Add admin interface
This commit is contained in:
@@ -116,7 +116,9 @@ curl --data-binary @MyGame.zip \
|
||||
```
|
||||
|
||||
`Content-Disposition`, `Vanity` and `Expiry` are all optional. Without a vanity
|
||||
name you get a UUIDv4; vanity names require a token. The reply carries the
|
||||
name you get a UUIDv4; vanity names require a token. These headers work with a
|
||||
`multipart/form-data` body too, where a non-empty form field of the same name
|
||||
overrides them. The reply carries the
|
||||
download URL and a **delete token**, shown exactly once:
|
||||
|
||||
```json
|
||||
@@ -142,10 +144,29 @@ file is accepted.
|
||||
| `GET /i/{id}` | a page showing name, size, expiry and digest |
|
||||
| `POST /api/d/{id}/delete` | delete, with `token=` in the form or `Authorization: Bearer` |
|
||||
| `POST /api/forget` | clear a remembered token |
|
||||
| `GET /admin` | administration page; admin tokens only |
|
||||
|
||||
Deleting accepts the object's delete token, the token that uploaded it, or any
|
||||
admin token.
|
||||
|
||||
## Administration
|
||||
|
||||
An admin token adds a page at `/admin`, linked from the header whenever the
|
||||
token you are using is one. It is the view that privilege is for: every stored
|
||||
file, whoever uploaded it, with a delete button on each row.
|
||||
|
||||
- Files, with size, owner, upload time and expiry, sortable by column. Expired
|
||||
files are not listed even if the sweeper has not reached them yet, since they
|
||||
are already gone as far as anything else is concerned.
|
||||
- Totals: how many files, how much is stored, how much of the quota is used and
|
||||
how much disk is left.
|
||||
- The configured tokens with their limits — names only. Hashes are never
|
||||
rendered, and there is no way to mint or revoke a token from the page.
|
||||
Anything that hands out credentials stays in the CLI, off the network.
|
||||
|
||||
Deleting from the table returns to the table. A non-admin gets `403` and never
|
||||
sees the link.
|
||||
|
||||
## Data directory
|
||||
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user