Editing one security answer no longer deletes the others
Shipped 2026-09-21
Same-day follow-up to TUN-873, found while verifying it in production.
Security answers are stored hashed, so the profile editor cannot show a member what they already set — every answer box is blank when the page loads. The writer shipped that morning treated a blank answer as “this question is gone” and deleted its row. A member who opened the screen to change one answer, typed into one box and saved, lost the other two without being told.
A blank now means leave this question alone. Only a question the member did
not submit at all is removed, which is what happens when they change the question
in a slot rather than the answer. planSecurityAnswers returns the two sets
separately — keep, every question submitted, and write, those with an answer
to store — so the delete and the upsert no longer share one list.
The form blocked it too: all three answer boxes were required, so the browser
would not submit until every answer was retyped. A slot whose question is
unchanged is now optional, labelled “Leave blank to keep your current answer”.
Change the question and its answer is required again — three answers remain
mandatory, so a swapped question needs a new answer or the member would end up
with two.
The behaviour it replaced was worse, for what it is worth: before TUN-873 the same edit stored empty strings for the untouched answers, which counted as “has security questions” while never matching anything a member could type. That left them being offered a fallback they could not complete. Neither version let a member update a single answer; this one does.