Skip to content

feat: delete guides, pages, and files from the console with their token - #9

Merged
beastyrabbit merged 3 commits into
mainfrom
t3code/add-console-guide-deletion
Sep 24, 2026
Merged

beastyrabbit merged 3 commits into
mainfrom
t3code/add-console-guide-deletion

Conversation

@beastyrabbit

Copy link
Copy Markdown
Owner

Note

🤖 Claude Opus 5.5 responding on behalf of beastyrabbit

A published guide could only be removed through the /admin or /account web interfaces. Anyone working from a terminal or an agent had no way to delete it, even while holding the token that created it. The same applied to pages and files.

The token that created a guide, page, or file can now delete it directly, and admin tokens can delete anything:

npx schaffa delete guide <id>
npx schaffa delete https://schaffa.dev/p/<slug>
curl -X DELETE -H "Authorization: Bearer $SCHAFFA_TOKEN" "$SCHAFFA_URL/api/guides/<id>"
  • DELETE /api/guides/:slug, /api/pages/:slug, and /api/files/:id return 204. Other tokens get 403, unknown IDs 404. Files accept either their ID or the public filename.
  • Like admin takedowns, deletion still works during publishing lockdown. Anonymous pages cannot be deleted through the API.
  • The CLI only accepts URLs from the configured SCHAFFA_URL and rejects version or revision URLs, so a whole page is never removed by mistake.
  • A guide's attached video is a separate file and stays until it is deleted itself.

Review surfaced one race that owner deletion made reachable: deleting a guide while a screenshot upload was still being virus-scanned made that upload fail with HTTP 500. It now returns 404 and cleans up the stored image; a stalled-scanner test failed before the fix.

Verified with the full test suite, new API and CLI tests covering ownership, admin override, missing token, and repeat deletion, and a run of the built CLI against a local server.

Add DELETE /api/pages/:slug, /api/files/:id, and /api/guides/:slug.
The token that created the content, or an admin token, may delete it;
other tokens get 403. Deletion stays available during publishing
lockdown, matching admin takedowns.

The CLI gains `schaffa delete <page|file|guide> <id>` and
`schaffa delete <public-url>`. URLs must match SCHAFFA_URL, and
version or revision URLs are rejected so a whole page is never removed
by mistake.
Screenshot uploads await virus scanning before their transaction. An owner
can now delete the guide in that window, which made the insert fail on the
foreign key with HTTP 500. Recheck the guide inside the transaction so the
upload fails with 404 and its stored image is removed.
Deletion always needs a token, so the flag could only produce an error.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T13:12:22.705983Z 4cd8e6c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sonarqube-skyway-gmbh

Copy link
Copy Markdown

@beastyrabbit
beastyrabbit merged commit 901bebd into main Sep 24, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant