feat: add invalid_users directive for Samba shares
Samba shares now support an 'invalid users' list (deny list), written as 'invalid users = u1,u2' in smb.conf. The UI shows a ChipPicker for valid_users and invalid_users, mutually exclusive, sourced from the system user list. feat: add ImportSystemUsers for fresh installations When NASCTL_IMPORT_ON_BOOT=true, nasctl now imports existing system users from /etc/passwd (UID 1000-60000) and /etc/group (supplemental groups), and detects which have Samba accounts via 'pdbedit -L'. Imported users are marked dirty so the admin can review before applying. New POST /api/import/users endpoint for manual re-import. This mirrors the existing import-on-boot flow for smb.conf and /etc/exports.
This commit is contained in:
@@ -196,6 +196,7 @@ type Server struct {
|
||||
Auth *AuthService
|
||||
SMBConfPath string
|
||||
ExportsPath string
|
||||
AdminUsername string
|
||||
UploadMaxBytes int64
|
||||
PreviewMaxBytes int64
|
||||
}
|
||||
@@ -205,6 +206,7 @@ type Options struct {
|
||||
Auth *AuthService
|
||||
SMBConfPath string
|
||||
ExportsPath string
|
||||
AdminUsername string
|
||||
UploadMaxBytes int64
|
||||
PreviewMaxBytes int64
|
||||
}
|
||||
@@ -223,6 +225,7 @@ func NewServer(database *db.DB, eng *engine.Engine, opts Options) *Server {
|
||||
Auth: opts.Auth,
|
||||
SMBConfPath: opts.SMBConfPath,
|
||||
ExportsPath: opts.ExportsPath,
|
||||
AdminUsername: opts.AdminUsername,
|
||||
UploadMaxBytes: opts.UploadMaxBytes,
|
||||
PreviewMaxBytes: opts.PreviewMaxBytes,
|
||||
}
|
||||
|
||||
@@ -8,11 +8,13 @@ import (
|
||||
"github.com/darroyo/nasctl/internal/importer"
|
||||
"github.com/darroyo/nasctl/internal/modules/nfs"
|
||||
"github.com/darroyo/nasctl/internal/modules/samba"
|
||||
"github.com/darroyo/nasctl/internal/modules/users"
|
||||
)
|
||||
|
||||
type importStatus struct {
|
||||
Samba moduleImportStatus `json:"samba"`
|
||||
NFS moduleImportStatus `json:"nfs"`
|
||||
Samba moduleImportStatus `json:"samba"`
|
||||
NFS moduleImportStatus `json:"nfs"`
|
||||
Users moduleImportStatus `json:"users"`
|
||||
}
|
||||
|
||||
type moduleImportStatus struct {
|
||||
@@ -24,9 +26,11 @@ type moduleImportStatus struct {
|
||||
func (s *Server) handleImportStatus(w http.ResponseWriter, r *http.Request) {
|
||||
sambaDone, _, _ := s.DB.GetSetting("import.samba.done")
|
||||
nfsDone, _, _ := s.DB.GetSetting("import.nfs.done")
|
||||
usersDone, _, _ := s.DB.GetSetting("import.users.done")
|
||||
|
||||
shares, _ := s.DB.ListSambaShares()
|
||||
exports, _ := s.DB.ListNFSExports()
|
||||
userList, _ := s.DB.ListUsers()
|
||||
|
||||
status := importStatus{
|
||||
Samba: moduleImportStatus{
|
||||
@@ -37,6 +41,10 @@ func (s *Server) handleImportStatus(w http.ResponseWriter, r *http.Request) {
|
||||
Done: nfsDone == "true",
|
||||
Count: len(exports),
|
||||
},
|
||||
Users: moduleImportStatus{
|
||||
Done: usersDone == "true",
|
||||
Count: len(userList),
|
||||
},
|
||||
}
|
||||
|
||||
if ts, ok, _ := s.DB.GetSetting("import.samba.at"); ok {
|
||||
@@ -45,6 +53,9 @@ func (s *Server) handleImportStatus(w http.ResponseWriter, r *http.Request) {
|
||||
if ts, ok, _ := s.DB.GetSetting("import.nfs.at"); ok {
|
||||
status.NFS.LastImportAt = ts
|
||||
}
|
||||
if ts, ok, _ := s.DB.GetSetting("import.users.at"); ok {
|
||||
status.Users.LastImportAt = ts
|
||||
}
|
||||
|
||||
writeJSON(w, http.StatusOK, status)
|
||||
}
|
||||
@@ -115,9 +126,43 @@ func (s *Server) handleImportNFS(w http.ResponseWriter, r *http.Request) {
|
||||
writeJSON(w, http.StatusOK, map[string]any{"imported": len(exports)})
|
||||
}
|
||||
|
||||
