Skip to main content

Module ops

Module ops 

Source
Expand description

Account operations judged against a Principal: who is in an org, invitations, API tokens, SSH keys, sessions and users. The identity endpoints (super::http) and the daemon’s account tools (member_list, token_create, …) both call these, so a rule holds the same on every surface. Answers are the JSON the endpoints return.

The rules on top of each role (Role::permissions):

  • Nobody outside an org learns about it: its members, invitations and tokens answer 404 to non-members (platform admins excepted).
  • Only an owner (or platform admin) touches an owner or makes one.
  • A workspace (its isb_ws_ token) is nobody’s account: it reaches none of this.
  • A token cannot mint tokens (may_mint_tokens): API tokens, workspace tokens and superadmin tokens are refused, so revoking a leaked token always ends what it could do. New tokens come from a browser session, an Access or tailnet identity, or the host CLI.

Structs§

NewAgentIdentity
What PUT orgs/{org}/agent-identities and agent_identity_set take.
NewToken
What POST tokens and token_create take.
UserChange
What PATCH admin/users/ID and user_update change.

Functions§

account_holder
Refuse a workspace: account operations are for people and their tokens.
add_ssh_key
agent_identities
The org’s tailnet and Access mappings, and which front doors this server has. Any member may read.
create_token
Mint an API token for the caller: {token, info}, the token shown once.
delete_ssh_key
invitations
invite
Invite email to org as role (default member). The answer carries the invitation token once, and a link when public_url is known.
link
<public_url>/<page>#<token>: the token goes in the fragment, which browsers never send to a server or put in a Referer.
may_change_accounts
Refuse a token scoped short of admin (and a workspace) a change to accounts, tokens, keys, invitations or members.
may_mint_tokens
May p mint an API token? Not with a token of any kind: a token that could mint another would survive its own revocation through the copy, and a scope or expiry bound on the copy would not change that.
me
Who is calling: the user, their orgs, and how they signed in.
members
org_tokens
Every token in org, with who holds each: a platform admin’s token in an org they are not a member of has no member row to name it.
remove_agent_identity
Remove a mapping (owners and admins; a mapping is never an owner’s).
remove_member
Remove uid from org: anyone may leave; removing others needs the right to manage.
revoke_invitation
revoke_session
revoke_token
Revoke token id: its holder’s own, or any in an org the caller manages. Anything else is indistinguishable from a token that does not exist.
sessions
set_agent_identity
Map a tailnet login or tag, an Access email or a service token to a role (never owner, and at most the caller’s own) in org.
set_role
ssh_keys
tokens
The caller’s own tokens (an org token sees only its org’s), or only org’s when given.
update_user
Disable or enable a user, or make or unmake a platform admin. Nobody does either to themselves, and the platform keeps an enabled admin.
users
Every user, with their orgs and when they were last active.
visible_org
Members see who else is in their org; nobody else learns it exists.