feat(auth): viewer role limited to the statistics deck #121

Closed
opened 2026-09-25 19:21:03 +00:00 by gabogg · 0 comments
Owner

Decided 2026-09-25 with the maintainer, for the statistics deck (RFC #80). Settled; the deck UI itself is separate work.

Decisions

  • New role viewer, alongside admin and operator. A viewer logs in straight to the statistics deck and can reach nothing else.
  • Enforced on the server, not only by hiding tabs. Many routes today only require a login (require_auth: live overview, doors, telemetry, the WebSocket), so a viewer account could call them all. The viewer gets an explicit list of allowed routes: the /api/statistics/ routes, login/logout and its own session. Every other route returns 403 FORBIDDEN for a viewer, and the WebSocket refuses it.
  • Operators also see the deck (read-only), as a tab. Admins see it in place of today's analytics tab (see #80).
  • User management: admins can create users with the viewer role, wherever users are created today (CLI/admin), with the same seed/provisioning rules.

Acceptance

  • A viewer can log in and read every /api/statistics/ route, and gets 403 on every other route; tests cover a representative route from each controller and the WebSocket.
  • Admin and operator access is unchanged, except that operators can now reach the statistics routes (they already can: require_auth).
  • The client sends a viewer straight to the deck and shows no other tabs (client-side is convenience only; the server list is the enforcement).

Related: #80 (deck RFC), #72 (role policy for door commands).

🤖 Generated with Claude Code

Decided 2026-09-25 with the maintainer, for the statistics deck (RFC #80). Settled; the deck UI itself is separate work. ## Decisions - **New role `viewer`**, alongside `admin` and `operator`. A viewer logs in straight to the statistics deck and can reach nothing else. - **Enforced on the server, not only by hiding tabs.** Many routes today only require a login (`require_auth`: live overview, doors, telemetry, the WebSocket), so a viewer account could call them all. The viewer gets an explicit list of allowed routes: the `/api/statistics/` routes, login/logout and its own session. Every other route returns `403 FORBIDDEN` for a viewer, and the WebSocket refuses it. - **Operators also see the deck** (read-only), as a tab. **Admins** see it in place of today's `analytics` tab (see #80). - **User management:** admins can create users with the `viewer` role, wherever users are created today (CLI/admin), with the same seed/provisioning rules. ## Acceptance - A viewer can log in and read every `/api/statistics/` route, and gets 403 on every other route; tests cover a representative route from each controller and the WebSocket. - Admin and operator access is unchanged, except that operators can now reach the statistics routes (they already can: `require_auth`). - The client sends a viewer straight to the deck and shows no other tabs (client-side is convenience only; the server list is the enforcement). Related: #80 (deck RFC), #72 (role policy for door commands). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
gabogg/hikcentral#121
No description provided.