You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix: tombstone is not reversible; stop claiming otherwise (CL-6288)
tombstoneDocument overwrites chunk.text with '[redacted]' — there is no
history/audit table and no un-tombstone verb, so the original content does
not survive a forget request; only version metadata does. The route summary
and docs/RETENTION.md previously said "reversible in principle," which would
lead a host to build an "undo forget" button with nothing to undo to.
Describe what forget actually does (stops appearing in search, content
redacted, row kept for audit) instead. purge remains genuinely irreversible
(the row itself is removed) — that claim was already correct.
Drive-by: docs/RETENTION.md said the ephemeral sweeper "hard-deletes" past
valid_until; sweepEphemeral only sets status=deprecated and never deletes.
Pre-existing inaccuracy, fixed while already editing this file.
0 commit comments