Each account has one of five fixed roles (internal/auth, role of the
account: owner, admin, operator, auditor, member). Owner,
administrator and member come with every plan; operator and auditor come
with Warda Business (business.roles, beta: open to every installation
during the beta). When the plan does not give Warda Business, an operator
or auditor account acts as a member (never more than before).
| Role | Plan | What it does |
|---|---|---|
Owner (owner) |
all | Everything, including the accounts and their roles, the system, the backups and the updates. The emergency account admin is always an owner, and at least one owner always remains. |
Administrator (admin) |
all | Everything except the accounts of the owners (it cannot change, reset, delete or create an owner, nor make one) and the backups (read only). |
Operator (operator) |
Business | The everyday administration: devices, people and household, groups, hours of Internet, rules, suggestions, pauses, guests. Reads the network; no system, backups or accounts. |
Auditor (auditor) |
Business | Reads everything an administrator sees and changes nothing; the values that may carry a secret (the addresses of the lists and of the upstream servers) are shown without their path. |
Member (member) |
all | The everyday use: the dashboard, "something is broken" on a device, their own account. |
What each role may do, by area (W: change, R: read, —: no access):
| Area | Owner | Administrator | Operator | Auditor | Member |
|---|---|---|---|---|---|
home: dashboard, devices seen, pause or unblock a device, reports of the people |
W | W | W | R | W |
devices: rename, place, rules of a device, quarantine |
W | W | W | R | — |
household: people, groups, hours of Internet, holidays, requests, guest Wi-Fi |
W | W | W | R | — |
rules: rules, suggestions, protections, blocked services, pause of the network |
W | W | W | R | — |
reports: query log, reports, alerts, administration log |
W | W | W | R | — |
network: local DNS, DNS services and certificate, DHCP, map, tools, network check |
W | W | R | R | — |
system: settings, updates, terms, anonymous statistics, SIEM export, restarts, diagnostic |
W | W | — | R | — |
backups |
W | R | — | R | — |
accounts: accounts, temporary passwords, second factors, roles |
W | W* | — | R | — |
* Not the accounts of the owners, and it cannot make an owner. The routes of one's own account (password, second factor, own dashboard, consent to the reports, invitations) are open to every role.
- Upgrade (0.6.7): every former administrator and the emergency account become owners; the members stay members. A backup made before 0.6.7 is restored the same way. The account created at the installation is an owner, as the emergency account.
- Rules: only an owner changes the account of an owner or makes someone
an owner; the last owner and the emergency account cannot stop being
owners. The API token and the
wardacommands act as an owner. - The interface shows each role only the pages of the menu it can open; a page it can only read shows a "read only" banner, its controls turned off. Business → Roles explains the roles, shows the table above and lists every account with its role; the role is chosen per account on Administration → Access to Warda, and when giving an access from the card of a person.
- Log: every change of role is written to the administration log
(
account.role,name: old → new). - Enforcement: one table (
routePermissionsininternal/httpapi) gives every route of the API its permission — an area read, an area changed, or one's own account; a route without a declared permission stops the service at start, and the tests check every route against every role.
API: a route the role does not allow answers 403
{"error": "your role does not allow this", "state": "signed_in"};
GET /api/v1/session gives permissions ("area.read",
"area.write"), which the interface uses for its pages and buttons;
GET /api/v1/roles gives the areas and the table (areas, roles,
feature); POST /api/v1/accounts and PUT /api/v1/accounts/{id}/role
({"role": "operator", "confirm_password": "…"}) take the five roles
(402 for operator and auditor while Warda Business is locked, 403 for an
owner changed by a non-owner).