Expand description
User management, token management, and RBAC for UnENVerse.
Users are stored in the SQLCipher-encrypted vault database — they can only be read or created when the owner has unlocked the vault (i.e. the vault key is in memory). The owner is the only party who can manage users.
§Auth modes
- Username + password: stored as
SHA-256(salt || password)with a 16-byte random salt. - Token: 32 random bytes returned as a 64-char hex string once; stored as
SHA-256(token).
§Permission model
Each permission has:
scope_type:"vault"|"project"|"category"scope_value:"*", or a glob like"wg0-*"/"Cloud/AWS"permission:"read"|"write"(write implies read)
Glob rules: * matches any sequence of characters (including empty); ? matches one char.
Structs§
- Class
Permission - A single permission row scoped to a user class (no user_id — applies to all class members).
- Permission
Record - A single RBAC permission row.
- Token
Record - A stored API token descriptor. The actual token is returned only on creation.
- Totp
Status - What the UI and CLI need to draw a user’s second-factor state.
- User
Class - A named user class (role template) with capabilities and permissions.
- User
Record - A vault user (password hash is never exposed via this struct).
Enums§
- Admin
Seed - Outcome of
seed_default_admin.
Functions§
- assign_
user_ class - authority_
tier - Derives an authority tier from capability flags. Higher acts on strictly lower.
- class_
authority_ tier - Authority tier implied by a class’s stored capabilities. Returns 0 if unknown.
- create_
user - Creates a new user. Pass
password = Nonefor token-only auth. - create_
user_ class - create_
user_ token - Creates a token for
user_id. Returns(token_id, plaintext_token)— the plaintext is shown once. - delete_
user - Deletes a user plus all their tokens and permissions.
Returns
Errifuser_idbelongs to the owner account. - delete_
user_ class - effective_
permission_ expr - Resolves what a user may actually do, combining their class and individual rules.
- ensure_
owner_ user - Ensures the vault has exactly one owner row and returns its id.
- filter_
vault_ for_ user - Returns a filtered copy of
vaultcontaining only entries readable underread. Also trims theprojectsanduser_categorieslists to what the visible entries actually reference, so the taxonomy itself does not leak. - get_
class_ permissions - get_
permission_ expr - Reads a stored expression for a subject, if any.
- get_
user_ capabilities - Returns the capabilities of the user’s class (None values mean no class = no extra capabilities).
- get_
user_ permissions - Returns all permissions for a user.
- glob_
matches - Standard wildcard matching:
*= any sequence,?= one char. - init_
users_ schema - Creates all user-related tables (idempotent) and seeds default classes.
- list_
user_ classes - list_
user_ tokens - Lists all tokens for a user (no hashes).
- list_
users - Lists all users, owners first, then by creation date.
- merge_
user_ vault_ write - Merges a user’s submitted vault data into the full vault, respecting write permissions.
- rename_
user - Renames a user (owner or non-owner). Fails if
new_usernameis already taken. - revoke_
user_ token - Revokes a token by its UUID.
- seed_
default_ admin - Idempotently seeds a default
adminuser assigned to the built-incls-adminclass. Never hardcodes a credential: usesenv_passwordwhen present, otherwise generates a 128-bit random password the caller is responsible for displaying once. - set_
class_ permissions - set_
permission_ expr - Stores an expression, or clears it when
expressionis empty/blank. - set_
strict_ write - Turn strict write scoping on or off for a user or a class.
- set_
user_ password - Updates (or clears) a user’s password.
- set_
user_ permissions - Atomically replaces all permissions for a user.
- strict_
write_ for - Whether writes for this user must satisfy every scope rather than any.
- token_
user_ id - Returns the owning user id of a token, or
Noneif the token id is unknown. - totp_
confirm - Phase two: enables the factor once the user proves their authenticator works.
- totp_
disable - Removes the factor entirely, secret included.
- totp_
enroll - Phase one of enrollment: mints a secret and returns it with its URI.
- totp_
required - Whether login for this user must present a code.
- totp_
status - Reports enrollment and enabled state. Never returns the secret — see
TotpStatus::secret. - update_
user_ class - user_
authority_ tier - Authority tier of a stored user (by their class capabilities, or the
is_ownerflag). Returns 0 for an unknown user id. - verify_
user_ password - Verifies username + password. Returns
Noneon invalid credentials. - verify_
user_ token - Verifies a raw 64-char hex token. Returns
Noneif invalid or expired. - verify_
user_ totp - Verifies a login code and advances the anti-replay high-water mark.