No admin by username, no Swagger in production, no exception text to clients
S14 and the privacy items of P0: - signing up as "admin" no longer grants admin; `PrivaPub admin promote <root>` (and `demote`) does, run on the box against the configured database; - Swagger is served in Development only; - every service and controller answers "Something went wrong." where it used to send ex.Message, and the SMTP warnings no longer log the recipient's address; - sign-up and login no longer log the IP, User-Agent and root id together; - invitation sign-up takes the persona's own AvatarUserName (and optional AvatarName) instead of naming the avatar after the private login, and refuses a persona username equal to the login's. Invitation login uses the named persona, creating it if it is new; - recovery mail comes from "PrivaPub", not collAnon's support address name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
2eb2a63f1e
commit
0f85030744
11 files changed
+144
-76
No files matched your search
@@ -0,0 +1,40 @@
|
||||
using MongoDB.Entities;
|
||||
|
||||
using PrivaPub.ClientModels;
|
||||
using PrivaPub.Models.User;
|
||||
|
||||
namespace PrivaPub.Infrastructure.Cli
|
||||
{
|
||||
public static class AdminCommands
|
||||
{
|
||||
const string Usage = "usage: PrivaPub admin promote|demote <root username>";
|
||||
|
||||
public static async Task<int> Run(string[] args)
|
||||
{
|
||||
if (args is not [("promote" or "demote") and var verb, var userName])
|
||||
{
|
||||
Console.Error.WriteLine(Usage);
|
||||
return 2;
|
||||
}
|
||||
|
||||
userName = userName.ToLowerInvariant();
|
||||
var user = await DB.Default.Find<RootUser>().Match(u => u.UserName == userName).ExecuteFirstAsync();
|
||||
if (user == default)
|
||||
{
|
||||
Console.Error.WriteLine($"no root user '{userName}'");
|
||||
return 1;
|
||||
}
|
||||
|
||||
user.Policies.RemoveAll(p => p is Policies.IsAdmin or Policies.IsModerator);
|
||||
if (verb == "promote")
|
||||
user.Policies.AddRange(new[] { Policies.IsAdmin, Policies.IsModerator });
|
||||
if (!user.Policies.Contains(Policies.IsUser))
|
||||
user.Policies.Add(Policies.IsUser);
|
||||
user.UpdatedAt = DateTime.UtcNow;
|
||||
await DB.Default.SaveAsync(user);
|
||||
|
||||
Console.WriteLine($"{userName}: {string.Join(", ", user.Policies)}");
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user