Fix: Removing Delete button from customer view, deletes should flow only through the privacy services

This commit is contained in:
2026-09-28 10:05:40 +03:00
parent 088d8cb809
commit a55411aaf2
@@ -3,6 +3,7 @@
namespace Modules\Core\Privacy\Filament\Extensions;
use Filament\Actions\Action;
use Filament\Actions\DeleteAction;
use Filament\Forms\Components\Checkbox;
use Filament\Notifications\Notification;
use Lunar\Admin\Support\Extending\BaseExtension;
@@ -20,13 +21,18 @@ use Modules\Core\Privacy\Services\PrivacyService;
* docs/modules.md "Layering Module and App Configuration"), and this extension
* deliberately only implements headerActions(), so it never conflicts with an
* app's own extension for the same resource.
*
* Also strips Lunar's own plain DeleteAction from these pages — with Privacy
* installed, "Request Erasure" (grace period, cascades, audit trail via
* DataErasureRequest) is the only sanctioned way to remove a Customer; a
* direct delete would bypass all of that.
*/
class CustomerErasureActionsExtension extends BaseExtension
{
public function headerActions(array $actions): array
{
return [
...$actions,
...array_filter($actions, fn ($action) => ! $action instanceof DeleteAction),
Action::make('requestErasure')
->label('Request Erasure')
->icon('heroicon-o-shield-exclamation')