Unlinking a device is one flow in the core: link::unlink

The desktop's sync_unlink and the ffi's unlink were both written out in full: try
the revoke, clear the link either way, and log the outcome. link::unlink(db, held)
now does that. Each client reads its link with state::credentials (with its seal)
before the await and passes it in.

DRY pass #2, batch 1, F3 (#5372).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-08 14:16:59 -04:00
co-authored by Claude Opus 5.5
parent 91c47245ab
commit 1f2ddd70d3
3 changed files with 31 additions and 27 deletions
+5 -14
View File
@@ -526,23 +526,14 @@ impl Inkwell {
/// so the revoke is attempted first, its outcome returned for the UI to report
/// honestly, and the link cleared either way.
pub async fn unlink(&self) -> Result<RevokeOutcome, CoreError> {
// Read and release before the network call: a std MutexGuard isn't Send, so
// it cannot be held across an await, and holding the store through a
// round-trip would freeze every note operation in the UI. A token that won't
// open on this phone can't be revoked from here, so it is skipped.
let link = match self.credentials() {
Ok(link) => Some(link),
// A token that won't open on this phone can't be revoked from here, so it
// is skipped.
let held = match self.credentials() {
Ok(held) => Some(held),
Err(CoreError::NotLinked) => None,
Err(e) => return Err(e),
};
let revoked = match &link {
Some((base_url, token)) => client::revoke_self(base_url, token).await,
None => client::RevokeOutcome::Skipped,
};
let conn = self.db.conn().map_err(CoreError::store)?;
state::clear_link(&conn).map_err(CoreError::store)?;
log::info!("unlinked from server (server-side token: {revoked:?})");
let revoked = link::unlink(&self.db, held).await.map_err(CoreError::store)?;
Ok(revoked.into())
}