11%> (+3.19%) ⬆️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@cypress

cypress Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

datalab    Run #6199

Run Properties:  status check passed Passed #6199  •  git commit 8b382b085b ℹ️: Merge 82c48848c40391202ea2c93d478764994620eb83 into 5c9fab09d68669a58dd7e5ec0de4...
Project datalab
Branch Review ml-evs/tombstone-user-accounts
Run status status check passed Passed #6199
Run duration 04m 50s
Commit git commit 8b382b085b ℹ️: Merge 82c48848c40391202ea2c93d478764994620eb83 into 5c9fab09d68669a58dd7e5ec0de4...
Committer Matthew Evans
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 0
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 275
View all changes introduced in this branch ↗︎

@ml-evs
ml-evs force-pushed the ml-evs/tombstone-user-accounts branch from 9e80f31 to 61edddd Compare September 30, 2026 18:37
@ml-evs ml-evs changed the title Add admin endpoints and UI for deleting and expunging user acconts Add admin endpoints and UI for deleting and expunging user accounts Oct 2, 2026
@davidwaroquiers

Copy link
Copy Markdown
Member

Happy to review this if you want @ml-evs. Just assign me in case.

@ml-evs

ml-evs commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

Happy to review this if you want @ml-evs. Just assign me in case.

Sure, I think this is now safe after the XSS fixes which sanitize display names, but I'll also double check myself.

Comment thread pydatalab/tests/server/test_delete_users.py Dismissed
@ml-evs
ml-evs requested a review from davidwaroquiers October 5, 2026 08:54

@davidwaroquiers davidwaroquiers left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @ml-evs

Very nice work and useful in general thx! I left a couple of comments, some are "cosmetic" (not in the UI/UX sense), some I think are worth checking/addressing.

Comment thread pydatalab/src/pydatalab/models/people.py
Comment thread pydatalab/src/pydatalab/models/people.py
Comment thread pydatalab/src/pydatalab/routes/v0_1/admin.py
Comment thread pydatalab/src/pydatalab/routes/v0_1/admin.py
Comment thread pydatalab/src/pydatalab/routes/v0_1/admin.py
Comment thread pydatalab/tests/server/test_delete_users.py
Comment thread webapp/src/components/UserActionsCell.vue
Comment thread pydatalab/tests/server/test_delete_users.py Outdated
Comment thread pydatalab/src/pydatalab/routes/v0_1/admin.py
Comment thread pydatalab/src/pydatalab/routes/v0_1/admin.py
@ml-evs
ml-evs force-pushed the ml-evs/tombstone-user-accounts branch from 456e940 to 7f2eba5 Compare October 11, 2026 17:01
@ml-evs
ml-evs merged commit 306d350 into main Oct 11, 2026
30 of 31 checks passed
@ml-evs
ml-evs deleted the ml-evs/tombstone-user-accounts branch October 11, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

API For issues/PRs pertaining to the API enhancement New feature or request webapp For issues/PRs pertaining to the web interface

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add ability to tombstone user accounts

3 participants