Skip to content

fix(user): purge used and expired verification codes daily - #73

Merged
jplacht merged 1 commit into
mainfrom
fix/verification-code-cleanup
Oct 2, 2026
Merged

jplacht merged 1 commit into
mainfrom
fix/verification-code-cleanup

Conversation

@jplacht

@jplacht jplacht commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What and why

Verification codes were never deleted once used or expired. The only cleanup was replacing a user's previous code of the same purpose, so every user kept a dead row (code stored in plaintext). This adds a daily purge task.

Closes #12

Changes

  • add user_purge_verification_codes task: bulk-deletes codes that are used or older than EXPIRY_TIME (same cutoff as VerificationCode.is_expired)
  • log verification_codes_purged with the deleted count
  • test: used and expired codes deleted, active code kept, for both purposes

How it was verified

uv run ruff check, uv run ruff format --check, uv run ty check --exclude "**/migrations/*.py", uv run pytest (811 passed).

Deploy step

After deploy, add a Periodic task in the admin: task user_purge_verification_codes, crontab daily (e.g. 03:00 UTC). Periodic tasks live in the DB (DatabaseScheduler); the task does not run until this row exists.

Note (out of scope)

EXPIRY_TIME reads only verification_expiry_minutes, so password-reset codes expire on that setting, while the reset email states password_reset_expiry_minutes. Both default to 30; it only matters if they diverge.

🤖 Generated with Claude Code

- add user_purge_verification_codes task: bulk-deletes codes that are used
  or older than EXPIRY_TIME (same cutoff as VerificationCode.is_expired)
- log verification_codes_purged with the deleted count
- test: used and expired codes deleted, active code kept, for both purposes

Closes #12

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codacy-production

codacy-production Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

🟢 Coverage 100.00% diff coverage · +0.01% coverage variation

Metric Results
Coverage variation ✅ +0.01% coverage variation (-1.00%)
Diff coverage ✅ 100.00% diff coverage

View coverage diff in Codacy

Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (b50ca03) 4883 4673 95.70%
Head commit (be2606f) 4891 (+8) 4681 (+8) 95.71% (+0.01%)

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#73) 9 9 100.00%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@jplacht
jplacht merged commit 9796e21 into main Oct 2, 2026
6 checks passed
@jplacht
jplacht deleted the fix/verification-code-cleanup branch October 2, 2026 05:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

VerificationCode cleanup task

1 participant