Add admin interface

This commit is contained in:
2026-09-13 00:27:29 +02:00
parent 505e4f472f
commit ca34f1506d
12 changed files with 576 additions and 13 deletions
+22 -1
View File
@@ -116,7 +116,9 @@ curl --data-binary @MyGame.zip \
```
`Content-Disposition`, `Vanity` and `Expiry` are all optional. Without a vanity
name you get a UUIDv4; vanity names require a token. The reply carries the
name you get a UUIDv4; vanity names require a token. These headers work with a
`multipart/form-data` body too, where a non-empty form field of the same name
overrides them. The reply carries the
download URL and a **delete token**, shown exactly once:
```json
@@ -142,10 +144,29 @@ file is accepted.
| `GET /i/{id}` | a page showing name, size, expiry and digest |
| `POST /api/d/{id}/delete` | delete, with `token=` in the form or `Authorization: Bearer` |
| `POST /api/forget` | clear a remembered token |
| `GET /admin` | administration page; admin tokens only |
Deleting accepts the object's delete token, the token that uploaded it, or any
admin token.
## Administration
An admin token adds a page at `/admin`, linked from the header whenever the
token you are using is one. It is the view that privilege is for: every stored
file, whoever uploaded it, with a delete button on each row.
- Files, with size, owner, upload time and expiry, sortable by column. Expired
files are not listed even if the sweeper has not reached them yet, since they
are already gone as far as anything else is concerned.
- Totals: how many files, how much is stored, how much of the quota is used and
how much disk is left.
- The configured tokens with their limits — names only. Hashes are never
rendered, and there is no way to mint or revoke a token from the page.
Anything that hands out credentials stays in the CLI, off the network.
Deleting from the table returns to the table. A non-admin gets `403` and never
sees the link.
## Data directory
```