hivectl: drop forge create-user; SSO makes a human's forge account
The forge now creates a human's account on their first authelia login, so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser, its handler, provision_user_token, change_user_password and the hive's TOKEN_SCOPES. change_user_password also passed the password as an argument to `forgejo admin user change-password`, so it showed in the container's process list. ensure_user_exists and mint_token stay for the `core` bootstrap, their one caller now. ensure_user_exists loses its password parameter: only the deleted path set one. Refs #3782
This commit is contained in:
parent
113f3fe6e2
commit
ef494af188
10 changed files with 40 additions and 227 deletions
|
|
@ -315,17 +315,6 @@ pub enum HostRequest {
|
|||
#[serde(default)]
|
||||
room: Option<String>,
|
||||
},
|
||||
/// Create or refresh a forge account + API token for `name`. Daemon-side
|
||||
/// equivalent of `hivectl forge create-user`: for a non-agent
|
||||
/// (operator/human) it mints a user and returns the token in
|
||||
/// [`HostResponse::messages`]. An existing agent is refused: its token is
|
||||
/// swarm-controller's to mint. `password` is resolved client-side
|
||||
/// (inline flag or stdin) and only meaningful for non-agent accounts.
|
||||
ForgeCreateUser {
|
||||
name: Ident,
|
||||
#[serde(default)]
|
||||
password: Option<String>,
|
||||
},
|
||||
/// Report the divergence between agent `agent`'s local applied config
|
||||
/// checkout and its forge `agent-configs/<agent>` `main`. The daemon
|
||||
/// fetches forge `main` read-only and returns a human-readable report
|
||||
|
|
|
|||
Loading…
Reference in a new issue