feat(user): add is_external flag, will permit integration of external users (without any storage) but able to be invited

This commit is contained in:
Edouard Vanbelle
2026-06-01 15:51:05 +02:00
parent bb6429a620
commit e130842bfc
8 changed files with 226 additions and 28 deletions
+6
View File
@@ -91,9 +91,15 @@ pub struct AdminCreateUserDto {
/// "admin" or "user"; defaults to "user"
pub role: Option<String>,
/// Storage quota in bytes; 0 = unlimited. If omitted, uses role default.
/// Ignored when `is_external = true` (external users have no storage).
pub quota_bytes: Option<i64>,
/// Whether the account is active; defaults to true
pub active: Option<bool>,
/// `true` to create a grant-only external user (no home folder, no
/// storage quota). Defaults to `false` (internal user). External
/// users authenticate via magic-link / OIDC / OCM federation —
/// password is set but never used.
pub is_external: Option<bool>,
}
/// Request body for admin password reset
+6
View File
@@ -19,6 +19,11 @@ pub struct UserDto {
pub auth_provider: String,
pub image: Option<String>,
pub can_edit_image: bool,
/// `true` for grant-only external recipients (magic-link, OIDC-only,
/// future OCM federated). External users have no home folder and
/// can't own storage; their quota is always 0. Internal users
/// default to `false`.
pub is_external: bool,
}
impl From<User> for UserDto {
@@ -37,6 +42,7 @@ impl From<User> for UserDto {
auth_provider: user.oidc_provider().unwrap_or("local").to_string(),
image: user.image().map(|s| s.to_string()),
can_edit_image: !user.is_oidc_user(),
is_external: user.is_external(),
}
}
}