Managing users
Settings → Administration. The tab is drawn only for an account whose role is admin;
Open registration says where that role comes from and why the
tab may not be there at all.
What the table says
Section titled “What the table says”One row per account on the instance, oldest first:
| Column | What it holds |
|---|---|
| User | the username, the full name and the email, with (you) on your own row |
| Role | Admin, User, or Demo for the read-only demonstration account |
| Security | 2FA on or 2FA off, as a checked or a struck-through shield |
| Created | the day the account was opened |
| Last sign-in | the newest session’s date, and how many sessions are still live |
| API keys | how many of its keys have not been revoked |
| Accounts | how many wealth accounts it owns |
| Transactions | how many operations across those accounts |
A session counts while its refresh token is neither revoked nor expired, so that figure is live
sessions rather than sign-ins ever made. An account that has never signed in reads Never.
Deleting an account
Section titled “Deleting an account”The bin at the end of a row asks to confirm, names the username, and deletes that account with everything it owns. There is no undo, and nothing is exported on the way out: if the data matters, take an export from that reader’s own session first.
Two deletions are refused outright:
- Your own.
You cannot delete your own account here.Settings → Data holds the one that deletes your own, and it asks for your password. - The last administrator.
The last administrator cannot be deleted.The count ignores the demonstration account, which is read-only and administers nothing, so an admin badge on it never stands in for a real one.
Where the first administrator comes from
Section titled “Where the first administrator comes from”Nothing grants the role from the interface. On every start the application counts the real,
non-demonstration administrators, and when there are none it promotes the oldest account on the
instance and says so in docker compose logs app:
Promoted "<username>" to admin (no admin existed)That is how a single-reader install older than this screen ends up with one. The check is skipped rather than fatal when the database is not up yet, and runs again at the next start.
The routes behind it
Section titled “The routes behind it”| Route | What it does |
|---|---|
GET /api/admin/users |
the table above |
DELETE /api/admin/users/:id |
one deletion, with the two refusals |
GET /api/admin/settings |
the two switches on this tab |
PUT /api/admin/settings |
moves whichever switch was sent |
All four answer 403 Administrators only to anyone else, whatever the session carries.