Skip to main content

create_user

Function create_user 

Source
pub async fn create_user(
    username: &str,
    plaintext: &str,
    context: &PasswordContext,
    role: Option<AdminRole>,
    database: Arc<Database>,
) -> Result<AdminUser, UserError>
Expand description

Creates an operator at role, or at AdminRole::Admin when none is named.

Order matters: the policy is checked before the duplicate lookup, and the duplicate lookup before the (expensive) hash, so a rejected request never pays 600 000 iterations.

One write. This used to create at admin and call set_role afterwards, which made admin user create --role viewer two statements: a failure between them left an operator at full authority with their password already set, and the second statement had to be exempted from set_role’s last-admin guard, since the row it was demoting was the admin it had just created.