feat: delete guides, pages, and files from the console with their token - #9
Merged
Merged
Conversation
Add DELETE /api/pages/:slug, /api/files/:id, and /api/guides/:slug. The token that created the content, or an admin token, may delete it; other tokens get 403. Deletion stays available during publishing lockdown, matching admin takedowns. The CLI gains `schaffa delete <page|file|guide> <id>` and `schaffa delete <public-url>`. URLs must match SCHAFFA_URL, and version or revision URLs are rejected so a whole page is never removed by mistake.
Screenshot uploads await virus scanning before their transaction. An owner can now delete the guide in that window, which made the insert fail on the foreign key with HTTP 500. Recheck the guide inside the transaction so the upload fails with 404 and its stored image is removed.
Deletion always needs a token, so the flag could only produce an error.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

0 New Issues
0 Fixed Issues
0 Accepted Issues
No data about coverage (0.00% Estimated after merge)
Note
🤖 Claude Opus 5.5 responding on behalf of beastyrabbit
A published guide could only be removed through the
/adminor/accountweb interfaces. Anyone working from a terminal or an agent had no way to delete it, even while holding the token that created it. The same applied to pages and files.The token that created a guide, page, or file can now delete it directly, and admin tokens can delete anything:
DELETE /api/guides/:slug,/api/pages/:slug, and/api/files/:idreturn204. Other tokens get403, unknown IDs404. Files accept either their ID or the public filename.SCHAFFA_URLand rejects version or revision URLs, so a whole page is never removed by mistake.Review surfaced one race that owner deletion made reachable: deleting a guide while a screenshot upload was still being virus-scanned made that upload fail with HTTP 500. It now returns
404and cleans up the stored image; a stalled-scanner test failed before the fix.Verified with the full test suite, new API and CLI tests covering ownership, admin override, missing token, and repeat deletion, and a run of the built CLI against a local server.