Skip to content

OAuth deprovisioning on delete

Auto-generated from the source archive. Do not edit by hand — rerun catalyst-changelog-sync instead.

  • Deleting a HubApp now deprovisions its OAuth identity in the same all-or-nothing transaction: the OAuth application, its clients, their link rows, and every refresh token of those clients are hard-deleted. Any failure rolls everything back.
  • Access tokens are deliberately left to expire on their own and are purged later by the existing token-retention job — only the renewal vector dies immediately.
  • Because the OAuth application is physically removed, the app’s unique code is freed and can be registered again; the delete confirmation dialog now warns that credentials and SSO end immediately and irreversibly.

This is the mirror of provisioning-on-register. Before, deleting an app left its OAuth identity orphaned: the code stayed occupied forever and the satellite’s sessions could keep renewing indefinitely. Now deletion is a real teardown — a deleted app can no longer renew a session, and the catalog keeps its history while the credentials genuinely disappear. The HUB delete flow is the single owner of deprovisioning, completing the no-drift guarantee in both directions.


View original proposal