Review fixes: holds and create agree, and no password leaves a check

create re-enables what holds refuses (mssql login, mosquitto client,
mailu mailbox, gitea user) and clears an expired postgres password, so
no disabled account loops. mssql and mongodb checks take the password
from the environment, never argv; mosquitto_ctrl failures no longer
repeat -P. mosquitto reads 'could not ask' as an error, not absence.
mailu checks existence and enabled only: its imap passdb cannot verify
a password. mssql checks the user's SID; gitea pages teams at 50.
This commit is contained in:
jochen
2026-09-26 01:24:32 +02:00
parent 0cb0f814b4
commit 6fd93afc6c
7 changed files with 92 additions and 46 deletions
+1 -1
View File
@@ -65,6 +65,6 @@ runProvisioner("smtp", {
// Asked every minute by the harness: whether the backend still holds this consumer exactly as
// the mesh gave it, so a login lost behind the provisioner's back is made again (novox/hq issue 120).
async holds(p: Provision): Promise<boolean> {
return mailu.holdsUser(addressOf(p), p.password);
return mailu.holdsUser(addressOf(p));
},
});