Problem
The verification API creates pending tokens in the database when domains are claimed, but there's currently no mechanism to clean up old tokens that were never verified. This could lead to:
- Database growth over time
- Slower query performance as the tokens collection grows
- Potential confusion with multiple pending tokens for the same domain
Proposed Solution
Implement a cleanup strategy for expired verification tokens. Options to consider:
- TTL-based cleanup: Set a reasonable expiration time (e.g., 30 days) for pending tokens
- Periodic cleanup job: Run a background task to remove old unverified tokens
- Database-level TTL: Use MongoDB TTL indexes to automatically expire old tokens
- Cleanup on new claims: When claiming a domain, remove any existing pending tokens first
Implementation Considerations
- Should preserve verified tokens indefinitely
- Need to decide on appropriate token lifetime (suggested: 30-90 days)
- Consider impact on existing tokens in production
- May want to add token creation timestamps if not already present
Related
Problem
The verification API creates pending tokens in the database when domains are claimed, but there's currently no mechanism to clean up old tokens that were never verified. This could lead to:
Proposed Solution
Implement a cleanup strategy for expired verification tokens. Options to consider:
Implementation Considerations
Related