Add internal staff IAM: named users, roles, and management permissions.
Some checks are pending
offline / test (push) Waiting to run
Some checks are pending
offline / test (push) Waiting to run
verae-staff-iam (:3028) is the people directory — owner, billing-admin, cs, sales, accounting, operator, viewer — with scrypt passwords, sessions, and an audit log. Admin console login uses it when STAFF_IAM_URL is set and hides tabs the account cannot use. CS/sales/accounting/staff/fleet check permissions such as cs.credit and fleet.operate. Shared staff key remains only as a fallback when IAM is unset.
This commit is contained in:
parent
2740d51446
commit
d299d245e8
41 changed files with 1337 additions and 52 deletions
32
packages/verae-staff-iam/README.md
Normal file
32
packages/verae-staff-iam/README.md
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
# verae-staff-iam
|
||||
|
||||
Named **internal staff** accounts with **roles and permissions**. Source of truth for who may use CS, sales, accounting, the staff plane, the operator console, and the billing admin console.
|
||||
|
||||
**Forgejo:** https://git.georgelambert.org/marchon/verae-staff-iam
|
||||
|
||||
Port **`:3028`**. UI: sign-in, people, roles, audit.
|
||||
|
||||
## Seed lab users
|
||||
|
||||
| Username | Password | Roles |
|
||||
|----------|----------|--------|
|
||||
| `admin` | `admin-dev-key` | owner (all) |
|
||||
| `cs` | `cs-dev-key` | cs |
|
||||
| `sales` | `sales-dev-key` | sales |
|
||||
| `accounting` | `acct-dev-key` | accounting |
|
||||
| `operator` | `fleet-dev-key` | operator |
|
||||
|
||||
Override with `IAM_OWNER_PASSWORD`, `IAM_CS_PASSWORD`, etc. Persist: `STAFF_IAM_PATH`.
|
||||
|
||||
## Wire other doors
|
||||
|
||||
```bash
|
||||
STAFF_IAM_URL=http://127.0.0.1:3028
|
||||
STAFF_AUTH=1 # department HTML still redirects if check fails
|
||||
```
|
||||
|
||||
`GET /check?permission=cs.credit` — cookie or `Authorization: Bearer`. Cookie name remains `staff_session`. Multi-host: `STAFF_COOKIE_DOMAIN`.
|
||||
|
||||
## Roles
|
||||
|
||||
`owner`, `iam-admin`, `billing-admin`, `cs`, `sales`, `accounting`, `operator`, `viewer`. Permissions are listed on `/roles`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue