mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 15:09:42 +02:00
feat(multiuser): phase 5a, admin user-management API
- routes/admin-routes.ts: GET/POST /api/admin/users, PATCH/DELETE /api/admin/users/:username, reset-password, logout. Multi-user only (404 otherwise), requireAdmin, last-admin invariants, one-time-password on create / reset (returned once + mustChangePassword), disable/reset/delete revoke cookie sessions, delete kills the user's live sessions first (normal teardown) and can delete their space (guarded). Per-user stats (live/active sessions, case count). - web/admin-audit.ts: append-only ~/.codeman/admin-audit.jsonl (timestamp, acting admin, action, target, IP) for every user-management action. - SSE admin:usersChanged + auth:passwordChangeRequired (sse-events.ts + constants.js). fix(user-store): serialize users.json read-modify-write touchLastLogin fires on every Basic auth (fire-and-forget) and was racing route writes (create/update), clobbering records — a real corruption bug surfaced by the admin tests. All mutators now run under a single write lock, and touchLastLogin is throttled to once/minute per user to bound disk churn. Tests: test/admin-routes.test.ts (8, live server) + user-store lock verified by the existing user-store suite. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -481,6 +481,9 @@ const SSE_EVENTS = {
|
||||
DOCKER_IMAGE_BUILD_PROGRESS: 'docker:imageBuildProgress',
|
||||
DOCKER_IMAGE_BUILD_COMPLETE: 'docker:imageBuildComplete',
|
||||
DOCKER_IMAGE_BUILD_FAILED: 'docker:imageBuildFailed',
|
||||
// Multi-user (admin-only / targeted)
|
||||
ADMIN_USERS_CHANGED: 'admin:usersChanged',
|
||||
AUTH_PASSWORD_CHANGE_REQUIRED: 'auth:passwordChangeRequired',
|
||||
};
|
||||
|
||||
// ═══════════════════════════════════════════════════════════════
|
||||
|
||||
Reference in New Issue
Block a user