Legal holds, step 5: held accounts can't be destroyed
Destroying a held account removes the login, as offboarding needs, but keeps its data as a deleted account with no expiry, whether or not undelete keeps accounts; its addresses stay reserved and its holds name it from then on. Destroy-now refuses it, and its DestroyAccount task defers itself while it's held or its time hasn't come. Holds placed or released later freeze or free kept accounts in the same settle pass, with 30 days' grace after the last release (LH-8, LH-10).
This commit is contained in:
@@ -484,6 +484,19 @@ pub async fn keep_moved(data: &Store, before: &Member, after: &Member) -> trc::R
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// LH-8: names `account_id` in every hold that reaches it, so a deleted
|
||||
/// account, no longer in any domain or tenant, stays held.
|
||||
pub async fn pin_account(data: &Store, member: &Member) -> trc::Result<()> {
|
||||
for mut hold in covering(data, member).await? {
|
||||
if !hold.scope.accounts.contains(&member.account) {
|
||||
hold.scope.accounts.push(member.account);
|
||||
hold.scope.accounts.sort_unstable();
|
||||
update(data, &hold).await?;
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Replaces a hold that `check_update` allowed.
|
||||
pub async fn update(data: &Store, hold: &Hold) -> trc::Result<()> {
|
||||
let mut batch = BatchBuilder::new();
|
||||
|
||||
Reference in New Issue
Block a user