pub fn ensure_owner_user(conn: &Connection) -> Result<String, String>Expand description
Ensures the vault has exactly one owner row and returns its id.
The owner is whoever can derive the SQLCipher key from the master password.
Before this existed the server represented them with the magic string
"owner", which meant they appeared in no user list, carried no class, and
could not be named in an audit row.
The row is deliberately created with password_hash = NULL. Storing a
hash of the master password here would put an offline oracle for the vault
key back into the database — the exact hole removed from the desktop
unlock_vault. Proof of ownership stays “your password opened the
database”; verify_user_password refuses a NULL hash, so this row can never
be logged into via /api/auth.