feat(control-plane): confirm destructive org/project/repo delete

Commit

toothbrush3mo ago

org/project/repo delete called the destructive API immediately after resolving the ref — a name typo that resolves to a real resource (or a wrong-but-valid ULID) deleted silently. Gate each behind a confirmation prompt (the existing trail-delete pattern) with a --force/-f bypass and --yes/-y alias; non-interactive runs refuse without --force rather than deleting unprompted. Shared body extracted to runControlPlaneDelete.

Addresses trail #642 finding.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 5201fa5dc67c

Checkpoints

Control Plane Delete and Revoke Safety

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1