swarmctl: add user reset-password
authelia's file backend has no self-service reset (no SMTP notifier), so the only way a human account got a new password after the old one was forgotten was hand-editing users.yml as root. `user add` already hashes a password into the file; this verb does the same for an existing user instead of refusing on the name. Mirrors `user add`'s UX exactly: no password flag, authelia generates and hashes it (never crosses argv), and it's printed once and never stored. Refuses on an unknown user before ever invoking authelia. Same publish path as add/update, so the same atomic write and no-restart (authelia watches the file) behaviour apply. Split the digest-replacement into users::reset_password so it's testable without a command line or a running authelia, same pattern as apply_update.
This commit is contained in:
parent
ccb5bd3b38
commit
69ae23f801
4 changed files with 151 additions and 1 deletions
|
|
@ -11,6 +11,7 @@ This document contains the help content for the `swarmctl` command-line program.
|
|||
* [`swarmctl agent mint-forge-token`↴](#swarmctl-agent-mint-forge-token)
|
||||
* [`swarmctl user`↴](#swarmctl-user)
|
||||
* [`swarmctl user add`↴](#swarmctl-user-add)
|
||||
* [`swarmctl user reset-password`↴](#swarmctl-user-reset-password)
|
||||
* [`swarmctl user update`↴](#swarmctl-user-update)
|
||||
* [`swarmctl user list`↴](#swarmctl-user-list)
|
||||
* [`swarmctl forge`↴](#swarmctl-forge)
|
||||
|
|
@ -137,6 +138,7 @@ Manage subjects in the swarm's SSO provider
|
|||
###### **Subcommands:**
|
||||
|
||||
* `add` — Add a user, generating a password for them
|
||||
* `reset-password` — Set a new password for an existing user, generating it the same way `user add` does
|
||||
* `update` — Change an existing user's attributes
|
||||
* `list` — List every user in authelia's users database
|
||||
|
||||
|
|
@ -160,6 +162,20 @@ Add a user, generating a password for them
|
|||
|
||||
|
||||
|
||||
## `swarmctl user reset-password`
|
||||
|
||||
Set a new password for an existing user, generating it the same way `user add` does.
|
||||
|
||||
authelia's file store has no self-service reset (no SMTP notifier), so this is the only way a human account gets a new password once an operator forgets the old one. Refuses if the user doesn't exist — there's no separate "create" path here.
|
||||
|
||||
**Usage:** `swarmctl user reset-password <USERNAME>`
|
||||
|
||||
###### **Arguments:**
|
||||
|
||||
* `<USERNAME>` — Login name of an existing user
|
||||
|
||||
|
||||
|
||||
## `swarmctl user update`
|
||||
|
||||
Change an existing user's attributes.
|
||||
|
|
|
|||
Loading…
Reference in a new issue