feat(grant): clean up expired grants

This commit is contained in:
Edouard Vanbelle
2026-07-12 18:14:15 +02:00
parent 9ed360443a
commit ba620166ee
12 changed files with 623 additions and 1 deletions
+13
View File
@@ -230,6 +230,19 @@ DATABASE_URL=postgres://postgres:postgres@localhost:5432/oxicloud
# Enable trash/recycle bin functionality (default: true)
#OXICLOUD_ENABLE_TRASH=true
# Background daemon that deletes expired `storage.role_grants` rows.
# The AuthZ engine already filters expired grants out of every
# permission check at read time, so leaving expired rows in place is
# a hygiene issue — not a security one. This purge deletes rows
# whose `expires_at` is more than GRACE_DAYS in the past, preserving
# the audit / support answer to "what happened to my access?" for
# the grace window.
#
# Default: enabled. Recommended grace: >= 15 days.
#OXICLOUD_GRANT_CLEANUP_ENABLED=true
#OXICLOUD_GRANT_CLEANUP_GRACE_DAYS=15
#OXICLOUD_GRANT_CLEANUP_INTERVAL_HOURS=24
# Enable search functionality (default: true)
#OXICLOUD_ENABLE_SEARCH=true