hivectl: drop forge create-user; SSO makes a human's forge account
The forge now creates a human's account on their first authelia login, so the verb has no job left. Deletes it, HostRequest::ForgeCreateUser, its handler, provision_user_token, change_user_password and the hive's TOKEN_SCOPES. change_user_password also passed the password as an argument to `forgejo admin user change-password`, so it showed in the container's process list. ensure_user_exists and mint_token stay for the `core` bootstrap, their one caller now. ensure_user_exists loses its password parameter: only the deleted path set one. Refs #3782
This commit is contained in:
parent
113f3fe6e2
commit
ef494af188
10 changed files with 40 additions and 227 deletions
|
|
@ -30,12 +30,10 @@ use super::Client;
|
|||
/// of its re-mints, and a later sweep of those must never match this one.
|
||||
pub const AGENT_TOKEN_NAME: &str = "swarm-agent";
|
||||
|
||||
/// The scopes an agent token carries. Byte-identical to `hive-c0re`'s
|
||||
/// `forge::users::TOKEN_SCOPES`, so the move from hive to swarm changes
|
||||
/// nothing an agent can do. Narrowing it is a separate decision.
|
||||
///
|
||||
/// ⚠️ Duplicated across the crate boundary until the last `hive-c0re` caller
|
||||
/// of that constant goes. A test here pins the literal.
|
||||
/// The scopes an agent token carries. Byte-identical to the `TOKEN_SCOPES`
|
||||
/// `hive-c0re` minted with, so the move from hive to swarm changes nothing an
|
||||
/// agent can do. Narrowing it is a separate decision. A test here pins the
|
||||
/// literal.
|
||||
pub const AGENT_TOKEN_SCOPES: &str = "read:user,write:user,read:notification,write:notification,write:repository,write:issue,write:organization,write:misc";
|
||||
|
||||
/// How often [`spawn`] re-checks every agent's token.
|
||||
|
|
|
|||
Loading…
Reference in a new issue