mirror of
https://github.com/go-gitea/gitea.git
synced 2026-09-19 10:49:30 +00:00
3bec08f998
Adds first-class bot accounts (`UserTypeBot`): local, password-less
users for automation that authenticate only with access tokens.
1. Admin UI: create bots, filter users by type, manage a bot's access
tokens, convert between user and bot
2. API: `POST /admin/users/{username}/convert-type`, and user objects
gain a GitHub-compatible `type` (`User`, `Organization`, `Bot`)
3. CLI: `gitea admin user change-type`, `--user-type` accepts `User` or
`Bot` case-insensitively
4. Converting keeps the password, 2FA, OAuth2 grants and access tokens,
and since sign-in rejects bots, converting back restores the account.
Only local, non-admin accounts can be converted, and conversions are
audited
5. Session, reverse proxy, SSPI, external source and password reset
sign-in reject non-individual users, so a bot never gets an interactive
session
6. Bots receive no notifications or emails
Co-authored-by: Nicolas <bircni@icloud.com>
Co-authored-by: joestump <joe@joestump.net>
Co-authored-by: Joe Stump <joe@stu.mp>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
89 lines
3.6 KiB
Go
89 lines
3.6 KiB
Go
// Copyright 2015 The Gogs Authors. All rights reserved.
|
|
// Copyright 2019 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package structs
|
|
|
|
import "time"
|
|
|
|
// CreateUserOption create user options
|
|
type CreateUserOption struct {
|
|
// The authentication source ID to associate with the user
|
|
SourceID int64 `json:"source_id"`
|
|
// identifier of the user, provided by the external authenticator (if configured)
|
|
LoginName string `json:"login_name"`
|
|
// username of the user
|
|
// required: true
|
|
Username string `json:"username" binding:"Required;Username;MaxSize(40)"`
|
|
// The full display name of the user
|
|
FullName string `json:"full_name" binding:"MaxSize(100)"`
|
|
// required: true
|
|
Email string `json:"email" binding:"Required;Email;MaxSize(254)"`
|
|
// The plain text password for the user
|
|
Password string `json:"password" binding:"MaxSize(255)"`
|
|
// Whether the user must change password on first login
|
|
MustChangePassword *bool `json:"must_change_password"`
|
|
// Whether to send welcome notification email to the user
|
|
SendNotify bool `json:"send_notify"`
|
|
// Whether the user has restricted access privileges
|
|
Restricted *bool `json:"restricted"`
|
|
// User visibility level: public, limited, or private
|
|
Visibility VisibilityString `json:"visibility" binding:"In(,public,limited,private)"`
|
|
|
|
// For explicitly setting the user creation timestamp. Useful when users are
|
|
// migrated from other systems. When omitted, the user's creation timestamp
|
|
// will be set to "now".
|
|
Created *time.Time `json:"created_at"`
|
|
}
|
|
|
|
// EditUserOption edit user options
|
|
type EditUserOption struct {
|
|
// required: true
|
|
// The authentication source ID to associate with the user
|
|
SourceID int64 `json:"source_id"`
|
|
// identifier of the user, provided by the external authenticator (if configured)
|
|
LoginName *string `json:"login_name"`
|
|
// swagger:strfmt email
|
|
// The email address of the user
|
|
Email *string `json:"email" binding:"MaxSize(254)"`
|
|
// The full display name of the user
|
|
FullName *string `json:"full_name" binding:"MaxSize(100)"`
|
|
// The plain text password for the user
|
|
Password string `json:"password" binding:"MaxSize(255)"`
|
|
// Whether the user must change password on next login
|
|
MustChangePassword *bool `json:"must_change_password"`
|
|
// The user's personal website URL
|
|
Website *string `json:"website" binding:"OmitEmpty;ValidUrl;MaxSize(255)"`
|
|
// The user's location or address
|
|
Location *string `json:"location" binding:"MaxSize(50)"`
|
|
// The user's personal description or bio
|
|
Description *string `json:"description" binding:"MaxSize(255)"`
|
|
// Whether the user account is active
|
|
Active *bool `json:"active"`
|
|
// Whether the user has administrator privileges
|
|
Admin *bool `json:"admin"`
|
|
// Whether the user can use Git hooks
|
|
AllowGitHook *bool `json:"allow_git_hook"`
|
|
// Whether the user can import local repositories
|
|
AllowImportLocal *bool `json:"allow_import_local"`
|
|
// Maximum number of repositories the user can create
|
|
MaxRepoCreation *int `json:"max_repo_creation"`
|
|
// Whether the user is prohibited from logging in
|
|
ProhibitLogin *bool `json:"prohibit_login"`
|
|
// Whether the user can create organizations
|
|
AllowCreateOrganization *bool `json:"allow_create_organization"`
|
|
// Whether the user has restricted access privileges
|
|
Restricted *bool `json:"restricted"`
|
|
// User visibility level: public, limited, or private
|
|
Visibility VisibilityString `json:"visibility" binding:"In(,public,limited,private)"`
|
|
}
|
|
|
|
// ConvertUserTypeOption options when converting a user between individual and bot
|
|
type ConvertUserTypeOption struct {
|
|
// The target user type
|
|
//
|
|
// required: true
|
|
// enum: ["User","Bot"]
|
|
UserType UserTypeString `json:"user_type" binding:"Required;In(User,Bot)"`
|
|
}
|