Background
#548 adds an /admin/users page where an existing admin can promote and demote other users. Promotion is limited to GitHub users, matching the documented rule that admin login stays GitHub-only (the email one-time-code login introduced in #523 is a weaker credential than OAuth against the server's client secret).
Proposal
Decide whether, and under what conditions, an email/OTP user can hold admin. Possible directions:
- allow it outright (simplest; relies on the mailbox being as trustworthy as a GitHub account),
- allow it behind a setting or
.env flag so operators opt in,
- require a stronger second factor for email admins.
Whichever is picked, Auth.PromoteAdmin currently returns ErrNotPromotable for Provider == "email"; that check and the README note are the things to change.
Follow-on from #548.
Background
#548 adds an
/admin/userspage where an existing admin can promote and demote other users. Promotion is limited to GitHub users, matching the documented rule that admin login stays GitHub-only (the email one-time-code login introduced in #523 is a weaker credential than OAuth against the server's client secret).Proposal
Decide whether, and under what conditions, an email/OTP user can hold admin. Possible directions:
.envflag so operators opt in,Whichever is picked,
Auth.PromoteAdmincurrently returnsErrNotPromotableforProvider == "email"; that check and the README note are the things to change.Follow-on from #548.