Data deleted... or not ? security concern

Relatedly, if you change the name of a field, the original name you created still shows up in the developer console. There is no way to “optimize” a changed field name. Really poor stuff.

2 Likes

I’m not sure if they changed anything due to this thread, but it looks like privacy rules get reset for deleted fields (here’s a test):

Screenshot 2024-10-06 205700

When I restore a field, the privacy rules are always the least permissive.

@randomanon i wonder what happens after optimization…, I did not test yet

@fede.bubble would you have any insights to share about this problem ?

1 Like

honestly not really, I’d have to dig through it.
Are you asking if Bubble is planning on including work around this area in the future?

1 Like

I think that’s what she was going for.

@fede.bubble
yes

  1. As a very strict minimum (and it does not represent a lot of work effort), users should be aware : documentation updated + message to clean-up data before deleting a field
  2. Correcting the situation

great, I’ll bring it up to the team (assuming they aren’t already discussing this internally)

1 Like

thanks, let’s ut know !!

Happy to share the following from the team:

Hi everyone,
Thank you for your patience. We want to clarify some recent changes we’ve made to help reduce WU consumption based on community feedback. As of October 16 2024, we no longer charge WU for removing a field from a data type in the Performing a Database Search and Lookup a Specific Item activities.

The reason we don’t delete data by default is to maintain the ability to revert application changes, as we generally avoid making irreversible operations when editing an application.

In the meantime, we recommend deleting data before removing a field from a data type. If you notice any discrepancies, please submit a support case.
We’ve heard your feedback about needing more clarity on this, and the product team is discussing next steps. Thank you!

9 Likes

Looks like the system closed this based on time. Reopened in case people want to add more

Thanks @fede.bubble, Great to see things moving.
“As of October 16 2024, we no longer charge WU for removing a field from a data type in the Performing a Database Search and Lookup a Specific Item activities.” : I understand that before this date, bubble clients were charged for searches on deleted data, and hopefully, this is not the case anymore.

Still, It does not address security concern of having data still showing in the app with no access on their privacy rules.
Is there any plan to update the documentation and/or bubble to include warning at the time of field deletion ?

3 Likes

Really think the obvious next step here is to ensure that the most restrictive possible privacy rules are automatically applied to any deleted field or type.

3 Likes

Has this been fixed? If we delete data, does it get deleted permanently?

@fede.bubble can you please check with the team if this topic is on the roadmap ? Thank you

1 Like

Would like to know as well.

Seems it is there to stay Data types and fields | Bubble Docs

2 Likes

I think we should be able to permanently delete a field, knowing that it would be permanently removed and impossible to recover even with save points that were older than the time the field was removed. Maybe would be enough to have a way of consent and alert to the developer, like when we are going to delete a branch, where we are forced to manually type the name of the branch as a confirmation. This way, any problems due to permanent deletion would not fall on Bubble, since alerts and confirmations were given.

So, if I already marked a field as ‘deleted’. Do I then have to:

  1. restore the field
  2. create a workflow to delete values from that field
  3. push to LIVE
  4. run that workflow in LIVE
  5. mark the field as deleted
  6. push to LIVE

This seems absurd to me… :melting_face:

1 Like