Warda-DNSDocs Warda: from ward — to protect, guardian
v0.7.10

Devices shared by several people

From 0.7.10 (beta, free; internal/category/shared.go, internal/admin/shared.go). A device used by several people of the household (the tablet of the family, the computer of the living room) is given to all of them. Nobody tells Warda who is at the device: it follows, for each setting, the most protective value among its people, the same whoever uses it, and it is counted for none of them.

Sharing a device. Household → Devices, Share… on the device (shown once the household has two people): tick the People who use this device, then Save (one person ticked: the device is theirs; none: nobody's). Or Household → People, on the card of a person, Share a device… under Shared devices: the devices someone else uses already, alone or with others. The device then says "Shared by A, B, C — follows the rules of the child profile, the most protective." Twenty people at most share a device; the box of Warda itself is never shared. A device shared is in no group and is the device of none of its people.

The most protective value, setting by setting (TestSharedCategoriesServicesSafeSearch, TestSharedHoursAndModes, TestSharedTimeLimit, TestSharedDLP, TestSharedNotices of internal/category):

Setting What the shared device gets
The profile it is said to follow (follows) the first of child, teenager, adult among the profiles of its people; the profile alone is named, never one of them
A category the strictest action among the profiles of its people: block, then monitor, then allow
Safe search, the restricted mode of YouTube on when on for the profile of one of them
A service blocked when it is for one of them (their profile, themselves, the group of devices of their entry of the directory), besides the whole network and the device itself
The hours of Internet, a cut closed whenever Internet is closed for one of them: the hours open are those open for all of them; the names always permitted still answer
Extra time given given to a person: it opens their own closing only, never the one of another
The homework mode in force when it is for one of them
The time a day in a category the smallest time allowed today among its people who have one (their limit plus the minutes given to them today)
A channel of data out (Warda Business) for each of them the action of the most precise scope (themselves, their group, the network), then the strictest: block, then alert, then allow; what is allowed for one never lifts what is blocked for another, and an action set for the device itself still wins
The names asked (the alerts of the monitored categories, the name of a way around the filter or of a threat in a notice) kept only when every adult who shares the device agreed to detailed reports, and then for the device, without a person

What is set for the device itself (its rules, the names unblocked for it, its quarantine, its pause) is not of a person: unchanged. An adult is never limited: adults alone share a device with nothing closed nor counted, and an adult among children neither opens nor closes anything. The other side of the rule, to say plainly to the parents: an adult who shares a device with a child is cut with the child on that device (hours, cut, homework mode, time a day, categories); their own devices are not.

Its own time counter. The time a day used on a shared device is counted for the device alone (table shared_usage: device, category, day, steps of 5 minutes, 7 days kept), against the smallest time among its people: never in the time of one of them, whose own devices keep their own count, and the time a child used on their own device does not count for the shared one. So a child with one hour of games a day has that hour on their own devices and the shared device has its own: a child who used up the time on their own device has the allowance again on each shared device. The minutes given to the child extend both.

Nobody is counted for it. Its activity is in no report, time spent nor total of one of its people. It is listed apart, as a shared device:

  • the report of a person: shared of GET /api/v1/people/{id}/report (each device with its counts since it is shared; the card Shared devices);
  • the time spent: shared of GET /api/v1/people/{id}/time (On shared devices), and the summary of the week;
  • the hours of Internet: shared of GET /api/v1/schedules, for the devices shared with a child or a teenager (device_id, label, people, follows, open_now, next_change, homework, limits with the minutes allowed and used on the device);
  • the alerts and the notices: written for the device and no person, shown as "Shared device (A, B)" (shared_by), only while the device is still shared by the same people, a child or a teenager among them. A way around the filter asked on it is blocked and told when a child or a teenager is among its people; spyware found on it gives a notice each of its people reads as their own (GET /api/v1/me/spyware), from the time they share it;
  • the page http://warda/ask: a device shared with a child or a teenager shows its state and its time of the day (shared and device of GET /api/v1/ask) and says that no request for more time is made from it (POST /api/v1/ask refused, 400): a request is the one of a person, made from a device of their own, or asked to the parents. An adult who shares the device and has an account can still file an unblock request for it, which only an administrator approves.

Privacy. The names asked by a shared device are shown only when every adult who shares it agreed to detailed reports, as for a personal device; while one of them did not, only the totals are ("private": true in GET /api/v1/activity?scope=device:ID, the names answer 403), in the query log too, and the alerts and notices keep no name. A member sees a device they share among their own, unless another adult who shares it did not agree. A change of the consent of an adult (given, withdrawn, or their account unlinked from their person) applies at once to the devices that adult shares, not at the next reload of the minute. The other side of the rule, to say plainly: with an adult among its people who did not agree, a category that is only monitored for the child is neither blocked nor recorded on the shared device (its alert would keep a name) — less supervision there than on the child's own device.

API. PUT /api/v1/devices/{id}/person takes {"person_id": N} (one person, 0: nobody) or {"people": [N, M, …]} (the people who share it; one id: the device of that person; none: nobody), never both (400), nor a person twice, an unknown person or more than 20 (400). PUT /api/v1/hosts/{mac}/assign takes person_id, people or group_id, one of the three. Same rights as before (administrators; with Warda Business the write right of the area devices). New fields of the answers: people (the ids, sorted; person_id and group_id are then absent) and follows (child, teen or adult) of a device (GET /api/v1/devices, the answers of the two routes above, the devices of an account); people of a machine of GET /api/v1/network; shared_devices of a person (GET /api/v1/people: devices holds their own only); shared of the counts by device. warda people prints the column SHARED DEVICES. The administration log records device.people.

Changes. The history shown of a device starts again whenever its people change, and taking it from someone is recorded, to be shown to them, as for a personal device. A person removed leaves the device to the others; one left alone has it as their own. Put in a group, it leaves its people. Two devices merged keep the people (two devices shared by different people are not merged).

Migration. The schema gets two tables at the first start of 0.7.10, device_people (device, person) and shared_usage; nothing existing is rewritten: a device of one person stays in devices.person_id as before. The backups and the configuration given to the secondary of a pair carry device_people; shared_usage, like the other counts of the day, is not restored.