Legal holds, step 5: held accounts can't be destroyed

Destroying a held account removes the login, as offboarding needs, but
keeps its data as a deleted account with no expiry, whether or not
undelete keeps accounts; its addresses stay reserved and its holds name
it from then on. Destroy-now refuses it, and its DestroyAccount task
defers itself while it's held or its time hasn't come. Holds placed or
released later freeze or free kept accounts in the same settle pass,
with 30 days' grace after the last release (LH-8, LH-10).
This commit is contained in:
2026-09-27 19:33:07 -07:00
parent 8d3e99bc00
commit 39707cd2e8
5 changed files with 168 additions and 7 deletions
@@ -55,6 +55,23 @@ impl DestroyAccountTask for Server {
async fn destroy_account(server: &Server, task: &TaskDestroyAccount) -> trc::Result<TaskResult> {
let account_id = task.account_id.document_id();
// inbuxa: LH-8, LH-10: a kept account waits for its time, and a held one
// for its release; "destroy now" clears the kept record first
if let Some(kept) =
inbuxa_features::undelete::data::kept_account(&server.core.storage.data, account_id).await?
{
let now = store::write::now();
let held = inbuxa_features::hold::is_held_until(kept.kept_until)
|| server.is_kept_held(account_id, &kept).await?;
if held || kept.kept_until > now {
let retry = if held { now + 86_400 } else { kept.kept_until };
return Ok(TaskResult::deferred(
Some(retry),
"The account is still kept: a legal hold applies, or its time hasn't come.",
));
}
}
// Destroy public keys and masked emails
for object in [ObjectType::PublicKey, ObjectType::MaskedEmail] {
let mut batch = BatchBuilder::new();