feat: add invalid_users directive for Samba shares

Samba shares now support an 'invalid users' list (deny list), written
as 'invalid users = u1,u2' in smb.conf. The UI shows a ChipPicker
for valid_users and invalid_users, mutually exclusive, sourced from
the system user list.

feat: add ImportSystemUsers for fresh installations

When NASCTL_IMPORT_ON_BOOT=true, nasctl now imports existing system
users from /etc/passwd (UID 1000-60000) and /etc/group (supplemental
groups), and detects which have Samba accounts via 'pdbedit -L'.
Imported users are marked dirty so the admin can review before applying.
New POST /api/import/users endpoint for manual re-import.

This mirrors the existing import-on-boot flow for smb.conf and /etc/exports.
This commit is contained in:
2026-07-06 15:17:32 -04:00
parent 3e290164c5
commit 03e9368a91
18 changed files with 505 additions and 77 deletions
+4
View File
@@ -7,6 +7,7 @@ export interface SambaShare {
guest_ok: boolean;
valid_users: string[];
valid_groups: string[];
invalid_users: string[];
}
export interface NFSClient {
@@ -213,6 +214,9 @@ export const api = {
createWatchedMount: (path: string) => request<WatchedMount>("POST", "/system/watched-mounts", { path }),
deleteWatchedMount: (id: number) => request<void>("DELETE", `/system/watched-mounts/${id}`),
// import
importUsers: () => request<{ imported: number; message?: string }>("POST", "/import/users"),
// files
fileCapabilities: () => request<FileCapabilities>("GET", "/files/capabilities"),
fileRoots: () => request<{ roots: string[]; unrestricted: boolean }>("GET", "/files/roots"),