pub async fn set_status(
username: &str,
status: AdminStatus,
database: Arc<Database>,
) -> Result<Option<(AdminUser, u64)>, Error>Expand description
Moves an operator between active and disabled.
Disabling also drops their sessions: leaving them live would mean a
disabled operator kept working until their cookie happened to expire. That
revocation is audited by the caller as a session_revoked row, since only
the front end knows who asked for it.
Takes an AdminStatus rather than the &str five call sites used to
spell by hand. AdminUser::set_status below this still takes a string, and
deliberately: it is the raw column write, and the test that a value outside
the migration’s CHECK is refused by SQLite has to be able to pass one.
This layer is where a typo should stop being expressible — a mistyped
"enable" here would have written a status no is_active accepts, i.e. a
permanent lockout dressed as a successful re-enable.