cubes: user:add gets optional PUBKEY, space-separated GROUPS, exists guard
PUBKEY defaults to empty now — empty means no key is authorised, and some users need none. GROUPS was always split on whitespace by deploy.py, so the comma-separated prompt label and README were documenting a bug; both now say space-separated. The deploy script checks the Users fact up front and noops when the user exists, since rerunning reset the password and overwrote ~/.config/fish. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ce5atB2tXDXyz2jd9s1bqE
This commit is contained in:
co-authored by
Claude Fable 5
parent
f1cc9effa0
commit
643d7379ba
@@ -17,12 +17,14 @@ export default Manifest({
|
||||
PASSWORD: z.string().describe('Password for the new user account').default('changeme'),
|
||||
GROUPS: z
|
||||
.string()
|
||||
.describe('Comma-separated list of additional groups (e.g., "docker,sudo")')
|
||||
.describe('Space-separated list of additional groups (e.g., "docker sudo")')
|
||||
.default(''),
|
||||
// Empty by default, never a specific key: this used to carry a personal
|
||||
// key, which meant an unattended run authorised someone else's key on the
|
||||
// new account. Empty means no key is authorised — some users need none.
|
||||
PUBKEY: z
|
||||
.string()
|
||||
.describe('SSH public key to authorize for the user (empty for none)')
|
||||
.default(''),
|
||||
// No default on purpose. This used to carry a specific personal key, which
|
||||
// meant an unattended run authorised someone else's key on the new account.
|
||||
// Leaving it required makes `--use-defaults` refuse by name instead of
|
||||
// guessing, and there is no key that would be a sensible guess.
|
||||
PUBKEY: z.string().describe('SSH public key to authorize for the user'),
|
||||
}),
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user