feat(api): invite friends and manage accounts #9
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/invitations"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Backend of 0.3 "accounts for friends" (the web part comes in a second PR).
What changes
0007_invitations:invitations(kindinvite/reset, SHA-256 of the token only,expires_at,used_at) andtorrents.added_by(ON DELETE SET NULL, not exposed).require_adminon/api/admin/*and/api/indexers*→403 {"error":"admins only"}. Users keep everything on downloads.POST/GET /api/admin/invitations,DELETE /api/admin/invitations/{id},GET /api/admin/users,DELETE /api/admin/users/{id}(not oneself, never the last admin:409),POST /api/admin/users/{id}/reset.GET/POST /api/invitations/{token}. Same404for unknown/used/expired links, own per-address limiter (5 in 15 min →429), failed-login delay. An invite creates auserand logs in; a reset sets the password, closes all sessions, opens a new one. Links are single use (7 days / 24 h; a new reset link replaces the older ones).POST /api/auth/password{current, new}→204, other sessions closed; a wrongcurrentis403and counts as a failed login.-,_,., unique whatever the case (400/409). New passwords ≥ 10 characters (CLI too).httpspan gets auserfield once the session is checked, sodownload added/updated/removedcarry who did it. Invitation tokens are replaced by…in the logged URI.admin/folder.Tests
142 tests (13 new): admin vs user access, invite lifecycle (reuse/expired/revoked), validation and case-insensitive uniqueness, reset lifecycle, delete rules, password change, rate limiting,
added_by, username in logs.🤖 Generated with Claude Code
Accounts for friends (0.3), backend part: - Migration 0007: invitations (invite and reset links, only the SHA-256 of their token stored) and torrents.added_by. - require_admin on /api/admin/* and /api/indexers*: 403 for users. - Admin: create, list and revoke invitations; list and delete users (not oneself, never the last admin); password reset links. - Public GET/POST /api/invitations/{token}: same 404 for unknown, used or expired links, per-address limiter and failed-login delay, tokens kept out of the request logs. Using a link logs in. - POST /api/auth/password closes the other sessions. - Usernames: 1 to 32 ASCII letters, digits, '-', '_', '.'; new passwords at least 10 characters. - The request span carries the username, so download changes are logged with who made them; added_by is stored on add. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01947SGTYxD1CJLsk2PcULRA