Expand description
Administration: list and inspect accounts, ban and unban them, revoke their sessions, grant
and revoke roles, read the audit log, read and write a user’s storage objects
(AdminPutObject may set the server write lock). Routes: routes::admin; every one
needs an access token of an account with the ADMIN_ROLE role (others get 403 forbidden).
These routes are for operator tools (a dashboard, a script), not for game clients. A server may leave them out of its public API description.
Structs§
- Admin
PutObject - An administrator’s write: like
PutObject, plus the write lock. - Admin
User - An account as an administrator sees it:
GET /v1/admin/users/{user}(and the items of the listing). - Audit
Entry - One audit-log entry: who did what, when, from where. Never holds secrets.
- Audit
Query - Read the audit log:
GET /v1/admin/audit?user=…&action=…&cursor=…&limit=…→Page<AuditEntry>, newest first. - BanInfo
- A ban of an account.
- BanRequest
- Ban an account:
POST /v1/admin/users/{user}/ban→Ack. Every session of the account is revoked (open WebSockets close with 4003); logins answer 403bannedwhile the ban is in force. - BanUser
- Ban an account:
POST /v1/admin/users/{user}/banwith aBanRequest→Ack. - GetUser
- One account:
GET /v1/admin/users/{user}→AdminUser. - GetUser
Object - Read one of a user’s objects:
GET /v1/admin/users/{user}/storage/{collection}/{key}→StorageObject(audited asadmin.storage_read). - Grant
Role - Grant a role:
PUT /v1/admin/users/{user}/roles/{role}→Ack. - List
User Objects - List one collection of a user’s storage:
GET /v1/admin/users/{user}/storage/{collection}→Page<StorageObjectInfo>(no values; audited asadmin.storage_list). - Remove
User Object - Delete one of a user’s objects:
DELETE /v1/admin/users/{user}/storage/{collection}/{key}→Ack(audited asadmin.storage_delete; server-locked objects too). - Revoke
Role - Revoke a role:
DELETE /v1/admin/users/{user}/roles/{role}→Ack. - Revoke
Sessions - Revoke every session of an account:
DELETE /v1/admin/users/{user}/sessions→Ack. - Unban
User - Lift a ban:
POST /v1/admin/users/{user}/unban→Ack. - Unlink
User Identity - Unlink a login provider from an account:
DELETE /v1/admin/users/{user}/identities/{provider}→Ack. - User
List Query - List accounts:
GET /v1/admin/users?q=…&cursor=…&limit=…→Page<AdminUser>, newest first. - Write
User Object - Write one of a user’s objects:
PUT /v1/admin/users/{user}/storage/{collection}/{key}with anAdminPutObject→ObjectAck(audited asadmin.storage_write).
Constants§
- ADMIN_
ROLE - The role that may use the administration routes.
- BAN_
REASON_ MAX_ CHARS - The longest ban reason, in characters.
- ROLE_
MAX_ BYTES - The longest role name, in bytes.
- USER_
SEARCH_ MAX_ CHARS - The longest search text of a user listing, in characters.
Functions§
- is_
valid_ role - Whether
roleis a valid role name: 1 toROLE_MAX_BYTESbytes of[a-z0-9_.-], starting with a letter (admin,moderator,beta.tester).