Expand description
Administrative operations, shared by both front ends and owned by neither.
cli and crate::webadmin are the two front ends; everything
they can do lives here, so the password policy, the duplicate check and the
rehash-on-login cannot drift between a terminal and a browser.
ops— the operations themselves (accounts, orders, EAB, nonces, audit).render— one JSON renderer per shape, surfacing the admin-only fields (an order’s revocation, an account’s traceability columns) the ACME wire format deliberately does not carry. JSON only: both front ends parse these, so they are a wire format. The human-readable renderings have exactly one consumer and live incli::render, which is where colour is woven in — and therefore cannot reach a--jsonshape.password,users— the credential store and the KDF.changes— a change to an operator (by another, or their own contact address), with its audit rows and message, for both front ends.totp,recovery,mfa— the second factor: RFC 6238 over RFC 4226, single-use recovery codes, and where those two meet the database.prompt— confirmation, over an injectable reader so it is testable.subject— the one “not found” sentence per kind of row.
Destructive operations come in pairs: a bare form, and a confirm_*
wrapper taking assume_yes and a reader. Those two arguments are a
terminal’s concern, so the CLI calls the wrapper and the web calls the bare
form — rather than an HTTP caller passing true and an empty reader to
assert a confirmation that never happened.
Re-exports§
Modules§
- changes
- A change to an operator — by another operator, or, for the contact address, by themselves: each change with everything it owes — the write, the audit rows, the message — in one function both front ends call.
- mfa
- The second-factor operations, which both front ends dispatch to and neither owns.
- ops
- The operator operation layer: what an operator may do to a stored row, independent of which front end asked.
- password
- Password hashing for the web admin’s operators.
- prompt
- The
[y/N]confirmation every destructive CLI command asks. - recovery
- Recovery codes: the way back in when the phone holding the TOTP secret is gone.
- render
- The JSON renderings, shared by both front ends.
- subject
- What a lookup was for, so “not found” reads the same on every surface.
- totp
- RFC 6238 time-based one-time passwords, over RFC 4226’s HOTP.
- users
- Operator management for the web admin: create, list, re-password, set the privilege tier, enable, disable, delete, and the password check the login path runs.