Skip to content

fix(proxy): pass DELETE /users/delete through so the SDK can delete an account - #167

Merged
Bccorb merged 1 commit into
mainfrom
fix/users-delete-passthrough
Sep 14, 2026
Merged

Bccorb merged 1 commit into
mainfrom
fix/users-delete-passthrough

Conversation

@Bccorb

@Bccorb Bccorb commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Closes #166.

Summary

The client SDK's deleteUser() sends DELETE /users/delete, the auth API serves it on auth: 'access', and neither adapter registered it, so the call answered the adapter's own 404 in both transports. Both adapters now pass it through:

  • packages/core/src/handlers/deleteAccount.ts: deleteAccountHandler, exported from the package. Forwards with the caller's credential; on success returns the auth API's body with the access, refresh and pre-auth cookies to clear (the same trio /logout clears), on failure the upstream body through readUpstreamFailure and no cookie change.
  • Express: r.delete("/users/delete", ...) beside the logout routes, handler in packages/express/src/handlers/deleteAccount.ts.
  • Fastify: the same route in authRoutes.ts beside the logout loop.
  • ensureCookies: /users/delete requires the access cookie, like /users/update.
  • Express README lists the route; changeset is a patch for all three packages (a missing route, not a contract change).

Verification

pnpm build && pnpm test: core 305, express 186, fastify 103, all passing. New cases:

  • Express usersRoutes.test.js: the route forwards DELETE /users/delete with Authorization: Bearer <access>, answers the upstream body and clears seamless-access, seamless-ephemeral, seamless-refresh; a 404 from upstream passes through with no Set-Cookie; no session means no upstream call.
  • Fastify parity.test.js: "deleting the account clears every session cookie" holds both adapters to the same status, body and cookies.
  • Fastify bearerTransport.parity.test.js: both adapters forward the bearer token and set no cookie.

Found while building RoxTarget's account deletion (fells-code/roxtarget-web#8, fells-code/roxtarget-mobile#8), whose second half needs this release.

…n account

The client SDK's deleteUser() has always sent DELETE /users/delete and
the auth API has always served it, but neither adapter registered the
route, so the call answered the adapter's own 404 through Express and
the Fastify plugin alike. Nothing built on the SDK could delete an
account, which both app stores require.

Both adapters forward it with the caller's credential through a new
core deleteAccountHandler. In cookie transport a successful deletion
clears the access, refresh and pre-auth cookies the way /logout does,
since the account they named no longer exists and the silent refresh
would otherwise renew a session that is gone; a refused deletion leaves
them alone. In bearer transport the auth API's body passes through and
the client clears its own tokens. ensureCookies requires the access
cookie on the route, and the parity suites hold both adapters to the
same answer in both transports.

Closes #166.
@Bccorb
Bccorb merged commit 652881e into main Sep 14, 2026
2 checks passed
@Bccorb
Bccorb deleted the fix/users-delete-passthrough branch September 14, 2026 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(proxy): DELETE /users/delete is not passed through, so the SDK's deleteUser() answers 404

1 participant