feat: add invalid_users directive for Samba shares
Samba shares now support an 'invalid users' list (deny list), written as 'invalid users = u1,u2' in smb.conf. The UI shows a ChipPicker for valid_users and invalid_users, mutually exclusive, sourced from the system user list. feat: add ImportSystemUsers for fresh installations When NASCTL_IMPORT_ON_BOOT=true, nasctl now imports existing system users from /etc/passwd (UID 1000-60000) and /etc/group (supplemental groups), and detects which have Samba accounts via 'pdbedit -L'. Imported users are marked dirty so the admin can review before applying. New POST /api/import/users endpoint for manual re-import. This mirrors the existing import-on-boot flow for smb.conf and /etc/exports.
This commit is contained in:
@@ -24,6 +24,10 @@ func (d *DB) ReplaceSambaShares(shares []SambaShare) error {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
invalidUsers, err := encodeJSONStrings(share.InvalidUsers)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
readOnly := 0
|
||||
if share.ReadOnly {
|
||||
readOnly = 1
|
||||
@@ -33,9 +37,9 @@ func (d *DB) ReplaceSambaShares(shares []SambaShare) error {
|
||||
guestOK = 1
|
||||
}
|
||||
_, err = tx.Exec(`
|
||||
INSERT INTO samba_shares (name, path, comment, read_only, guest_ok, valid_users, valid_groups)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?)`,
|
||||
share.Name, share.Path, share.Comment, readOnly, guestOK, validUsers, validGroups,
|
||||
INSERT INTO samba_shares (name, path, comment, read_only, guest_ok, valid_users, valid_groups, invalid_users)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?)`,
|
||||
share.Name, share.Path, share.Comment, readOnly, guestOK, validUsers, validGroups, invalidUsers,
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("insert samba share %s: %w", share.Name, err)
|
||||
|
||||
Reference in New Issue
Block a user