UnENVerse 0.42.6
Local-first desktop secrets manager — TypeScript frontend
Loading...
Searching...
No Matches
users.ts File Reference
import type;

Functions

function async invoke< T=unknown > (cmd:string, args:Record< string, unknown >={},)
 User/class management dispatcher.
 
function strictToggleHtml (kind:'user'| 'class', on:boolean)
 Strict write scoping (unv user strict-write, Phase 33.4): under it a write must satisfy every scope the subject has, not any one.
 
function wireStrictToggle (kind:'user'| 'class', id:string, reload:()=> Promise< void >|void,)
 
function totpSectionHtml (totp:TotpState)
 The section body for a user's second factor.
 
function async changePassword (userId:string)
 
function async deleteUser (userId:string)
 
function async newToken (userId:string)
 
function showTokenCreatedOverlay (token:string)
 
function async revokeToken (tokenId:string, userId:string)
 
function export openCreateUserForm ()
 
function async renderClassesPanel ()
 
function async renderClassDetail (classId:string)
 
function async saveClassDetails (classId:string)
 
function async deleteClass (classId:string)
 
function openCreateClassForm ()
 
function export resetUsersPanelState ()
 Forgets which user/class was open.
 

Variables

const localInvoke
 
enabled __pad0__
 
let _activeClassId
 
let _activeSubPanel
 
let _usersPanelInited = false
 

Function Documentation

◆ invoke< T=unknown >()

function async invoke< T=unknown > (   cmd:string,
  args:Record< string, unknown > = {} 
)

User/class management dispatcher.

On a remote vault the local SQLCipher DB is locked, so route each command to the server's owner-only REST endpoints; on a local vault, fall through to the Tauri command. Keeps every call site unchanged.

◆ strictToggleHtml()

function strictToggleHtml (   kind:'user'| 'class',
  on:boolean 
)

Strict write scoping (unv user strict-write, Phase 33.4): under it a write must satisfy every scope the subject has, not any one.

Shown as a checkbox in the user and class detail. Owner-only on the server, as turning it off widens what a sub-user can write.

◆ wireStrictToggle()

function wireStrictToggle (   kind:'user'| 'class',
  id:string,
  reload:(),
  Promise< void >| void 
)

◆ totpSectionHtml()

function totpSectionHtml (   totp:TotpState)

The section body for a user's second factor.

Three states, and the middle one is the reason enrollment is two-phase: a secret exists but was never confirmed, so the account is not protected and must not look as though it is. Binds the section's buttons.

Assignment, not addEventListener: renderUserDetail rewrites this markup on every visit and after every action, and the enrollment panel is shown, hidden and shown again within one render — invariant 9. Phase one: mint a secret and show it for manual entry.

There is no QR code. Drawing one needs a library, and the CSP allows no external script — relaxing it so that a secret can be rendered would be an odd trade. Every authenticator accepts manual entry, so the secret is shown in groups of four, which is the difference between typing 32 characters right and typing them wrong. Base32 in groups of four, matching vault_core::totp::grouped.

◆ changePassword()

function async changePassword (   userId:string)

◆ deleteUser()

function async deleteUser (   userId:string)

◆ newToken()

function async newToken (   userId:string)

◆ showTokenCreatedOverlay()

function showTokenCreatedOverlay (   token:string)

◆ revokeToken()

function async revokeToken (   tokenId:string,
  userId:string 
)

◆ openCreateUserForm()

function export openCreateUserForm ( )

◆ renderClassesPanel()

function async renderClassesPanel ( )

◆ renderClassDetail()

function async renderClassDetail (   classId:string)

◆ saveClassDetails()

function async saveClassDetails (   classId:string)

◆ deleteClass()

function async deleteClass (   classId:string)

◆ openCreateClassForm()

function openCreateClassForm ( )

◆ resetUsersPanelState()

function export resetUsersPanelState ( )

Forgets which user/class was open.

User and class ids are scoped to one vault, so carrying a selection from one server to the next made the panel highlight — and try to load — an id that belongs to a different vault entirely. Call whenever the backing vault changes.

Variable Documentation

◆ localInvoke

const localInvoke
Initial value:
= <T>(cmd: string, args?: Record<string, unknown>) =>
isTauri() ? invokeTauri<T>(cmd, args) : undefined
const string
Definition auth-panel.ts:37

◆ __pad0__

enabled __pad0__

◆ _activeClassId

let _activeClassId

◆ _activeSubPanel

let _activeSubPanel

◆ _usersPanelInited

let _usersPanelInited = false