pub async fn set_role(
username: &str,
role: AdminRole,
database: Arc<Database>,
) -> Result<Option<(AdminUser, u64)>, UserError>Expand description
Sets an operator’s privilege tier and revokes every session they hold.
The revocation matches set_status("disabled") and set_password: a
demotion that left a live admin session alive would take effect only when
that cookie happened to expire. It is belt-and-braces rather than
load-bearing – the write extractors re-read role from admin_users on
every request – but this layer already holds that convention. None when
there is no such user; otherwise the operator and how many sessions went
with the change, which the caller records as its own session_revoked
audit row (this layer is front-end agnostic and does not know the actor).
Demoting the last admin is refused: /operators/* is admin-only on
both web surfaces, so a deployment with none has no way to manage operators
from the panel at all. Recoverable from this host — which is why it is a
refusal here rather than a CHECK — but the operator should hear about it
before it happens rather than after.