hivectl, hive-c0re: remove dead matrix create-user/promote-user/reset-password
Human matrix accounts come from SSO, not hivectl. Matrix homeserver admin will come from authelia's admins group (sync tracked in #4585); password reset moves to swarm level (#4798). promote-user and reset-password were already broken from the hive: the hive's sender account has no admin sender to call the admin room with, only the swarm's does. Removes the three hivectl matrix verbs, their HostRequest variants, their hive-c0re handlers, and the admin-room helpers (discover room id, send-and-poll, event-id extraction, password/success parsing) that only they used. sync-admin and invite are unchanged. Refs #4585
This commit is contained in:
parent
69ae23f801
commit
93bbec015f
12 changed files with 37 additions and 748 deletions
|
|
@ -220,16 +220,7 @@ async fn dispatch(req: &HostRequest, coord: Arc<Coordinator>) -> HostResponse {
|
|||
)
|
||||
.await?
|
||||
}
|
||||
HostRequest::MatrixCreateUser { name, password } => {
|
||||
handle_matrix_create_user(name, password.as_deref()).await?
|
||||
}
|
||||
HostRequest::MatrixSyncAdmin => handle_matrix_sync_admin().await?,
|
||||
HostRequest::MatrixPromoteUser { name } => {
|
||||
handle_matrix_promote_user(name.as_str()).await?
|
||||
}
|
||||
HostRequest::MatrixResetPassword { name } => {
|
||||
handle_matrix_reset_password(name.as_str()).await?
|
||||
}
|
||||
HostRequest::MatrixInvite { user, room } => {
|
||||
handle_matrix_invite(user, room.as_deref()).await?
|
||||
}
|
||||
|
|
@ -536,46 +527,6 @@ fn require_matrix_present() -> Result<()> {
|
|||
)
|
||||
}
|
||||
|
||||
async fn handle_matrix_create_user(
|
||||
name: &hive_types::Ident,
|
||||
password: Option<&str>,
|
||||
) -> Result<HostResponse> {
|
||||
require_matrix_present()?;
|
||||
if agent_exists(name)? {
|
||||
// The swarm mints an agent's account and stores its token where the
|
||||
// agent reads it; a second minter here would replace that token on the
|
||||
// same device.
|
||||
anyhow::bail!(
|
||||
"matrix create-user: '{name}' is an agent, and an agent's matrix account comes from \
|
||||
the swarm: swarm-controller creates it and re-checks it every five minutes"
|
||||
);
|
||||
}
|
||||
let as_token =
|
||||
crate::matrix::read_appservice_token().context("read matrix appservice token")?;
|
||||
let client = matrix_http_client()?;
|
||||
let mut out = Vec::new();
|
||||
let effective_password = match password {
|
||||
Some(p) => p.to_owned(),
|
||||
None => crate::matrix::random_password().context("generate random matrix password")?,
|
||||
};
|
||||
let token =
|
||||
crate::matrix::provision_user_token(&client, name.as_str(), &as_token, &effective_password)
|
||||
.await
|
||||
.with_context(|| format!("matrix create-user {name}"))?;
|
||||
out.push(format!(
|
||||
"matrix: provisioned user '{name}' (not an agent — token not persisted)"
|
||||
));
|
||||
out.push(format!("token: {token}"));
|
||||
if password.is_some() {
|
||||
out.push("password: set as supplied — use it to log into a matrix web client".to_owned());
|
||||
} else {
|
||||
out.push(
|
||||
"password: random throwaway (not surfaced — pass --password or --password-stdin to set one you can use)".to_owned(),
|
||||
);
|
||||
}
|
||||
Ok(HostResponse::messages(out))
|
||||
}
|
||||
|
||||
async fn handle_set_agent_github_token(agent: &str, token: &str) -> Result<HostResponse> {
|
||||
crate::priv_client::write_agent_github_token(agent, token)
|
||||
.await
|
||||
|
|
@ -712,21 +663,6 @@ async fn handle_matrix_sync_admin() -> Result<HostResponse> {
|
|||
]))
|
||||
}
|
||||
|
||||
async fn handle_matrix_promote_user(name: &str) -> Result<HostResponse> {
|
||||
require_matrix_present()?;
|
||||
let sender_token = crate::matrix::read_sender_token()?;
|
||||
let client = matrix_http_client()?;
|
||||
let server_name = crate::matrix::discover_server_name(&client)
|
||||
.await
|
||||
.context("discover matrix server_name")?;
|
||||
crate::matrix::promote_user_to_admin(&client, &sender_token, name, &server_name)
|
||||
.await
|
||||
.with_context(|| format!("matrix promote-user {name}"))?;
|
||||
Ok(HostResponse::messages(vec![format!(
|
||||
"matrix: promoted @{name}:{server_name} to admin"
|
||||
)]))
|
||||
}
|
||||
|
||||
async fn handle_matrix_invite(user: &str, room: Option<&str>) -> Result<HostResponse> {
|
||||
require_matrix_present()?;
|
||||
let sender_token = crate::matrix::read_sender_token()?;
|
||||
|
|
@ -747,24 +683,6 @@ async fn handle_matrix_invite(user: &str, room: Option<&str>) -> Result<HostResp
|
|||
)]))
|
||||
}
|
||||
|
||||
async fn handle_matrix_reset_password(name: &str) -> Result<HostResponse> {
|
||||
require_matrix_present()?;
|
||||
let sender_token = crate::matrix::read_sender_token()?;
|
||||
let client = matrix_http_client()?;
|
||||
let server_name = crate::matrix::discover_server_name(&client)
|
||||
.await
|
||||
.context("discover matrix server_name")?;
|
||||
crate::matrix::reset_user_password(&client, &sender_token, name, &server_name)
|
||||
.await
|
||||
.with_context(|| format!("matrix reset-password {name}"))?;
|
||||
// Password is persisted by reset_user_password.
|
||||
let pw_path = crate::paths::matrix_creds_dir().join(format!("{name}-password"));
|
||||
Ok(HostResponse::messages(vec![
|
||||
format!("matrix: password for @{name}:{server_name} reset"),
|
||||
format!("password persisted at: {}", pw_path.display()),
|
||||
]))
|
||||
}
|
||||
|
||||
/// Single-agent queue verbs the admin socket exposes. Each submits the
|
||||
/// matching DAG (persisting the `wanted` intent, serializing on the
|
||||
/// agent's lease, with the transient/crash-watch suppression the old
|
||||
|
|
|
|||
Loading…
Reference in a new issue