The record of what was sent can be destroyed or rewritten: cascading deletes, uploads replaced in place, files left on disk #217
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#217
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
applications/models.py:10says "Nothing here deletes history", and PLAN §5 and the wiki (Files and what you sent: "the record of what you sent has to stay true") promise that sent snapshots are kept unchanged. Three paths break that. Found in the 2026-09-15 code audit.1. Deleting a company, listing or application silently deletes applications and their sent documents
The chain is all
CASCADE:JobPosting.company(jobs/models.py:617)Application.posting(applications/models.py:195)ApplicationEvent.applicationandInterview.applicationRenderedDocument.application(documents/models.py:486-492)What the person sees:
templates/partials/confirm_delete.html).documents/signals.py:31-48). Deleting the application is not.sent_uploads.Proposal:
PROTECTonApplication.posting, or a confirmation page that lists how many applications, timeline entries, interviews and sent documents will go.SET_NULLonRenderedDocument.application, keeping company and role as text on the render.2. Editing an uploaded file replaces it in place
UploadedDocumentFormincludesfile(documents/forms.py:220), andUploadUpdateView(documents/views.py:318) uses the same form.sent_uploadspoints at the row, so it now shows a file it never sent.UploadedDocumenthas no checksum, so the change cannot be detected.signals.py:24acts only on creation, so external stores keep the old copy marked archived.Proposal: make
fileread-only on edit, so a new file means a new version throughreplaces. Add achecksumto uploads and pass it inmetadata_for, which today sends an empty checksum.3. Deleted documents' files stay on disk
accounts/deletion.py:109-117is the only code that removes a document file.UploadDeleteView, render rows removed with an application, and files replaced as in 2 all leave their bytes behind.backupcopies them.Proposal:
post_deleteofUploadedDocumentandRenderedDocument, remove the file after commit when no other row uses the name.manage.py prune_media --dry-run, which lists files underdocuments/<owner>/with no row.Tests