Skip to main content

Module admin

Module admin 

Source
Expand description

Administration: list and inspect accounts, ban and unban them, revoke their sessions, grant and revoke roles, read the audit log, read and write a user’s storage objects (AdminPutObject may set the server write lock). Routes: routes::admin; every one needs an access token of an account with the ADMIN_ROLE role (others get 403 forbidden).

These routes are for operator tools (a dashboard, a script), not for game clients. A server may leave them out of its public API description.

Structs§

AdminPutObject
An administrator’s write: like PutObject, plus the write lock.
AdminUser
An account as an administrator sees it: GET /v1/admin/users/{user} (and the items of the listing).
AuditEntry
One audit-log entry: who did what, when, from where. Never holds secrets.
AuditQuery
Read the audit log: GET /v1/admin/audit?user=…&action=…&cursor=…&limit=… → Page<AuditEntry>, newest first.
BanInfo
A ban of an account.
BanRequest
Ban an account: POST /v1/admin/users/{user}/ban → Ack. Every session of the account is revoked (open WebSockets close with 4003); logins answer 403 banned while the ban is in force.
BanUser
Ban an account: POST /v1/admin/users/{user}/ban with a BanRequest → Ack.
GetUser
One account: GET /v1/admin/users/{user} → AdminUser.
GetUserObject
Read one of a user’s objects: GET /v1/admin/users/{user}/storage/{collection}/{key} → StorageObject (audited as admin.storage_read).
GrantRole
Grant a role: PUT /v1/admin/users/{user}/roles/{role} → Ack.
ListUserObjects
List one collection of a user’s storage: GET /v1/admin/users/{user}/storage/{collection} → Page<StorageObjectInfo> (no values; audited as admin.storage_list).
RemoveUserObject
Delete one of a user’s objects: DELETE /v1/admin/users/{user}/storage/{collection}/{key} → Ack (audited as admin.storage_delete; server-locked objects too).
RevokeRole
Revoke a role: DELETE /v1/admin/users/{user}/roles/{role} → Ack.
RevokeSessions
Revoke every session of an account: DELETE /v1/admin/users/{user}/sessions → Ack.
UnbanUser
Lift a ban: POST /v1/admin/users/{user}/unban → Ack.
UnlinkUserIdentity
Unlink a login provider from an account: DELETE /v1/admin/users/{user}/identities/{provider} → Ack.
UserListQuery
List accounts: GET /v1/admin/users?q=…&cursor=…&limit=… → Page<AdminUser>, newest first.
WriteUserObject
Write one of a user’s objects: PUT /v1/admin/users/{user}/storage/{collection}/{key} with an AdminPutObject → ObjectAck (audited as admin.storage_write).

Constants§

ADMIN_ROLE
The role that may use the administration routes.
BAN_REASON_MAX_CHARS
The longest ban reason, in characters.
ROLE_MAX_BYTES
The longest role name, in bytes.
USER_SEARCH_MAX_CHARS
The longest search text of a user listing, in characters.

Functions§

is_valid_role
Whether role is a valid role name: 1 to ROLE_MAX_BYTES bytes of [a-z0-9_.-], starting with a letter (admin, moderator, beta.tester).