hivectl: drop forge create-user; SSO makes a human's forge account
The forge now creates a human's account on their first authelia login, so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser, its handler, provision_user_token, change_user_password and the hive's TOKEN_SCOPES. change_user_password also passed the password as an argument to `forgejo admin user change-password`, so it showed in the container's process list. ensure_user_exists and mint_token stay for the `core` bootstrap, their one caller now. ensure_user_exists loses its password parameter: only the deleted path set one. Refs #3782
This commit is contained in:
parent
113f3fe6e2
commit
ef494af188
10 changed files with 40 additions and 227 deletions
|
|
@ -233,9 +233,6 @@ async fn dispatch(req: &HostRequest, coord: Arc<Coordinator>) -> HostResponse {
|
|||
HostRequest::MatrixInvite { user, room } => {
|
||||
handle_matrix_invite(user, room.as_deref()).await?
|
||||
}
|
||||
HostRequest::ForgeCreateUser { name, password } => {
|
||||
handle_forge_create_user(name, password.as_deref()).await?
|
||||
}
|
||||
HostRequest::ReconcileConfigStatus { agent, verbose } => {
|
||||
crate::forge::reconcile_config_status(agent.as_str(), *verbose).await?
|
||||
}
|
||||
|
|
@ -591,43 +588,6 @@ async fn handle_matrix_create_user(
|
|||
Ok(HostResponse::messages(out))
|
||||
}
|
||||
|
||||
async fn handle_forge_create_user(
|
||||
name: &hive_types::Ident,
|
||||
password: Option<&str>,
|
||||
) -> Result<HostResponse> {
|
||||
if !crate::forge::is_present().await {
|
||||
anyhow::bail!(
|
||||
"hive-forge container not running — wait for hive-c0re to start it before provisioning forge users"
|
||||
);
|
||||
}
|
||||
if agent_exists(name)? {
|
||||
// An agent's forge user and token are swarm-controller's: it mints
|
||||
// the token into the swarm secret store and the agent fetches it
|
||||
// from there. A hive-minted token would be one the swarm neither
|
||||
// tracks nor rotates.
|
||||
anyhow::bail!(
|
||||
"forge create-user: '{name}' is an agent; its forge token is minted by \
|
||||
swarm-controller — run `swarmctl agent mint-forge-token {name}` on the \
|
||||
controller host"
|
||||
);
|
||||
}
|
||||
let token = crate::forge::provision_user_token(name.as_str(), password)
|
||||
.await
|
||||
.with_context(|| format!("forge create-user {name}"))?;
|
||||
let mut out = vec![
|
||||
format!("forge: provisioned user '{name}' (not an agent — token not persisted)"),
|
||||
format!("token: {token}"),
|
||||
];
|
||||
if password.is_some() {
|
||||
out.push("password: set as supplied — use it to log into the forge web UI".to_owned());
|
||||
} else {
|
||||
out.push(
|
||||
"password: random throwaway (not surfaced — pass --password or --password-stdin to set one you can use)".to_owned(),
|
||||
);
|
||||
}
|
||||
Ok(HostResponse::messages(out))
|
||||
}
|
||||
|
||||
async fn handle_set_agent_github_token(agent: &str, token: &str) -> Result<HostResponse> {
|
||||
crate::priv_client::write_agent_github_token(agent, token)
|
||||
.await
|
||||
|
|
|
|||
Loading…
Reference in a new issue