Skip to main content

Module ops

Module ops 

Source
Expand description

Account operations judged against a Principal: who is in an org, invitations, API tokens, SSH keys, sessions and users. The identity endpoints (super::http) and the daemon’s account tools (member_list, token_create, …) both call these, so a rule holds the same on every surface. Answers are the JSON the endpoints return.

The rules on top of each role (Role::permissions):

  • Nobody outside an org learns about it: its members, invitations and tokens answer 404 to non-members (platform admins excepted).
  • Only an owner (or platform admin) touches an owner or makes one.
  • A workspace (its isb_ws_ token) is nobody’s account: it reaches none of this.
  • A token cannot mint tokens (may_mint_tokens): API tokens, workspace tokens and superadmin tokens are refused, so revoking a leaked token always ends what it could do. New tokens come from a browser session, an Access or tailnet identity, or the host CLI.

Structs§

NewAgentIdentity
What PUT orgs/{org}/agent-identities and agent_identity_set take.
NewToken
What POST tokens and token_create take.
UserChange
What PATCH admin/users/ID and user_update change.

Functions§

account_holder
Refuse a workspace: account operations are for people and their tokens.
add_ssh_key
agent_identities
The org’s tailnet and Access mappings, and which front doors this server has. Any member may read.
all_tokens
Every API token on the platform, with who holds each.
create_token
Mint an API token for the caller: {token, info}, the token shown once.
delete_ssh_key
delete_user_ssh_key
invitations
invite
Invite email to org as role (default member). The answer carries the invitation token once, and a link when public_url is known.
link
<public_url>/<page>#<token>: the token goes in the fragment, which browsers never send to a server or put in a Referer.
may_change_accounts
Refuse a token scoped short of admin (and a workspace) a change to accounts, tokens, keys, invitations or members.
may_mint_tokens
May p mint an API token? Not with a token of any kind: a token that could mint another would survive its own revocation through the copy, and a scope or expiry bound on the copy would not change that.
me
Who is calling: the user, their orgs, and how they signed in.
members
org_tokens
Every token in org, with who holds each: a platform admin’s token in an org they are not a member of has no member row to name it.
remove_agent_identity
Remove a mapping (owners and admins; a mapping is never an owner’s).
remove_member
Remove uid from org: anyone may leave; removing others needs the right to manage.
revoke_invitation
revoke_session
revoke_token
Revoke token id: its holder’s own, or any in an org the caller manages. Anything else is indistinguishable from a token that does not exist.
sessions
set_agent_identity
Map a tailnet login or tag, an Access email or a service token to a role (never owner, and at most the caller’s own) in org.
set_role
ssh_keys
tokens
The caller’s own tokens (an org token sees only its org’s), or only org’s when given.
update_user
Disable or enable a user, or make or unmake a platform admin. Nobody does either to themselves, and the platform keeps an enabled admin.
user_ssh_keys
users
Every user, with their orgs and when they were last active.
visible_org
Members see who else is in their org; nobody else learns it exists.

Type Aliases§

OrgsFn
The orgs that exist, as the runtime knows them (the daemon asks incus and its servers). The store’s org rows anchor memberships and tokens but are not the truth: an org made or removed past the daemon (isb org against incus with another state directory, a test) leaves them behind.