|
Some checks are pending
offline / test (push) Waiting to run
CS/sales/accounting/staff list endpoints and sales pricing writes require IAM; fleet service env sets STAFF_AUTH=1. Department tests use a private books file so lab NATS does not leak into them. |
||
|---|---|---|
| .. | ||
| public | ||
| src | ||
| test | ||
| NATS.md | ||
| package.json | ||
| README.md | ||
| SUMMARY.md | ||
verae-staff-iam
Named internal staff accounts with roles and permissions. Source of truth for who may use CS, sales, accounting, the staff plane, the operator console, and the billing admin console.
Forgejo: https://git.georgelambert.org/marchon/verae-staff-iam
Port :3028. UI: sign-in, people, roles, audit.
Seed lab users
| Username | Password | Roles |
|---|---|---|
admin |
admin-dev-key |
owner (all) |
cs |
cs-dev-key |
cs |
sales |
sales-dev-key |
sales |
accounting |
acct-dev-key |
accounting |
operator |
fleet-dev-key |
operator |
Override with IAM_OWNER_PASSWORD, IAM_CS_PASSWORD, etc. Persist: STAFF_IAM_PATH (users, audit, sessions). Login is rate-limited (8 failures / 10 minutes / IP+username). JSON APIs return 401/403; HTML doors 302 to /login.
Wire other doors
STAFF_IAM_URL=http://127.0.0.1:3028
STAFF_AUTH=1 # department HTML still redirects if check fails
GET /check?permission=cs.credit — cookie or Authorization: Bearer. Cookie name remains staff_session. Multi-host: STAFF_COOKIE_DOMAIN.
Roles
owner, iam-admin, billing-admin, cs, sales, accounting, operator, viewer. Permissions are listed on /roles.