Skip to content

Require password when deleting account#1054

Merged
Toastbrot236 merged 5 commits intoLittleBigRefresh:mainfrom
Toastbrot236:delete-check
Mar 21, 2026
Merged

Require password when deleting account#1054
Toastbrot236 merged 5 commits intoLittleBigRefresh:mainfrom
Toastbrot236:delete-check

Conversation

@Toastbrot236
Copy link
Copy Markdown
Contributor

For security reasons, this PR makes requests to the user's own account deletion endpoint require a body with a SHA512 hash of the user's password, regardless of whether they are already authenticated. This does alter APIv3 spec, but it's likely not a widely used endpoint. A complementary PR for the refresh-web legacy branch will be opened alongside this one.

@Toastbrot236 Toastbrot236 merged commit 7ca1750 into LittleBigRefresh:main Mar 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant