Legal holds, step 2: who a hold covers

A hold reaches an account by name, through any of its addresses'
domains, its groups or its tenant, as they are now, so an account added
to a held domain later is held too. An account that leaves a held
domain, group or tenant stays held: the registry write hook adds it to
the hold by name on every account change, whoever makes it (LH-2).
Server::holds_on answers for the deletion paths, from the store each
time so a hold binds every node at once.
This commit is contained in:
2026-09-27 19:33:06 -07:00
parent 5d2e35b2dc
commit 318783f444
5 changed files with 202 additions and 0 deletions
+1
View File
@@ -68,6 +68,7 @@ use utils::{
pub mod auth;
pub mod cache;
pub mod audit; // inbuxa: the audit log (audit-hold-lock spec, AU)
pub mod hold; // inbuxa: legal holds (audit-hold-lock spec, LH)
pub mod config;
pub mod expr;
pub mod i18n;