Codeman maintainer
|
f496e35d71
|
feat(multiuser): phase 1, user store, mode plumbing, CLI
Opt-in multi-user foundation (off by default; no behavior change without
CODEMAN_MULTIUSER/--multiuser):
- src/config/multiuser.ts: isMultiUserMode(), getUserSpacesDir()/userCasesDir(),
maxUsers(), maxSessionsPerUser() (per-user fairness cap = global/2).
- src/types/user.ts: UserRecord/PasswordHash/AuthUser/PublicUser/UserRole.
- src/user-store.ts: ~/.codeman/users.json (atomic tmp+rename, mode 0600, short
TTL cache). scrypt hashing with per-record params + timingSafeEqual verify plus
rehash detection; createUser/setPassword/updateUser/deleteUser with last-admin
invariants; guarded deleteUserSpace (symlink + realpath confinement, section 8);
pure section-6.3 resolvers (resolveClaudeModeForUser downgrades bypass to auto
for non-granted users; canRunPrivilegedCommands); bootstrapInitialAdmin.
- src/cli.ts: "codeman users add|passwd|list|rm" (hidden prompt or
--password-stdin) operating directly on users.json; a --multiuser flag on the
web command.
Tests: test/user-store.test.ts (29 tests: hashing/verify/rehash, username
validation, atomic 0600 write, last-admin invariants, 6.3 resolvers,
delete-space guards, bootstrap).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
2026-07-20 02:58:51 +02:00 |
|