Expand description
Operator management for the web admin: create, list, re-password, set the privilege tier, enable, disable, delete, and the password check the login path runs.
The operation layer, not a front end: no printing, no HTTP, no terminal.
src/cli/webadmin.rs and crates/admin/src/webadmin/handlers/session.rs both dispatch
here, which is what keeps the password policy, the duplicate check and the
rehash-on-login identical between them.
Enums§
- Auth
Outcome - The result of checking a username and password.
- User
Delete Outcome - What
confirm_delete_userdid. - User
Error - Why creating or re-passwording an operator failed.
Functions§
- authenticate
- Checks a username and password, re-hashing the stored digest if it was written under parameters this build has moved past.
- change_
own_ password - Changes an operator’s own password, keeping the session that requested it alive and revoking every other one.
- confirm_
delete_ user delete_user, asking first and naming what goes with it.- create_
user - Creates an operator at
role, or atAdminRole::Adminwhen none is named. - delete_
user - Deletes an operator, cascading to their sessions.
falsewhen there was no such user. - list_
users - One page of the operators, oldest first, plus the total the table holds.
- operators_
without_ a_ contact - How many operators have no
contact_emailon file. - revoke_
sessions - Revokes every session one operator holds, without touching the account.
Nonewhen there is no such user. - set_
contact_ email - Sets (
Some) or clears (None/ empty / whitespace) the address an operator receives security notifications at.Someis validated as a mailbox — the same parseacme_proxy_jobs::notify::emaildoes before it sends — so a malformed address is refused here rather than becoming a permanent delivery failure later. Not a credential: sessions are left alone. - set_
password - Replaces an operator’s password and revokes every session they hold.
- set_
role - Sets an operator’s privilege tier and revokes every session they hold.
- set_
status - Moves an operator between
activeanddisabled. - valid_
username - Whether a normalized username is one the web admin can address.