Currently there is a problem if an exception is thrown in `User::delete`, because at that point the user is already removed from the backend, but not all data is deleted. There is no way to recover from this state, as the user is gone no information is available anymore. This means the data is still available on the server but can not removed by any API anymore. The solution here is to first set a flag and backup the user home, this can be used to recover failed user deletions in a way the delete can be re-tried. Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>pull/47896/head
parent
c8a907fc8c
commit
16833aff86
@ -0,0 +1,30 @@ |
||||
<?php |
||||
|
||||
declare(strict_types=1); |
||||
|
||||
/** |
||||
* SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors |
||||
* SPDX-License-Identifier: AGPL-3.0-or-later |
||||
*/ |
||||
namespace OC\Repair; |
||||
|
||||
use OC\User\BackgroundJobs\CleanupDeletedUsers; |
||||
use OCP\BackgroundJob\IJobList; |
||||
use OCP\Migration\IOutput; |
||||
use OCP\Migration\IRepairStep; |
||||
|
||||
class AddCleanupDeletedUsersBackgroundJob implements IRepairStep { |
||||
private IJobList $jobList; |
||||
|
||||
public function __construct(IJobList $jobList) { |
||||
$this->jobList = $jobList; |
||||
} |
||||
|
||||
public function getName(): string { |
||||
return 'Add cleanup-deleted-users background job'; |
||||
} |
||||
|
||||
public function run(IOutput $output) { |
||||
$this->jobList->add(CleanupDeletedUsers::class); |
||||
} |
||||
} |
||||
@ -0,0 +1,55 @@ |
||||
<?php |
||||
|
||||
declare(strict_types=1); |
||||
|
||||
/** |
||||
* SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors |
||||
* SPDX-License-Identifier: AGPL-3.0-or-later |
||||
*/ |
||||
namespace OC\User\BackgroundJobs; |
||||
|
||||
use OC\User\FailedUsersBackend; |
||||
use OC\User\Manager; |
||||
use OC\User\User; |
||||
use OCP\AppFramework\Utility\ITimeFactory; |
||||
use OCP\BackgroundJob\TimedJob; |
||||
use OCP\EventDispatcher\IEventDispatcher; |
||||
use OCP\IConfig; |
||||
use Psr\Log\LoggerInterface; |
||||
|
||||
class CleanupDeletedUsers extends TimedJob { |
||||
public function __construct( |
||||
ITimeFactory $time, |
||||
private Manager $userManager, |
||||
private IConfig $config, |
||||
private LoggerInterface $logger, |
||||
) { |
||||
parent::__construct($time); |
||||
$this->setInterval(3600); |
||||
} |
||||
|
||||
protected function run($argument): void { |
||||
$backend = new FailedUsersBackend($this->config); |
||||
$users = $backend->getUsers(); |
||||
|
||||
if (empty($users)) { |
||||
$this->logger->debug('No failed deleted users found.'); |
||||
return; |
||||
} |
||||
|
||||
foreach ($users as $userId) { |
||||
try { |
||||
$user = new User( |
||||
$userId, |
||||
$backend, |
||||
\OCP\Server::get(IEventDispatcher::class), |
||||
config: $this->config, |
||||
); |
||||
$user->delete(); |
||||
$this->logger->info('Cleaned up deleted user {userId}', ['userId' => $userId]); |
||||
} catch (\Throwable $error) { |
||||
$this->logger->warning('Could not cleanup deleted user {userId}', ['userId' => $userId, 'exception' => $error]); |
||||
} |
||||
} |
||||
} |
||||
} |
||||
@ -0,0 +1,46 @@ |
||||
<?php |
||||
|
||||
/** |
||||
* SPDX-FileCopyrightText: 2024 Nextcloud GmbH and Nextcloud contributors |
||||
* SPDX-License-Identifier: AGPL-3.0-or-later |
||||
*/ |
||||
namespace OC\User; |
||||
|
||||
use OCP\IConfig; |
||||
use OCP\IUserBackend; |
||||
use OCP\User\Backend\IGetHomeBackend; |
||||
|
||||
/** |
||||
* This is a "fake" backend for users that were deleted, |
||||
* but not properly removed from Nextcloud (e.g. an exception occurred). |
||||
* This backend is only needed because some APIs in user-deleted-events require a "real" user with backend. |
||||
*/ |
||||
class FailedUsersBackend extends Backend implements IGetHomeBackend, IUserBackend { |
||||
|
||||
public function __construct( |
||||
private IConfig $config, |
||||
) { |
||||
} |
||||
|
||||
public function deleteUser($uid): bool { |
||||
// fake true, deleting failed users is automatically handled by User::delete() |
||||
return true; |
||||
} |
||||
|
||||
public function getBackendName(): string { |
||||
return 'deleted users'; |
||||
} |
||||
|
||||
public function userExists($uid) { |
||||
return $this->config->getUserValue($uid, 'core', 'deleted') === 'true'; |
||||
} |
||||
|
||||
public function getHome(string $uid): string|false { |
||||
return $this->config->getUserValue($uid, 'core', 'deleted.backup-home') ?: false; |
||||
} |
||||
|
||||
public function getUsers($search = '', $limit = null, $offset = null) { |
||||
return $this->config->getUsersForUserValue('core', 'deleted', 'true'); |
||||
} |
||||
|
||||
} |
||||
Loading…
Reference in new issue