## Summary - Add self-service deletion for the authenticated customer or subuser identity only. - Preserve shared customer grants, reset keys, bookings, order bookings, vehicles, invoices, and legally required history. - Require password/TOTP or a fresh deletion-specific, five-minute, single-use WebAuthn assertion. - Reject support impersonation and expired legacy plain-session tokens. - Use durable database throttling, transactional request processing, a durable outbox, and terminal `manual_review` state. - Keep API and worker default-off behind separate `account_deletion.api_enabled` and `account_deletion.worker_enabled` module-config flags. ## Safe rollout 1. Keep both flags disabled. 2. Run `php scripts/account-deletion-schema.php check`. 3. If needed, run `php scripts/account-deletion-schema.php apply --yes`, then rerun `check` until `ready:true`. 4. Deploy the frontend companion PR while the API remains disabled. 5. Enable `api_enabled` for a controlled canary; verify password and passwordless request flows plus immediate authentication revocation. 6. Inspect queued request/outbox state, then enable `worker_enabled`. 7. Verify anonymization, preserved tenant/history data, outbox delivery, retries, and manual-review behavior before broad rollout. ## Verification - Account deletion unit tests: 2 passed, 43 assertions. - PHP lint, both OpenAPI YAML parses, runtime-DDL scan, destructive-scope scan, and `git diff --check` passed. - Full API/unit/integration evidence is required from exact-head CI; local Docker is unavailable and shared-vendor tests were explicitly discarded. ## Security notes - Schema mutation is CLI-only; web and cron paths perform read-only readiness checks. - Runtime behavior fails closed when schema/config/throttle/delivery prerequisites are unavailable.
17 lines
581 B
PHP
17 lines
581 B
PHP
<?php
|
|
|
|
return [
|
|
[
|
|
'id' => 'account.process_deletion_requests',
|
|
'legacy_name' => 'ProcessAccountDeletionRequestsCron',
|
|
'name' => 'Process account deletion requests',
|
|
'description' => 'Anonymizes requested customer and chauffeur accounts while retaining legally required records.',
|
|
'module' => 'account',
|
|
'handler' => 'ProcessAccountDeletionRequestsCron',
|
|
'schedule' => ['type' => 'interval', 'seconds' => 300],
|
|
'timeout_seconds' => 300,
|
|
'estimated_duration_ms' => 2000,
|
|
'priority' => 25,
|
|
],
|
|
];
|