hivectl, hive-c0re: remove dead matrix create-user/promote-user/reset-password
Human matrix accounts come from SSO, not hivectl. Matrix homeserver admin will come from authelia's admins group (sync tracked in #4585); password reset moves to swarm level (#4798). promote-user and reset-password were already broken from the hive: the hive's sender account has no admin sender to call the admin room with, only the swarm's does. Removes the three hivectl matrix verbs, their HostRequest variants, their hive-c0re handlers, and the admin-room helpers (discover room id, send-and-poll, event-id extraction, password/success parsing) that only they used. sync-admin and invite are unchanged. Refs #4585
This commit is contained in:
parent
69ae23f801
commit
93bbec015f
12 changed files with 37 additions and 748 deletions
|
|
@ -286,47 +286,11 @@ impl From<ReconcileFrom> for hive_host_sock::ReconcileDirection {
|
|||
|
||||
#[derive(Subcommand)]
|
||||
pub enum MatrixCmd {
|
||||
/// Create a matrix account for a person or other non-agent `<name>` and
|
||||
/// print its access token to stdout.
|
||||
///
|
||||
/// Refuses an agent's name: its account comes from the swarm
|
||||
/// (`swarm-controller` creates it and stores its token where the agent
|
||||
/// reads it). Set a password to enable matrix web-client login
|
||||
/// (otherwise it uses a random throwaway).
|
||||
CreateUser {
|
||||
/// Matrix localpart of a non-agent account — `mara`, `damocles`, etc.
|
||||
name: String,
|
||||
/// Set the account password to this string instead of a random
|
||||
/// throwaway. Use this for operator accounts that need to log
|
||||
/// into matrix web clients via `m.login.password`. Mutually
|
||||
/// exclusive with `--password-stdin`. WARNING: the
|
||||
/// password is visible in shell history + process listings;
|
||||
/// prefer `--password-stdin` for anything sensitive.
|
||||
#[arg(long)]
|
||||
password: Option<String>,
|
||||
/// Read the password from stdin (single line, trailing newline
|
||||
/// stripped) instead of an inline flag. Mutually exclusive with
|
||||
/// `--password`.
|
||||
#[arg(long, conflicts_with = "password")]
|
||||
password_stdin: bool,
|
||||
},
|
||||
/// Provision (or re-provision) the matrix appservice's sender account.
|
||||
///
|
||||
/// Runs automatically on startup; run manually to recover a missing
|
||||
/// access token.
|
||||
SyncAdmin,
|
||||
/// Promote a matrix user to homeserver admin.
|
||||
PromoteUser {
|
||||
/// Matrix localpart of the user to promote (for example `argus`).
|
||||
name: String,
|
||||
},
|
||||
/// Reset a matrix user's password via the admin API.
|
||||
///
|
||||
/// Persists the new password so a later `create-user` can re-login.
|
||||
ResetPassword {
|
||||
/// Matrix localpart of the account to reset (for example `argus`).
|
||||
name: String,
|
||||
},
|
||||
/// Invite a matrix user to the hive Space, or a specific room with
|
||||
/// `--room`. Idempotent.
|
||||
Invite {
|
||||
|
|
|
|||
|
|
@ -8,20 +8,12 @@ use std::path::Path;
|
|||
use anyhow::{Context as _, Result, bail};
|
||||
|
||||
use crate::cli::MatrixCmd;
|
||||
use crate::util::resolve_password;
|
||||
|
||||
/// Route a `matrix` subcommand to its handler. Extracted from `main`'s
|
||||
/// dispatch match so the top-level router stays small.
|
||||
pub(crate) async fn run_matrix_cmd(socket: &Path, cmd: MatrixCmd) -> Result<()> {
|
||||
match cmd {
|
||||
MatrixCmd::CreateUser {
|
||||
name,
|
||||
password,
|
||||
password_stdin,
|
||||
} => matrix_create_user(socket, &name, password.as_deref(), password_stdin).await,
|
||||
MatrixCmd::SyncAdmin => matrix_sync_admin(socket).await,
|
||||
MatrixCmd::PromoteUser { name } => matrix_promote_user(socket, &name).await,
|
||||
MatrixCmd::ResetPassword { name } => matrix_reset_password(socket, &name).await,
|
||||
MatrixCmd::Invite { user, room } => matrix_invite(socket, &user, room.as_deref()).await,
|
||||
}
|
||||
}
|
||||
|
|
@ -46,40 +38,10 @@ async fn matrix_request(socket: &Path, req: hive_host_sock::HostRequest) -> Resu
|
|||
Ok(())
|
||||
}
|
||||
|
||||
async fn matrix_create_user(
|
||||
socket: &Path,
|
||||
name: &str,
|
||||
password: Option<&str>,
|
||||
password_stdin: bool,
|
||||
) -> Result<()> {
|
||||
// Resolve the password client-side (an inline flag or a stdin read);
|
||||
// the daemon never touches this process's stdin. The agent-vs-operator
|
||||
// branch + throwaway-password handling now live in the daemon handler.
|
||||
let password = resolve_password(password, password_stdin)?;
|
||||
matrix_request(
|
||||
socket,
|
||||
hive_host_sock::HostRequest::MatrixCreateUser {
|
||||
name: crate::util::parse_ident(name)?,
|
||||
password,
|
||||
},
|
||||
)
|
||||
.await
|
||||
}
|
||||
|
||||
async fn matrix_sync_admin(socket: &Path) -> Result<()> {
|
||||
matrix_request(socket, hive_host_sock::HostRequest::MatrixSyncAdmin).await
|
||||
}
|
||||
|
||||
async fn matrix_promote_user(socket: &Path, name: &str) -> Result<()> {
|
||||
matrix_request(
|
||||
socket,
|
||||
hive_host_sock::HostRequest::MatrixPromoteUser {
|
||||
name: crate::util::parse_ident(name)?,
|
||||
},
|
||||
)
|
||||
.await
|
||||
}
|
||||
|
||||
async fn matrix_invite(socket: &Path, user: &str, room: Option<&str>) -> Result<()> {
|
||||
matrix_request(
|
||||
socket,
|
||||
|
|
@ -90,13 +52,3 @@ async fn matrix_invite(socket: &Path, user: &str, room: Option<&str>) -> Result<
|
|||
)
|
||||
.await
|
||||
}
|
||||
|
||||
async fn matrix_reset_password(socket: &Path, name: &str) -> Result<()> {
|
||||
matrix_request(
|
||||
socket,
|
||||
hive_host_sock::HostRequest::MatrixResetPassword {
|
||||
name: crate::util::parse_ident(name)?,
|
||||
},
|
||||
)
|
||||
.await
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue