From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mail.toke.dk; dkim=none; arc=none (Message is not ARC signed); dmarc=fail (Used From Domain Record) header.from=dietrich.cx policy.dmarc=reject Received: from mout-p-101.mailbox.org (mout-p-101.mailbox.org [IPv6:2001:67c:2050:0:465::101]) by mail.toke.dk (Postfix) with ESMTPS id 03CA2170A981 for ; Sun, 27 Sep 2026 16:18:25 +0200 (CEST) Received: from smtp202.mailbox.org (smtp202.mailbox.org [IPv6:2001:67c:2050:b231:465::202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519MLKEM768 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-101.mailbox.org (Postfix) with ESMTPS id 4ht63t3QW9z8vGb; Sun, 27 Sep 2026 16:18:18 +0200 (CEST) Date: Sun, 27 Sep 2026 16:18:17 +0200 (CEST) From: Alexander Dietrich To: Juliusz Chroboczek Cc: Galene Mailing List Message-ID: <1248415078.226067.1790518697463@app.mailbox.org> In-Reply-To: <877bk86lrb.wl-jch@irif.fr> References: <179043064484.1076.1779405941341360418@gauss> <877bk86lrb.wl-jch@irif.fr> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Priority: 3 Importance: Normal X-Rspamd-Queue-Id: 4ht63t3QW9z8vGb Message-ID-Hash: SSMC5T63TPFKPOI57KUYHBH7ION5VNTZ X-Message-ID-Hash: SSMC5T63TPFKPOI57KUYHBH7ION5VNTZ X-MailFrom: alexander@dietrich.cx X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list Subject: [Galene] Re: Thoughts on global user passwords List-Id: =?utf-8?q?Gal=C3=A8ne_videoconferencing_server_discussion_list?= Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: > - data/config.json is read-only, so it won't be possible to add new > global users through the API; Ok, using a separate file for this data would work as well. > - you'd probably want users that only exist in a subhierarchy, for > example a user that's an op in all groups under "group/teaching/*". My initial thought was to support global passwords only, and leave permissions in the group description. So the user would be "op" in "teaching", plus whatever is necessary for the subgroups? > So my take would be to create a database of users, similar to the token > database. > > I encourage you to design and implement a proof of concept, but please be > aware that it'll likely not be merged until we find satisfactory answers > to the questions above (and others). Ok, I'll start looking into it and see if I can come up with something sensible. Kind regards, Alexander