Skip to content

Scope history deletion to the requested target - #2462

Open
bitbonsai wants to merge 1 commit into
ergochat:masterfrom
bitbonsai:histserv-delete-target
Open

bitbonsai wants to merge 1 commit into
ergochat:masterfrom
bitbonsai:histserv-delete-target

Conversation

@bitbonsai

@bitbonsai bitbonsai commented Oct 3, 2026 •

Copy link
Copy Markdown

Problem

A single IRC message sent to multiple targets has the same msgid in each target's history. DeleteMessage receives a target and checks permission against it, but persistent-history lookup used only the msgid with LIMIT 1. It could select and delete a copy from another target, leaving the requested copy in place. In some paths, the wrong row could also trigger a permission failure for a valid request.

Deleting every row with that msgid would be worse: it would erase history from targets the delete did not name, without a corresponding REDACT there.

Change

Scope history lookup and deletion by both msgid and the casefolded sequence.target in SQLite, MySQL, and PostgreSQL. Only the requested target's row is affected; copies in other targets remain intact. This keeps the database mutation aligned with the target used for authorization and avoids cross-target data loss.

Regression test TestDeleteMsgidIsTargetScoped stores one msgid under two targets, verifies lookup selects the requested target, deletes that copy, and confirms the unrelated copy remains.

Checked in golang:1.27: go test -tags "i18n mysql postgresql sqlite" ./... and go vet pass; gofmt is clean. MySQL and PostgreSQL were compile-tested, not run against live databases.

I am new to this codebase, so please flag it if I have misunderstood the target-scoping semantics.

Channel deletes and their authorization lookups now use the casefolded
sequence target as well as the msgid. This prevents a copy under another
target from being selected or deleted. Direct-message lookup behavior stays
unchanged.

Add a SQLite regression test with the same msgid under two channel targets;
deleting one target must leave the other copy intact.
@bitbonsai
bitbonsai force-pushed the histserv-delete-target branch from 664a3ad to 5a278e9 Compare October 3, 2026 14:17
@bitbonsai bitbonsai changed the title Delete every history copy for a msgid Scope history deletion to the requested target Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant