Repository navigation
feat(chat): add mass deletion of conversations - #680
Conversation
Add a bulk delete endpoint that takes a list of session IDs and deletes the sessions and their messages in a single transaction, restricted to sessions owned by the current user. Non-existent or foreign session IDs are ignored, like the single deletion endpoint ignores unknown IDs. In the conversation list, add a deletion mode with a "Delete multiple conversations" entry button matching the "New conversation" button style, per-conversation selection, a select-all/deselect-all toggle and a confirmation dialog. Single deletion reuses the bulk endpoint and dialog. Destructive buttons use the error variant like the confirmation dialogs of the server apps, and the deletion mode is left with Escape. The dialog is bound with v-model on a writable computed and remounted via a key on every open: closing it with Escape leaves a 300ms delayed internal teardown in NcDialog which, with a one-way open binding, kept the open prop stuck true when the dialog was quickly reopened, making the delete button unresponsive until a page reload. Fixes nextcloud#639 Assisted-by: opencode:glm-5.3 Signed-off-by: WSHAPER <42714629+WSHAPER@users.noreply.github.com>
…inline Address review feedback: having one action inline and one in the action menu looked inconsistent, and NcAppNavigationItem's action menu does not open when the assistant is used inside the viewer because its popover container is hardcoded to "#app-navigation-vue", of which a second instance exists beneath the viewer. The global "Delete multiple conversations" button at the top of the list is enough to enter the deletion mode; the single-delete action is now the only per-item action and is always inline, so no action menu is rendered at all. Assisted-by: opencode:glm-5.3 Signed-off-by: WSHAPER <42714629+WSHAPER@users.noreply.github.com>
69b474a to
69c41e8
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 4 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThe change adds API endpoints for deleting multiple chat sessions. The service removes matching sessions owned by the current user and their messages in a transaction. The chat interface adds a deletion mode with individual or select-all selection, confirmation, and local state updates after successful deletion. Service tests cover deletion, ownership, duplicate and unknown IDs, empty input, and a missing user ID. Priority: ➖ Normal Merge Risk: 🟡 Moderate · up to Large conversation selections may fail to delete, and running the new tests against a shared database could remove an existing account. Address those risks before merging; the dialog also needs a small rendering safeguard. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The bulk API preserves account ownership and deletes sessions and messages transactionally. The identified new risk is limited to database-backed tests: cleanup can delete pre-existing accounts when the tests run against a shared installation. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 18 functions across 6 files. (2 skipped: 2 unsupported.)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
ℹ️ Review info
⚙️ Run configuration
- Configuration used: Organization UI
- Review profile: CHILL
- Plan: Advanced
- Run ID:
a6db6ef8-f622-490c-bae0-0ba70ab36c70
📒 Files selected for processing (8)
appinfo/routes.phplib/Controller/ChattyLLMController.phplib/Db/ChattyLLM/MessageMapper.phplib/Db/ChattyLLM/SessionMapper.phplib/Service/ChatService.phpopenapi.jsonsrc/components/ChattyLLM/ChattyLLMInputForm.vuetests/unit/Service/ChatServiceTest.php
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.
julien-nc
left a comment
There was a problem hiding this comment.
Nice! Works just fine.
- Let's put the button at the bottom of the conversation list for now.
Chunk the IN queries of the bulk session operations with IQueryBuilder::MAX_IN_PARAMETERS so large ID lists stay within the database bind limits, guard the confirmation message and title getter against missing sessions, and make the ChatServiceTest only remove the users and sessions it created so tests don't alter instance state in CI. Assisted-by: opencode:glm-5.3 Signed-off-by: WSHAPER <42714629+WSHAPER@users.noreply.github.com>
Fixes #639
Summary
Adds mass deletion of chat conversations:
DELETE /ocs/v2.php/apps/assistant/chat/sessions(RESTful) andDELETE /ocs/v2.php/apps/assistant/chat/delete_sessions(legacy). It deletes the sessions and their messages in a single transaction, restricted to sessions owned by the current user. Non-existent or foreign session IDs are ignored, like the single deletion endpoint ignores unknown IDs.openapi.jsonregenerated.#app-navigation-vueand floating-vue then resolves to the Files instance underneath the viewer. Tracked for upstream in nextcloud-vue (no prop exists as of 9.9.0 / latest / master).Implementation notes
v-model:openon a writable computed and remounted via a key on every open: closing it with Escape leaves a 300ms delayed internal teardown in NcDialog which, with a one-way open binding, left the open prop stuck true when the dialog was quickly reopened, making the delete button unresponsive until a page reload.ChatServiceTestcovers the service-level edge cases (happy path, ownership/unknown/duplicate IDs, empty list, null user). Full suite passes (45 tests).Manual test plan
DELETE .../chat/delete_sessions?sessionIds[]=1&sessionIds[]=2→ 200, sessions and messages gone, other users' data untouched; empty list → 400.Detailed testing notes are in the issue.
AI disclosure
This change was developed with AI assistance (opencode / glm-5.3); the code was reviewed, tested manually and adjusted by the contributor.