No way to prevent permanent deletion / emptying the trash bin (make files.permanent_deletion configurable) #3638
nomoreqwerty
started this conversation in
Ideas
Replies: 1 comment 1 reply
|
There is another way: many providers are using the decomposedS3 driver. They configure a S3 bucket Retention policy and do regular snapshots of the posix storage. The deletion process in openCloud is already a two step process. For spaces, you could use a sharing role „without trashbin“ to prevent trashbin purges and single file deletes. That still leaves the personal space of a user where all actions are always allowed. |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
As an administrator, I want to control whether users are allowed to permanently delete items (the "Empty trash bin" action and the permanent "Delete" in the trash), so that regular users can only delete into the trash bin and data can only be purged by an administrator / by the retention policy.
User Value
Current Behaviour (against
main)files.permanent_deletionplus a resource-level permission check:packages/web-app-files/src/composables/actions/files/useFileActionsEmptyTrashBin.ts—isVisible()returnsfalseif!capabilityStore.filesPermanentDeletion, then requiresresources[0].canDeleteFromTrashBin({ user }).packages/web-app-files/src/composables/actions/files/useFileActionsDelete.ts— the permanentdelete-permanentaction uses the same capability +canDeleteFromTrashBin().packages/web-pkg/src/composables/piniaStores/capabilities.ts—permanent_deletion: trueis the client-side default andfilesPermanentDeletionis derived from it.permanent_deletion/PermanentDeletionanywhere inservices/,pkg/orvendor/.services/frontend/pkg/revaconfig/config.gobuilds thefilescapability block withundelete,versioning,private_links, … but nopermanent_deletion, so the client always falls back to itstruedefault. Therefore an administrator cannot turn permanent deletion off today.PurgeRecycle, mapped to the Graph actionlibre.graph/driveItem/deleted/delete(
services/graph/pkg/unifiedrole/conversion.go). Built-in role behaviour:PurgeRecycle(decomposedfs/node/permissions.go,OwnerPermissions()), and the web client short-circuits on ownership (packages/web-client/src/helpers/space/functions.ts→canDeleteFromTrashBin()returnstruefor a personal-space owner, with aFIXME: server permissions are a mess currentlyreferring to The permissions for Graph drives are not appropriate #10). → the owner can always empty their own trash.ManagerhasPurgeRecycle(revaNewManagerRole());SpaceEditor/SpaceEditorWithoutVersionsandSpaceViewerdo not. → editors can delete and restore, but not purge. This is the only working control that exists today, and it is not configurable.services/settings/pkg/store/defaults/permissions.gohas no trash/purge-related permission, and the web runtime config (web.config.json→options,OptionsConfigSchemainweb-pkg) has no trash-related option.Proposed Behaviour
Drives.DeleteFromTrashBin, mirroringDrives.DeletePersonal/Drives.DeleteProject) with the usual constraintOwn/All, checked wherePurgeRecycleis assembled today — i.e. it must be enforced server-side (WebDAV/trash-binpurge, Graph, and CLI/service account excluded so the retention task keeps working).files.permanent_deletion(in the frontend/OCS capabilities block) reflecting that permission, so clients that already understand it (the web UI does, see above) work without changes. Defaults must preserve today's behaviour — this must be a no-op on upgrade.canDeleteFromTrashBin()must not short-circuit on ownership when the capability is off), with a hint such as "Permanent deletion is disabled by your administrator — items are removed automatically after N days";DELETEon a trash-bin item, purge request) return403 Forbidden.opencloud storage-users trash-bin purge-expired,… trash-bin list/restore-all/restore <spaceID>,opencloud trash purge-empty-dirs -p …) and/or the admin role/Space Adminrole having the permission.OwnvsAll) so that e.g.Manager/Space Adminmay still empty the trash of the spaces they manage.STORAGE_USERS_PURGE_TRASH_BIN_PERSONAL_DELETE_BEFORE/…_PROJECT_DELETE_BEFORE.Related
FIXMEreferenced fromfunctions.ts.Workaround available today
Only partial, and it does not cover personal spaces: give members the space role Can view (nothing lands in the trash at all) or Can edit (SpaceEditor cannot purge), and keep the Manager role for administrators; purge/restore is done by an admin via the
storage-users trash-binCLI. For personal spaces there is no way to prevent the owner from emptying the trash, and disabling personal spaces is not an option — the share jail lives inside the personal space root.All reactions