feat: Allow admins to disable the login capability of an account #1272

Merged
nex merged 6 commits from nex/feat/admin-disable-login into main 2026-01-07 19:24:51 +00:00
Owner

This pull request allows admins to disable the login capability of an account without changing its password, locking, suspending, or disabling it. This is especially useful for bot accounts where you typically will not want them to be able to log in again after they've already got a session token (since they typically won't need to).

Also fixes a spec misinterpretation in #1266 that allowed locked users to log in but do nothing else (it makes no sense for them to be able to log in at all, so that check is now also performed during login)

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
<!-- In order to help reviewers know what your pull request does at a glance, you should ensure that 1. Your PR title is a short, single sentence describing what you changed 2. You have described in more detail what you have changed, why you have changed it, what the intended effect is, and why you think this will be beneficial to the project. If you have made any potentially strange/questionable design choices, but didn't feel they'd benefit from code comments, please don't mention them here - after opening your pull request, go to "files changed", and click on the "+" symbol in the line number gutter, and attach comments to the lines that you think would benefit from some clarification. --> This pull request allows admins to disable the login capability of an account without changing its password, locking, suspending, or disabling it. This is especially useful for bot accounts where you typically will not want them to be able to log in again after they've already got a session token (since they typically won't need to). Also fixes a spec misinterpretation in #1266 that allowed locked users to log in but do nothing else (it makes no sense for them to be able to log in at all, so that check is now also performed during login) <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [x] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. - [x] I have written a [news fragment][n1] for this PR, if applicable<!--(can be done after hitting open!)-->. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages [n1]: https://towncrier.readthedocs.io/en/stable/tutorial.html#creating-news-fragments
nex added this to the 0.5.2 milestone 2026-01-06 21:39:39 +00:00
feat: Allow admins to disable the login capability of an account
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
0b42bb71e5
chore: Add news fragment
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m6s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
4368c96915
nex requested review from Owners 2026-01-06 21:40:46 +00:00
fix: Correctly return M_USER_LOCKED during login
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m41s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m57s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
51238daf78
fix: Await future
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Successful in 2m25s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 4m20s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 23m8s
06b1757b87
@ -296,2 +298,4 @@
}
pub fn disable_login(&self, user_id: &UserId) {
self.db.userid_login_disabled.insert(user_id, "1");
Owner

Sob

Also this table doesn't follow naming convention, should be userid_logindisabled

Sob Also this table doesn't follow naming convention, should be userid_logindisabled
nex marked this conversation as resolved
perf: Store empty value (row only needs to exist)
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m11s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m58s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 20m53s
d8bd8b0a77
@ -298,0 +304,4 @@
pub fn enable_login(&self, user_id: &UserId) { self.db.userid_logindisabled.remove(user_id); }
pub async fn is_login_disabled(&self, user_id: &UserId) -> bool {
self.db.userid_logindisabled.get(user_id).await.is_ok()
Owner

I think there's a function to check if a row with a key exists while ignoring the value (contains?), that might be more idiomatic

I think there's a function to check if a row with a key exists while ignoring the value (`contains`?), that might be more idiomatic
nex marked this conversation as resolved
@ -1045,0 +1100,4 @@
}
self.services.users.enable_login(&user_id);
self.write_str(&format!("{user_id} can now log in.")).await
Owner

We might want to return a note if the user in question was already able to log in?

We might want to return a note if the user in question was already able to log in?
Author
Owner

I don't think that info's relevant by the time it reaches the user

I don't think that info's relevant by the time it reaches the user
ginger marked this conversation as resolved
ginger left a comment
Owner

some thoughts

some thoughts
Owner

thank you forgejo for interpreting that as three separate reviews

thank you forgejo for interpreting that as three separate reviews
style: Use contains to check for row presence
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m1s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
9c7c0e4e8f
ginger approved these changes 2026-01-07 17:30:26 +00:00
nex force-pushed nex/feat/admin-disable-login from 9c7c0e4e8f
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 1m8s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m1s
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 77e8fd1744
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Successful in 2m57s
Checks / Prek / Clippy and Cargo Tests (pull_request) Failing after 3m23s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 4m17s
Documentation / Build and Deploy Documentation (push) Successful in 2m41s
Checks / Prek / Clippy and Cargo Tests (push) Failing after 3m27s
Checks / Prek / Pre-commit & Formatting (push) Successful in 4m37s
Release Docker Image / Build linux-amd64 (release) (push) Successful in 11m45s
Release Docker Image / Build linux-arm64 (release) (push) Successful in 9m12s
Release Docker Image / Create Multi-arch Release Manifest (push) Successful in 29s
Release Docker Image / Build linux-amd64 (max-perf) (push) Successful in 15m40s
Release Docker Image / Build linux-arm64 (max-perf) (push) Successful in 15m35s
Release Docker Image / Create Max-Perf Manifest (push) Successful in 17s
2026-01-07 17:32:06 +00:00
Compare
Jade approved these changes 2026-01-07 17:35:24 +00:00
Jade left a comment
Owner

Lgtm

Lgtm
nex merged commit 77e8fd1744 into main 2026-01-07 19:24:51 +00:00
nex deleted branch nex/feat/admin-disable-login 2026-01-07 19:24:51 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!1272
No description provided.