Skip to content

feat(web): add safe persisted session deletion - #396

Open
testikun wants to merge 1 commit into
openpi-dev:mainfrom
testikun:codex/issue-347-session-delete
Open

feat(web): add safe persisted session deletion#396
testikun wants to merge 1 commit into
openpi-dev:mainfrom
testikun:codex/issue-347-session-delete

Conversation

@testikun

@testikun testikun commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Problem

Related to #347. Web Workbench can archive Sessions but cannot safely remove a persisted non-active Session. Deletion must not be confused with archive metadata removal, and the active Session must never be deleted.

Value

Adds a bounded, auditable persistence-management primitive for Session retention while keeping Pi JSONL files authoritative and preventing accidental active-session loss.

Approach

  • Add an authenticated DELETE /api/sessions?path=... endpoint.
  • Resolve the target from the canonical Pi Session projection and require a .jsonl file inside the configured Web Session directory.
  • Reject the active Session with an explicit 409 SESSION_CONFLICT response.
  • Remove the persisted file first, then clean Web-owned archived and ungrouped derived indexes.
  • Publish a session_deleted event for connected clients.
  • Keep native confirmation/UI, archive browsing, historical editing, and fork semantics out of this backend-only slice; those remain separate lifecycle work.

Validation

  • Focused Node tests: 34 passed, 0 failed.
  • Full Node/Vitest suite: 1339 passed, 1 skipped, 0 failed; Vitest 30 passed.
  • biome format / biome lint --error-on-warnings: passed.
  • tsc --noEmit: passed.
  • Config-contract, discipline-ledger, and Web syntax checks: passed.
  • Ablation: removing the typed deletion-conflict error caused the active-session API regression to return 500 instead of the required 409; the error boundary was restored.
  • bun is not installed in this environment, so the equivalent repository scripts were run with the bundled Node 24 executable and local Biome/Vitest binaries.

Impact

  • User-visible behavior: backend deletion API and deletion event; no UI changes in this PR.
  • Model-visible context/tools: none.
  • Runtime/lifecycle: active Session deletion is rejected; non-active persisted files are removed.
  • Persisted data: targeted JSONL file is deleted and Web-owned index entries are cleaned.
  • Compatibility/risk: endpoint is authenticated and exact-target bounded; native confirmation remains a required follow-up before exposing this mutation in UI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant