From 6f35e6e6d8a5f50090ff07d9d4d72a99147b7ce6 Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Sun, 26 Jul 2026 15:40:33 -0400 Subject: [PATCH] Confirm irreversible deletes, which sync just made far more consequential MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The trash model itself was already right and needed no change: notes soft- delete (`trashed` locally, `deleted_at` server-side), Trash is a real view, restore works, permanent deletion is a separate second step only offered on an already-trashed note, `trash()` shows an Undo toast, and nothing auto- purges — trash persists until someone acts. Sync carries all of it: a trashed note syncs WITH its content, and only `purged_at` deletes a client's copy. What was missing is the guard on the irreversible step. "Delete forever" and label deletion were one click, silent, with no confirmation — and M10.7 has changed what that costs. Before, a mis-click lost a note on one machine. Now it pushes a tombstone that deletes it from every linked device, and the local tombstone survives to make sure it gets there. Both guards live in the STORE, not the call sites: NoteCard and NoteEditor both offer delete-forever, and duplicating the copy is how two prompts drift until one of them stops matching what actually happens. The copy names the real consequence — "deleted from every device you sync with" — because that's the part a user cannot infer from a button in a Trash view. The label prompt also says the notes themselves are kept, since that's what people actually worry about when deleting a label. Labels deliberately get a confirmation but NOT a trash of their own. A label is organization, not content; the reversible middle step notes get would be ceremony around something that costs nothing to recreate. Saved-filter deletion already confirmed (AppShell), so these two were the outliers, not a new convention. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01SreJkbxB4gx8pPsu8QbLPi --- frontend/src/stores/labels.ts | 13 +++++++++++++ frontend/src/stores/notes.ts | 12 ++++++++++++ 2 files changed, 25 insertions(+) diff --git a/frontend/src/stores/labels.ts b/frontend/src/stores/labels.ts index 1890b0c..f64a182 100644 --- a/frontend/src/stores/labels.ts +++ b/frontend/src/stores/labels.ts @@ -47,6 +47,19 @@ export const useLabelsStore = defineStore("labels", () => { } async function remove(id: string): Promise { + // Labels have no trash of their own — a label is organization, not content, so + // the reversible middle step notes get would be ceremony. But deleting one is + // still irreversible and now reaches every synced device, so it asks first. The + // notes themselves survive; only the membership goes, which is the part people + // most need reassuring about. + const label = items.value.find((lb) => lb.id === id); + const subject = label ? `the label "${label.name}"` : "this label"; + const confirmed = window.confirm( + `Delete ${subject}?\n\n` + + "It will be removed from every note that uses it, on every device you sync " + + "with. The notes themselves are kept.", + ); + if (!confirmed) return; await repo.labels.remove(id); items.value = items.value.filter((lb) => lb.id !== id); } diff --git a/frontend/src/stores/notes.ts b/frontend/src/stores/notes.ts index ed54ad7..4a73525 100644 --- a/frontend/src/stores/notes.ts +++ b/frontend/src/stores/notes.ts @@ -249,6 +249,18 @@ export const useNotesStore = defineStore("notes", () => { } async function deleteForever(id: string): Promise { + // Guarded HERE rather than at the call sites (NoteCard and NoteEditor both offer + // it) so the two can't drift on the one action with no undo. Trash is the + // reversible step and already offers Undo; this is the point of no return — and + // since sync propagates a tombstone, it reaches every linked device too. + const note = items.value.find((n) => n.id === id); + const title = note?.display_title.trim(); + const subject = title ? `"${title}"` : "this note"; + const confirmed = window.confirm( + `Permanently delete ${subject}?\n\n` + + "This can't be undone, and it will be deleted from every device you sync with.", + ); + if (!confirmed) return; await repo.notes.deleteForever(id); const idx = items.value.findIndex((n) => n.id === id); if (idx >= 0) items.value.splice(idx, 1);