mssql remaps a user only when orphaned; mailu's operator tool no longer re-enables
ALTER USER ... WITH LOGIN runs only when the user's SID is not the login's, so an already-mapped user is left alone. The provisioner enables a mailbox through its own method; the password tool an operator uses keeps changing the password only.
This commit is contained in:
+10
-2
@@ -127,8 +127,16 @@ export class MailuClient {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async changePassword(email: string, password: string): Promise<void> {
|
async changePassword(email: string, password: string): Promise<void> {
|
||||||
// enabled: a disabled mailbox is what the provisioner's check reports as lost, so applying the
|
await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password });
|
||||||
// mesh's password again also enables it; otherwise the two would disagree for ever.
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Set the mesh's password on a mailbox the mesh provisions, and enable it. A disabled mailbox is
|
||||||
|
* what the provisioner's check reports as lost, so applying again must enable it, or the two would
|
||||||
|
* disagree for ever. Separate from changePassword, which an operator's tool uses and which must
|
||||||
|
* not re-enable a mailbox someone disabled.
|
||||||
|
*/
|
||||||
|
async applyProvisioned(email: string, password: string): Promise<void> {
|
||||||
await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password, enabled: true });
|
await this.api("PATCH", `/user/${encodeURIComponent(email)}`, { raw_password: password, enabled: true });
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ runProvisioner("smtp", {
|
|||||||
try {
|
try {
|
||||||
await mailu.createUser(email, p.password);
|
await mailu.createUser(email, p.password);
|
||||||
} catch {
|
} catch {
|
||||||
await mailu.changePassword(email, p.password);
|
await mailu.applyProvisioned(email, p.password);
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|
||||||
|
|||||||
+11
-3
@@ -148,9 +148,17 @@ export class MssqlClient {
|
|||||||
if (users.length === 0) {
|
if (users.length === 0) {
|
||||||
await this.exec(`CREATE USER ${ident(login)} FOR LOGIN ${ident(login)}`, database);
|
await this.exec(`CREATE USER ${ident(login)} FOR LOGIN ${ident(login)}`, database);
|
||||||
} else {
|
} else {
|
||||||
// Re-point an existing user at the login. A database restored from elsewhere keeps its user
|
// Re-point an existing user at the login when its SID is not the login's: a database restored
|
||||||
// under the old login's SID, orphaned; this maps it back, and is a no-op when it already is.
|
// from elsewhere keeps its user under the old login's SID, orphaned. Only then, so a user that
|
||||||
await this.exec(`ALTER USER ${ident(login)} WITH LOGIN = ${ident(login)}`, database);
|
// is already mapped is left alone.
|
||||||
|
const orphaned = await this.query(
|
||||||
|
`SELECT 1 AS ok FROM sys.database_principals WHERE name = ${literal(login)} ` +
|
||||||
|
`AND (sid IS NULL OR sid <> SUSER_SID(${literal(login)}))`,
|
||||||
|
database,
|
||||||
|
);
|
||||||
|
if (orphaned.length > 0) {
|
||||||
|
await this.exec(`ALTER USER ${ident(login)} WITH LOGIN = ${ident(login)}`, database);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
await this.exec(`ALTER ROLE db_owner ADD MEMBER ${ident(login)}`, database);
|
await this.exec(`ALTER ROLE db_owner ADD MEMBER ${ident(login)}`, database);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user