- Auth tab is now a single choice (Off / Basic auth / SSO) instead of two
independent toggles that could both be on at once, which made it
ambiguous which gate actually protected a request. Enforced both in the
UI and server-side (POST/PUT), accounting for partial PUT updates against
the existing record.
- Add per-user basic-auth management (change password, delete) so an admin
no longer has to blow away and retype the whole user list to remove or
rotate one account.
- Fix: `Model.errors.ObjectValidateError(...)` is a constructor and was
being called without `new` everywhere in this codebase. Without `new`,
`this` inside it was the module's shared `errors` object (mutated in
place) and the call evaluated to `undefined` — so every
`throw Model.errors.ObjectValidateError(...)` actually threw `undefined`,
which Express's `next(undefined)` treats as "no error" and silently
falls through to the catch-all 404 handler. Every host/user/group/
permission/dns-provider validation error (bad hostname, bad IP, etc.) was
showing a confusing "Page not found" instead of the real message.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- Rename Grant -> Permission end-to-end (model, routes, view, frontend,
bootstrap) and add an idempotent redis migration for existing records.
- utils/roles.js: glob domain matching (* = one label, ** = any depth) against
the full host; authz passes the full hostname.
- Local groups: LocalGroup model + admin routes/UI; membership merged into
Permission.effectiveFor so app groups behave like SSO groups.
- Subject autocomplete via GET /api/permission/subjects (users + derived groups).
- User profile page (/profile) and username in the navbar; /api/user/me now
returns merged/local/external groups.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>