feat(auth): viewer role limited to the statistics deck #121
Labels
No labels
blocked
bug
enhancement
high-priority
low-priority
needs-info
needs-triage
ready-for-agent
ready-for-human
referenced
research
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
gabogg/hikcentral#121
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Decided 2026-09-25 with the maintainer, for the statistics deck (RFC #80). Settled; the deck UI itself is separate work.
Decisions
viewer, alongsideadminandoperator. A viewer logs in straight to the statistics deck and can reach nothing else.require_auth: live overview, doors, telemetry, the WebSocket), so a viewer account could call them all. The viewer gets an explicit list of allowed routes: the/api/statistics/routes, login/logout and its own session. Every other route returns403 FORBIDDENfor a viewer, and the WebSocket refuses it.analyticstab (see #80).viewerrole, wherever users are created today (CLI/admin), with the same seed/provisioning rules.Acceptance
/api/statistics/route, and gets 403 on every other route; tests cover a representative route from each controller and the WebSocket.require_auth).Related: #80 (deck RFC), #72 (role policy for door commands).
🤖 Generated with Claude Code