Expand description
Account operations judged against a Principal: who is in an org,
invitations, API tokens, SSH keys, sessions and users. The identity
endpoints (super::http) and the daemon’s account tools
(member_list, token_create, …) both call these, so a rule holds
the same on every surface. Answers are the JSON the endpoints return.
The rules on top of each role (Role::permissions):
- Nobody outside an org learns about it: its
members,invitationsandtokensanswer404to non-members (platform admins excepted). - Only an owner (or platform admin) touches an owner or makes one.
- A workspace (its
isb_ws_token) is nobody’s account: it reaches none of this. - A token cannot mint tokens (
may_mint_tokens): API tokens, workspace tokens and superadmin tokens are refused, so revoking a leaked token always ends what it could do. New tokens come from a browser session, an Access or tailnet identity, or the host CLI.
Structs§
- NewAgent
Identity - What
PUT orgs/{org}/agent-identitiesandagent_identity_settake. - NewToken
- What
POST tokensandtoken_createtake. - User
Change - What
PATCH admin/users/IDanduser_updatechange.
Functions§
- account_
holder - Refuse a workspace: account operations are for people and their tokens.
- add_
ssh_ key - agent_
identities - The org’s tailnet and Access mappings, and which front doors this server has. Any member may read.
- create_
token - Mint an API token for the caller:
{token, info}, the token shown once. - delete_
ssh_ key - invitations
- invite
- Invite
emailtoorgasrole(default member). The answer carries the invitation token once, and a link whenpublic_urlis known. - link
<public_url>/<page>#<token>: the token goes in the fragment, which browsers never send to a server or put in a Referer.- may_
change_ accounts - Refuse a token scoped short of
admin(and a workspace) a change to accounts, tokens, keys, invitations or members. - may_
mint_ tokens - May
pmint an API token? Not with a token of any kind: a token that could mint another would survive its own revocation through the copy, and a scope or expiry bound on the copy would not change that. - me
- Who is calling: the user, their orgs, and how they signed in.
- members
- org_
tokens - Every token in
org, with who holds each: a platform admin’s token in an org they are not a member of has no member row to name it. - remove_
agent_ identity - Remove a mapping (owners and admins; a mapping is never an owner’s).
- remove_
member - Remove
uidfromorg: anyone may leave; removing others needs the right to manage. - revoke_
invitation - revoke_
session - revoke_
token - Revoke token
id: its holder’s own, or any in an org the caller manages. Anything else is indistinguishable from a token that does not exist. - sessions
- set_
agent_ identity - Map a tailnet login or tag, an Access email or a service token to a
role (never owner, and at most the caller’s own) in
org. - set_
role - ssh_
keys - tokens
- The caller’s own tokens (an org token sees only its org’s), or only
org’s when given. - update_
user - Disable or enable a user, or make or unmake a platform admin. Nobody does either to themselves, and the platform keeps an enabled admin.
- users
- Every user, with their orgs and when they were last active.
- visible_
org - Members see who else is in their org; nobody else learns it exists.