Handle a request to be forgotten¶
The policy promises that anyone can see what the bot holds about
them and ask to be forgotten. This is how to do both with
phpbotscout forget.
Forgetting a person disconnects them. What they asked in a public channel stays, and so does the bot's answer and every count built on them. What goes is everything that leads back to them (spec 0032).
Before you start¶
- The request came from the person themselves. Reply to where it came from, not to a handle someone else gave you.
- You can run
phpbotscoutagainst the databaseserveuses.forgetruns whileserveis up.
Find the user ID¶
The bot keeps no names or handles, so the command needs the numeric Discord user ID. In Discord, turn on Settings → Advanced → Developer Mode, then right-click the person and choose Copy User ID. Or ask the person for it; they can copy their own.
Show them what is held¶
Piping the ID keeps it out of your shell history. The output lists each question, the answer the bot gave, and each vote. Send it to the person if they asked to see their data.
Forget them¶
Check what will change, then make the change:
$ echo 123456789012345678 | phpbotscout forget
Would disconnect 2 answers and 1 vote. Nothing has changed yet.
Run the same command with --yes to make the change, or --show to list them.
$ echo 123456789012345678 | phpbotscout forget --yes
Disconnected 2 answers and 1 vote.
The database file has been rewritten, so nothing connecting them remains in it.
If it fails saying another connection is reading, run the same command again. The records were already disconnected; the second run finishes rewriting the file.
Tell them what it did not reach¶
Say plainly what stays:
- Anything posted to a GitLab issue. If they want that removed, edit or delete the issue by hand.
- Their messages in Discord, and the bot's replies. They can delete their own; a moderator can delete the bot's.
- Log lines and database backups from the last 30 days, which expire on their own.
Keep the host to the same 30 days¶
The last item is only true if the host enforces it. Do this once per host, and again on any host the bot moves to.
Logs¶
serve writes no message text and no author to its log
(spec 0028),
but versions before it did. Cap the journal at 30 days:
journald removes whole files, never single lines. MaxFileSec=1day starts a new file each day, so
no line outlives the window by more than a day. Without it the default monthly file can hold a line
for nearly two months. The setting applies to every journal on the host, not only this service.
Backups¶
A copy of the database holds everything the database held when it was taken, and forget never
reaches it. Keep backups beside the database with a .bak suffix, and let a timer delete them
after 30 days:
# ~/.config/systemd/user/phpbotscout-backup-expiry.service
[Unit]
Description=Delete phpbotscout database backups older than 30 days
[Service]
Type=oneshot
ExecStart=/usr/bin/find %h/.local/share/phpbotscout -maxdepth 1 -name 'phpbotscout.db.*.bak' -mtime +30 -delete
# ~/.config/systemd/user/phpbotscout-backup-expiry.timer
[Unit]
Description=Delete phpbotscout database backups older than 30 days, daily
[Timer]
OnCalendar=daily
Persistent=true
[Install]
WantedBy=timers.target
$ systemctl --user daemon-reload
$ systemctl --user enable --now phpbotscout-backup-expiry.timer
$ systemctl --user list-timers phpbotscout-backup-expiry.timer
The last command shows when it last ran and when it runs next.