hivectl: drop forge create-user; SSO makes a human's forge account
The forge now creates a human's account on their first authelia login, so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser, its handler, provision_user_token, change_user_password and the hive's TOKEN_SCOPES. change_user_password also passed the password as an argument to `forgejo admin user change-password`, so it showed in the container's process list. ensure_user_exists and mint_token stay for the `core` bootstrap, their one caller now. ensure_user_exists loses its password parameter: only the deleted path set one. Refs #3782
This commit is contained in:
parent
113f3fe6e2
commit
ef494af188
10 changed files with 40 additions and 227 deletions
|
|
@ -1,6 +1,5 @@
|
|||
//! `hivectl forge create-user <name>` — provision a Forgejo account via the
|
||||
//! daemon (which owns the forge admin token);
|
||||
//! hivectl just resolves the password client-side and relays the request.
|
||||
//! `hivectl forge reconcile-config <agent>` — show and reconcile an
|
||||
//! agent's config divergence via the daemon.
|
||||
|
||||
use std::io::{self, Write};
|
||||
use std::path::Path;
|
||||
|
|
@ -9,29 +8,7 @@ use anyhow::Result;
|
|||
use hive_host_sock::{HostRequest, ReconcileDirection};
|
||||
|
||||
use crate::cli::ReconcileFrom;
|
||||
use crate::util::{daemon_request, resolve_password};
|
||||
|
||||
pub(crate) async fn forge_create_user(
|
||||
socket: &Path,
|
||||
name: &str,
|
||||
password: Option<&str>,
|
||||
password_stdin: bool,
|
||||
) -> Result<()> {
|
||||
// Resolve the password client-side (inline flag or stdin read); the
|
||||
// daemon never touches this process's stdin. The is-present check, the
|
||||
// agent-vs-operator branch, and token persistence now live in the
|
||||
// daemon handler.
|
||||
let password = resolve_password(password, password_stdin)?;
|
||||
daemon_request(
|
||||
socket,
|
||||
hive_host_sock::HostRequest::ForgeCreateUser {
|
||||
name: crate::util::parse_ident(name)?,
|
||||
password,
|
||||
},
|
||||
"forge",
|
||||
)
|
||||
.await
|
||||
}
|
||||
use crate::util::daemon_request;
|
||||
|
||||
/// `hivectl forge reconcile-config <agent> [--from <forge|local>] [--verbose]`.
|
||||
/// Always shows the divergence first (daemon computes it read-only), then
|
||||
|
|
|
|||
Loading…
Reference in a new issue