Allow administrators to immediately delete user accounts

(#703) Feature Under consideration moderation self-hosting

Current problem

Expected behaviour Administrators should be able to immediately delete user accounts, or configure the deletion delay instead of being forced to wait 60 days.

Additional information

Reproduction steps
  1. Log in as an instance administrator.
  2. Open the Admin Panel.
  3. Navigate to the user management page.
  4. Select a user account.
  5. Attempt to permanently delete the account.

Details

Summary

This issue was opened following a request from maintainer Kamalaja in Discussion #1235. Currently, the Admin Panel only allows scheduling account deletion with a mandatory minimum deletion period of 60 days. While this may be appropriate for user-initiated account deletion, it unnecessarily restricts instance administrators. Administrators should be able to permanently delete user accounts immediately, or at least configure the deletion delay. This is especially useful for:
  • Spam or abusive accounts
  • Duplicate accounts
  • Test accounts
  • Accounts removed at the user's request
At the moment, the only workaround is direct database manipulation, which should not be necessary for routine administrative tasks.

Current behavior

The deletion can only be scheduled and enforces a minimum deletion period of 60 days.
  1. Rex changed the status from Needs triage to Under consideration

3 comments

Sign in with Fluxer to comment and vote.
Comment by @nostelux
RexSystem 1 vote originally by @nostelux on GitHub
I don't think an immediate delete now is a good idea. There are sure to be admins who would abuse this, and once an account is deleted, it is gone and unrecoverable. There needs to be some sort of safeguard I think
Comment by @dunny1g
RexSystem 1 vote originally by @dunny1g on GitHub
I don't think an immediate delete now is a good idea. There are sure to be admins who would abuse this, and once an account is deleted, it is gone and unrecoverable. There needs to be some sort of safeguard I think
Fair but 60 days is too long imo. OP, my workaround was to login to the account (was only a test account) and delete it from the client which should be 14 days but the scheduled deletion date in the admin panel shows 3 days after the deletion request.
Comment by @IamLurking
RexSystem 1 vote originally by @IamLurking on GitHub
Making it possible to change the number of days until the account is deleted so that you can set it to what you want would be the best solution. I personally would not want the power to be able to delete a user immediately, mistakes happen and if you delete the wrong account, that would be bad if you have other users. I do not know what the process is when deleting accounts, I would expect they are disabled ? I've seen places have the account "deleted", but it's just hidden in another database table until it is eventually deleted some time later. So, ideas ? :
  • Disabling the account until it is deleted
  • Quarantine space for accounts to be in until deletion
  • Rename "to be deleted" accounts to make them unusable
  • Admin can change how long before an account is deleted from the database.
ie : Make it possible to see an account is set to be deleted but not accessible by the user, and still have it deleted at a later date, just in case it was a mistake.
Deleted comment
Removed by moderator Rex: Removed a general status note that was posted on many GitHub threads. It no longer applies here.