Skip to content

feat(admin): manage security, sessions, sharing, and federation policies #189

Description

@veryCrunchy

Parent: #185

Provide native, high-assurance administration for security-sensitive server controls.

Scope

  • inspect and revoke user sessions, devices, tokens, and app passwords when supported
  • manage password, two-factor, login, brute-force, trusted-domain, and rate-limit policies
  • manage internal, public-link, federated, and group sharing policies
  • inspect security warnings, configuration checks, certificate status, and relevant audit events
  • provide searchable trusted-server, user, group, and network inputs instead of raw identifiers

Safety and acceptance

  • security writes require fresh authentication or explicit confirmation where appropriate
  • secrets, tokens, passwords, recovery codes, and sensitive headers are never persisted or echoed
  • high-impact changes show affected users/services and a recovery path before execution
  • session and policy lists remain paged and filterable
  • tests cover revoked permission, stale session IDs, partial bulk revocation, lockout prevention, malformed domains/networks, offline retry prohibition, and cross-account isolation
  • unsupported server versions remain readable where possible and never expose guessed mutations

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:platformAndroid, desktop, iOS, Windows, macOS, and Linux platform workarea:uxNavigation, accessibility, responsive design, and interactionenhancementNew feature or requestneeds-protocol-reviewRequires protocol or upstream source verificationplatform:androidAndroid-specific implementation or validationplatform:desktopDesktop-specific implementation or validationpriority:P1Required for the pre-release product experiencetype:featureNew product capabilitytype:securityAuthentication, privacy, secrets, or data protection

    Type

    No type

    Projects

    Status
    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions