feat(cli): user management commands in hikctl CLI toolkit #38

Closed
opened 2026-09-21 14:55:22 +00:00 by gabogg · 1 comment
Owner

📌 Problem Statement

Currently, user accounts in HikCentral Gateway are only seeded statically (admin and operator) during initial database provisioning (init_db()).

There is no dedicated CLI management tool in hikctl to:

  1. List existing database accounts and roles.
  2. Add additional operator or admin accounts (e.g. for multiple SOC shifts, wall displays, or distinct monitoring stations).
  3. Reset or rotate user passwords.
  4. Remove departed operator accounts.

Administrators currently have to run custom Python or SQLite shell scripts directly against the database file.


🎯 Proposed Solution & Scope

Integrate a dedicated hikctl user subcommand group into the auxiliary CLI toolkit:

1. CLI Commands (hikctl user ...)

  • hikctl user list [--json]:
    • Tabulates all registered users: ID, username, role (admin/operator), and creation timestamp.
    • Supports --json for machine-readable output.
  • hikctl user add <username> [--role {operator,admin}] [--password PASSWORD]:
    • Creates a new user in the configured database (DATABASE_PATH).
    • Prompts securely for password with confirmation via getpass if --password is omitted (preventing shell history leakage).
    • Uses standard PBKDF2-HMAC-SHA256 password hashing (100,000 iterations).
  • hikctl user passwd <username> [--password PASSWORD]:
    • Resets password for an existing user.
    • Prompts securely via getpass if --password is omitted.
  • hikctl user remove <username> [--force]:
    • Deletes user from the database.
    • Revokes active sessions for that user.
    • Prevents deleting the last remaining admin account.

2. Backend Repository Support (UserRepository)

Add clean helper methods to UserRepository (app/db/user_repository.py):

  • list_users() -> list[dict[str, Any]]
  • create_user(username: str, password: str, role: str) -> dict[str, Any]
  • update_password(username: str, new_password: str) -> bool
  • delete_user(username: str) -> bool

✅ Acceptance Criteria

  • hikctl user list outputs all users in formatted table or JSON.
  • hikctl user add creates users with PBKDF2 hashes (interactive prompt by default).
  • hikctl user passwd allows changing password interactively or via flag.
  • hikctl user remove deletes user and prevents deleting the last remaining admin.
  • Cross-platform support (Linux and Windows Server).
  • Automated CLI unit tests added in tests/test_cli_commands.py.
## 📌 Problem Statement Currently, user accounts in HikCentral Gateway are only seeded statically (`admin` and `operator`) during initial database provisioning (`init_db()`). There is no dedicated CLI management tool in `hikctl` to: 1. List existing database accounts and roles. 2. Add additional operator or admin accounts (e.g. for multiple SOC shifts, wall displays, or distinct monitoring stations). 3. Reset or rotate user passwords. 4. Remove departed operator accounts. Administrators currently have to run custom Python or SQLite shell scripts directly against the database file. --- ## 🎯 Proposed Solution & Scope Integrate a dedicated `hikctl user` subcommand group into the auxiliary CLI toolkit: ### 1. CLI Commands (`hikctl user ...`) - `hikctl user list [--json]`: - Tabulates all registered users: ID, username, role (`admin`/`operator`), and creation timestamp. - Supports `--json` for machine-readable output. - `hikctl user add <username> [--role {operator,admin}] [--password PASSWORD]`: - Creates a new user in the configured database (`DATABASE_PATH`). - Prompts securely for password with confirmation via `getpass` if `--password` is omitted (preventing shell history leakage). - Uses standard PBKDF2-HMAC-SHA256 password hashing (100,000 iterations). - `hikctl user passwd <username> [--password PASSWORD]`: - Resets password for an existing user. - Prompts securely via `getpass` if `--password` is omitted. - `hikctl user remove <username> [--force]`: - Deletes user from the database. - Revokes active sessions for that user. - Prevents deleting the last remaining admin account. ### 2. Backend Repository Support (`UserRepository`) Add clean helper methods to `UserRepository` (`app/db/user_repository.py`): - `list_users() -> list[dict[str, Any]]` - `create_user(username: str, password: str, role: str) -> dict[str, Any]` - `update_password(username: str, new_password: str) -> bool` - `delete_user(username: str) -> bool` --- ## ✅ Acceptance Criteria - [x] `hikctl user list` outputs all users in formatted table or JSON. - [x] `hikctl user add` creates users with PBKDF2 hashes (interactive prompt by default). - [x] `hikctl user passwd` allows changing password interactively or via flag. - [x] `hikctl user remove` deletes user and prevents deleting the last remaining admin. - [x] Cross-platform support (Linux and Windows Server). - [x] Automated CLI unit tests added in `tests/test_cli_commands.py`.
gabogg changed title from feat(auth): basic user management panel in Admin UI and REST API to feat(cli): user management commands in hikctl CLI toolkit 2026-09-21 15:09:01 +00:00
Author
Owner

Implemented via Pull Request #39:

  • hikctl user list [--json]
  • hikctl user add <username> [--role {operator,admin}] [--password PASSWORD]
  • hikctl user passwd <username> [--password PASSWORD]
  • hikctl user remove <username> [--force] (alias: delete)

All 190 tests passing (100% green).

Implemented via Pull Request #39: - `hikctl user list [--json]` - `hikctl user add <username> [--role {operator,admin}] [--password PASSWORD]` - `hikctl user passwd <username> [--password PASSWORD]` - `hikctl user remove <username> [--force]` (alias: `delete`) All 190 tests passing (100% green).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
gabogg/hikcentral#38
No description provided.