trackslash
TRACK-66 P2

Delete a project from the project actions menu

0
All issues

Description

There is currently no way to delete a project from the UI. DELETE /projects/{key} and track_delete_project exist, but both are gated on site-admin, so a project owner cannot remove their own project through any surface they can reach.

Scope

  • Add a Delete project action to the project actions ("more") overflow menu on the project header.
  • Opening it shows a confirmation dialog that spells out what deletion does (the project and all of its issues are soft-deleted and the project disappears from every list) and requires the project key to be typed before the destructive button submits.
  • Cancelling returns to the current project view without navigating away.
  • On success, redirect to the owner's projects list.

Permission model

DELETE /projects/{key} and track_delete_project currently require site-admin. That leaves a project owner unable to delete a project they created, so the UI action would be dead for nearly everyone. Widen deletion to project owner or site admin across the HTTP API, MCP, and UI so all three surfaces share one rule. Project members with write access must not gain deletion rights - deleting a whole project is not the same authority as editing its contents.

This adds ProjectPermissions.CanDelete (owner or site admin) alongside the existing CanWrite / CanManageMembers flags.

Notes

  • Deletion stays a soft delete; store.DeleteProject already cascades deleted_at to the project's issues.
  • The menu item and both routes must be hidden and refused for anyone without delete permission.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

2
Bradley

Merged as 99b1060 (PR #151, squashed). CI green on both build + vet + test and docker build + healthcheck.

Bradley

PR open: https://github.com/badbundle/track-slash-app/pull/151 (branch track-66-delete-project).

Implemented as specified. One thing to review deliberately: deletion is now project owner or site admin across the UI, HTTP API, and MCP, via a new ProjectPermissions.CanDelete. It was site-admin only before, which would have made the new menu entry dead for anyone who is not a site admin. Write members do not gain deletion rights.