feat: add invalid_users directive for Samba shares

Samba shares now support an 'invalid users' list (deny list), written
as 'invalid users = u1,u2' in smb.conf. The UI shows a ChipPicker
for valid_users and invalid_users, mutually exclusive, sourced from
the system user list.

feat: add ImportSystemUsers for fresh installations

When NASCTL_IMPORT_ON_BOOT=true, nasctl now imports existing system
users from /etc/passwd (UID 1000-60000) and /etc/group (supplemental
groups), and detects which have Samba accounts via 'pdbedit -L'.
Imported users are marked dirty so the admin can review before applying.
New POST /api/import/users endpoint for manual re-import.

This mirrors the existing import-on-boot flow for smb.conf and /etc/exports.
This commit is contained in:
2026-07-06 15:17:32 -04:00
parent 3e290164c5
commit 03e9368a91
18 changed files with 505 additions and 77 deletions
+5 -1
View File
@@ -59,13 +59,16 @@ func main() {
}
if *importOnBoot {
result := importer.ImportOnBoot(nil, database, *smbConfPath, *exportsPath)
result := importer.ImportOnBoot(nil, database, *smbConfPath, *exportsPath, *adminUser)
if result.SambaImported > 0 {
log.Printf("[importer] imported %d existing samba shares — review and apply", result.SambaImported)
}
if result.NFSImported > 0 {
log.Printf("[importer] imported %d existing nfs exports — review and apply", result.NFSImported)
}
if result.UsersImported > 0 {
log.Printf("[importer] imported %d system users — review and apply", result.UsersImported)
}
}
sambaModule := samba.New(samba.Config{
@@ -87,6 +90,7 @@ func main() {
Auth: auth,
SMBConfPath: *smbConfPath,
ExportsPath: *exportsPath,
AdminUsername: *adminUser,
UploadMaxBytes: *uploadMaxBytes,
PreviewMaxBytes: *previewMaxBytes,
})