Add DB viewer access logging, account deletion, and forced password change
Logs a distinct db_viewer_accessed event (not just the earlier session_created "requested" event) when an admin's browser actually completes the hand-off into Adminer. Adds a password-confirmed account-deletion box to Settings, relying on the existing ON DELETE CASCADE foreign keys to clean up everything the account owns. Adds an admin-only "require password change" flag that get_current_user enforces server-side (403 on everything except /auth/me, /auth/change-password, /auth/logout) - meant for handing a demo account to someone with a known sample password. Co-Authored-By: Claude Sonnet 5 <[email protected]>
This commit is contained in:
@@ -23,6 +23,13 @@ class UserRepository:
|
||||
result = await self.db.execute(select(User.email).where(User.is_admin.is_(True)))
|
||||
return list(result.scalars().all())
|
||||
|
||||
async def delete(self, user: User) -> None:
|
||||
"""Cascades (ON DELETE CASCADE, see migrations) to every row the
|
||||
user owns - companies and everything under them, refresh tokens,
|
||||
security events, etc. Irreversible."""
|
||||
await self.db.delete(user)
|
||||
await self.db.flush()
|
||||
|
||||
async def create(
|
||||
self,
|
||||
*,
|
||||
|
||||
Reference in New Issue
Block a user