Expire trash after 30 days, and make the deadline something you can see
CI & Build / Python lint (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 6s
CI & Build / Python tests (push) Successful in 12s
CI & Build / Build & push image (push) Successful in 44s
Desktop (Tauri) / Tauri desktop (Linux) (push) Failing after 1m45s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m12s
CI & Build / Python lint (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 6s
CI & Build / Python tests (push) Successful in 12s
CI & Build / Build & push image (push) Successful in 44s
Desktop (Tauri) / Tauri desktop (Linux) (push) Failing after 1m45s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m12s
Trash had no end. A note sat in /trash until someone emptied it by hand, and its attachment BYTES sat on disk the whole time — the pile-up the operator asked about. Nothing purged; there was no scheduler at all. Retention is server-owned: `trash_retention_days` (default 30, 0 = keep forever) in the settings registry, so it lands in admin Settings with no migration and takes effect without a restart. A background sweep started in before_serving does the work. Clients learn about a purge the way they learn about any deletion — as a tombstone on the delta feed. An auto-purge nobody can see coming is data loss on a timer, so the window is now visible: /api/config publishes it, notes carry `deleted_at`, Trash leads with the policy, and each card counts down. The countdown rounds DOWN — saying "1 day left" for a note with ten minutes on the clock is the one error here that actually costs someone a note. Three things this turned up on the way: - `DELETE /api/notes/<id>` hard-deleted the row, leaving no tombstone at all. A permanent delete in the web UI never reached a linked device, which would keep its copy forever and push it back on the next edit. It now purges through the same path as everything else. - The purge left `note_revisions` and `note_link_previews` behind. A revision holds the full body, so the text of a "permanently deleted" note was still sitting in the database. - `deleted_at` now SURVIVES a purge instead of being cleared. It's still true, and it means every query that says "not trashed" excludes tombstones for free — without it a content-less row reads as a perfectly normal active note and shows up on the board as a blank card. Desktop keeps its own clock only when there's nobody else to keep one: the sweep runs at startup on an UNLINKED device and refuses otherwise. A linked client that expired notes on its own schedule could destroy something the server was deliberately keeping, then push that delete upstream. Local policy must never outrank the server's — so it also adopts the server's window for the countdown rather than showing its offline default. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SreJkbxB4gx8pPsu8QbLPi
This commit is contained in:
@@ -49,3 +49,36 @@ export function formatLocalDay(d: Date): string {
|
||||
const pad = (n: number) => String(n).padStart(2, "0");
|
||||
return `${d.getFullYear()}-${pad(d.getMonth() + 1)}-${pad(d.getDate())}`;
|
||||
}
|
||||
|
||||
// --- Trash retention. The server permanently deletes a trashed note once it's older
|
||||
// than `trash_retention_days` (0 = keep forever). Counting down from the note's own
|
||||
// deleted_at is what turns that from a surprise into a policy: a card in Trash can
|
||||
// say how long it has left while there's still time to restore it. ---
|
||||
|
||||
const MS_PER_DAY = 24 * 60 * 60 * 1000;
|
||||
|
||||
// Whole days a trashed note has left, or null when nothing will happen to it
|
||||
// (retention off, or the note isn't trashed).
|
||||
//
|
||||
// Rounds DOWN deliberately. Rounding up would report "1 day left" for a note with
|
||||
// ten minutes on the clock — overstating the time remaining is the one error here
|
||||
// that actually costs someone a note.
|
||||
export function trashDaysLeft(
|
||||
deletedAt: string | null | undefined,
|
||||
retentionDays: number,
|
||||
now: number = Date.now(),
|
||||
): number | null {
|
||||
if (!deletedAt || retentionDays <= 0) return null;
|
||||
const trashedAt = new Date(deletedAt).getTime();
|
||||
if (Number.isNaN(trashedAt)) return null;
|
||||
const remaining = trashedAt + retentionDays * MS_PER_DAY - now;
|
||||
return remaining <= 0 ? 0 : Math.floor(remaining / MS_PER_DAY);
|
||||
}
|
||||
|
||||
// The countdown as the card shows it. "" when there's nothing to say.
|
||||
export function formatTrashCountdown(daysLeft: number | null): string {
|
||||
if (daysLeft === null) return "";
|
||||
if (daysLeft <= 0) return "Deletes today";
|
||||
if (daysLeft === 1) return "1 day left";
|
||||
return `${daysLeft} days left`;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user