func (s *Server) handleImportUsers(w http.ResponseWriter, r *http.Request) {
|
||||
if err := importer.ResetImportFlags(r.Context(), s.DB); err != nil {
|
||||
writeError(w, http.StatusInternalServerError, err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
imported, err := importer.ImportSystemUsers(r.Context(), s.AdminUsername)
|
||||
if err != nil {
|
||||
writeError(w, http.StatusInternalServerError, err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if len(imported) == 0 {
|
||||
writeJSON(w, http.StatusOK, map[string]any{"imported": 0, "message": "no system users found to import"})
|
||||
return
|
||||
}
|
||||
|
||||
if err := s.DB.ReplaceUsers(imported); err != nil {
|
||||
writeError(w, http.StatusInternalServerError, err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if err := s.DB.MarkDirty(users.ModuleName); err != nil {
|
||||
writeError(w, http.StatusInternalServerError, err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
_ = s.DB.SetSetting("import.users.done", "true")
|
||||
_ = s.DB.SetSetting("import.users.at", time.Now().Format(time.RFC3339))
|
||||
|
||||
writeJSON(w, http.StatusOK, map[string]any{"imported": len(imported)})
|
||||
}
|
||||
|
||||
type dbExporter interface {
|
||||
ReplaceSambaShares(shares []db.SambaShare) error
|
||||
ReplaceNFSExports(exports []db.NFSExport) error
|
||||
ReplaceUsers(users []db.User) error
|
||||
MarkDirty(module string) error
|
||||
}
|
||||
|
||||
|
||||
@@ -24,13 +24,14 @@ func writeError(w http.ResponseWriter, status int, message string) {
|
||||
}
|
||||
|
||||
type sambaShareRequest struct {
|
||||
Name string `json:"name"`
|
||||
Path string `json:"path"`
|
||||
Comment string `json:"comment"`
|
||||
ReadOnly bool `json:"read_only"`
|
||||
GuestOK bool `json:"guest_ok"`
|
||||
ValidUsers []string `json:"valid_users"`
|
||||
ValidGroups []string `json:"valid_groups"`
|
||||
Name string `json:"name"`
|
||||
Path string `json:"path"`
|
||||
Comment string `json:"comment"`
|
||||
ReadOnly bool `json:"read_only"`
|
||||
GuestOK bool `json:"guest_ok"`
|
||||
ValidUsers []string `json:"valid_users"`
|
||||
ValidGroups []string `json:"valid_groups"`
|
||||
InvalidUsers []string `json:"invalid_users"`
|
||||
}
|
||||
|
||||
func (req sambaShareRequest) validate(allowedRoots []string) error {
|
||||
@@ -45,18 +46,24 @@ func (req sambaShareRequest) validate(allowedRoots []string) error {
|
||||
return err
|
||||
}
|
||||
}
|
||||
for _, user := range req.InvalidUsers {
|
||||
if err := system.ValidateUsername(user); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (req sambaShareRequest) toModel() db.SambaShare {
|
||||
return db.SambaShare{
|
||||
Name: req.Name,
|
||||
Path: req.Path,
|
||||
Comment: req.Comment,
|
||||
ReadOnly: req.ReadOnly,
|
||||
GuestOK: req.GuestOK,
|
||||
ValidUsers: req.ValidUsers,
|
||||
ValidGroups: req.ValidGroups,
|
||||
Name: req.Name,
|
||||
Path: req.Path,
|
||||
Comment: req.Comment,
|
||||
ReadOnly: req.ReadOnly,
|
||||
GuestOK: req.GuestOK,
|
||||
ValidUsers: req.ValidUsers,
|
||||
ValidGroups: req.ValidGroups,
|
||||
InvalidUsers: req.InvalidUsers,
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -39,6 +39,7 @@ func NewRouter(s *Server) chi.Router {
|
||||
protected.Get("/import/status", s.handleImportStatus)
|
||||
protected.Post("/import/samba", s.handleImportSamba)
|
||||
protected.Post("/import/nfs", s.handleImportNFS)
|
||||
protected.Post("/import/users", s.handleImportUsers)
|
||||
|
||||
protected.Route("/samba/shares", func(shares chi.Router) {
|
||||
shares.Get("/", s.handleListSambaShares)
|
||||
|
||||
Reference in New Issue
Block a user