Change account self-delete confirmation to be more lenient and recall current account (#40733)

This commit is contained in:
Claire
2026-09-30 10:40:34 +00:00
committed by GitHub
parent 215f59f937
commit cc10de7b97
4 changed files with 16 additions and 7 deletions

View File

@@ -29,7 +29,8 @@ class Settings::DeletesController < Settings::BaseController
end
def challenge_passed?
return false unless current_account.username == resource_params[:username]
username = resource_params[:username].strip.delete_prefix('@')
return false unless current_account.username.casecmp(username).zero? || current_account.local_username_and_domain.casecmp(username).zero?
current_user.encrypted_password.blank? || current_user.valid_password?(resource_params[:password])
end

View File

@@ -1,5 +1,5 @@
- content_for :page_title do
= t('settings.delete')
= t('deletes.title', acct: current_account.local_username_and_domain)
= simple_form_for @confirmation, url: settings_delete_path, method: :delete do |f|
%p.hint= t('deletes.warning.before')
@@ -20,10 +20,17 @@
%hr.spacer/
= f.input :username, wrapper: :with_block_label, input_html: { autocomplete: 'off' }, hint: t('deletes.confirm_username')
= f.input :username,
wrapper: :with_block_label,
input_html: { autocomplete: 'off' },
label: t('deletes.confirm_username'),
hint: t('deletes.confirm_username_hint_html', username: current_account.username)
- if current_user.encrypted_password.present?
= f.input :password, wrapper: :with_block_label, input_html: { autocomplete: 'current-password' }, hint: t('deletes.confirm_password')
= f.input :password,
wrapper: :with_block_label,
input_html: { autocomplete: 'current-password' },
hint: t('deletes.confirm_password')
.actions
= f.button :button, t('deletes.proceed'), type: :submit, class: 'negative'

View File

@@ -1525,9 +1525,11 @@ en:
deletes:
challenge_not_passed: The information you entered was not correct
confirm_password: Enter your current password to verify your identity
confirm_username: Enter your username to confirm the procedure
confirm_username: Confirm username
confirm_username_hint_html: Please type <code>%{username}</code> to confirm the account you want to delete
proceed: Delete account
success_msg: Your account was successfully deleted
title: Delete account %{acct}
warning:
before: 'Before proceeding, please read these notes carefully:'
caches: Content that has been cached by other servers may persist
@@ -2132,7 +2134,6 @@ en:
appearance: Appearance
authorized_apps: Authorized apps
back: Back to Mastodon
delete: Account deletion
development: Development
edit_profile: Edit profile
export: Export

View File

@@ -11,7 +11,7 @@ RSpec.describe 'Settings Deletes' do
it 'requires password and deletes user record', :inline_jobs do
visit settings_delete_path
expect(page)
.to have_title(I18n.t('settings.delete'))
.to have_title(I18n.t('deletes.title', acct: user.account.local_username_and_domain))
.and have_private_cache_control
# Wrong confirmation value