feat: add invalid_users directive for Samba shares
Samba shares now support an 'invalid users' list (deny list), written as 'invalid users = u1,u2' in smb.conf. The UI shows a ChipPicker for valid_users and invalid_users, mutually exclusive, sourced from the system user list. feat: add ImportSystemUsers for fresh installations When NASCTL_IMPORT_ON_BOOT=true, nasctl now imports existing system users from /etc/passwd (UID 1000-60000) and /etc/group (supplemental groups), and detects which have Samba accounts via 'pdbedit -L'. Imported users are marked dirty so the admin can review before applying. New POST /api/import/users endpoint for manual re-import. This mirrors the existing import-on-boot flow for smb.conf and /etc/exports.
This commit is contained in:
@@ -37,6 +37,7 @@ type templateShare struct {
|
||||
GuestOK bool
|
||||
ValidUsers []string
|
||||
ValidGroups []string
|
||||
InvalidUsers []string
|
||||
}
|
||||
|
||||
type templateData struct {
|
||||
@@ -109,13 +110,14 @@ func (m *Module) renderConfig(shares []db.SambaShare) ([]byte, error) {
|
||||
data := templateData{Shares: make([]templateShare, 0, len(shares))}
|
||||
for _, share := range shares {
|
||||
data.Shares = append(data.Shares, templateShare{
|
||||
Name: share.Name,
|
||||
Path: share.Path,
|
||||
Comment: share.Comment,
|
||||
ReadOnly: share.ReadOnly,
|
||||
GuestOK: share.GuestOK,
|
||||
ValidUsers: share.ValidUsers,
|
||||
ValidGroups: share.ValidGroups,
|
||||
Name: share.Name,
|
||||
Path: share.Path,
|
||||
Comment: share.Comment,
|
||||
ReadOnly: share.ReadOnly,
|
||||
GuestOK: share.GuestOK,
|
||||
ValidUsers: share.ValidUsers,
|
||||
ValidGroups: share.ValidGroups,
|
||||
InvalidUsers: share.InvalidUsers,
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
@@ -20,5 +20,8 @@
|
||||
{{- if .ValidGroups}}
|
||||
valid groups = {{join .ValidGroups ","}}
|
||||
{{- end}}
|
||||
{{- if .InvalidUsers}}
|
||||
invalid users = {{join .InvalidUsers ","}}
|
||||
{{- end}}
|
||||
|
||||
{{end}}
|
||||
|
||||
Reference in New Issue
Block a user