Accounts and permissions
Applies to: Rubian 4.0.2; administrative operations require appropriate access
Updated
Rubian uses the signed-in identity for the connected operating environment. Host utilities can also act under the host account. Establish which account and filesystem an operation affects before changing access.
Sign in and check identity#
Use the sign-in prompt and credentials supplied with your environment. Password entry is hidden. If the account requires a password change, complete that step before proceeding. The interactive login permits three failed attempts before ending the attempt sequence.
account = whoami
groups(account)
whoami prints and returns the session username. Pass that name explicitly to groups; its no-argument default can use the host's username. A connected session queries the environment's group information; a host-mode session uses the host utility.
Do not put passwords into ordinary Ruby command arguments. Interactive command history can persist across sessions. Prefer the product's password prompts.
Change a password#
passwd(account)
Replace account with the username you intend to change. The command prompts for the current password and the new password with confirmation. It returns true on success or false after a handled failure. When disconnected from the Rubian environment, it can invoke the host password utility; confirm the connection and target account first.
Set file permissions and ownership#
| Command | Arguments | Scope |
|---|---|---|
chmod(mode, *files) |
Numeric mode or an octal string, followed by explicit paths. | Host files and supported Rubian-managed files. |
chown(owner, *files) |
Numeric user ID, "uid:gid", or the supported owner/group pair. |
Host files and supported Rubian-managed files. Managed ownership requires numeric IDs. |
For an owner-only host document:
chmod('600', '/path/to/private-note.txt')
The string is interpreted as octal permission notation. These commands report errors and normally return nil; that value alone is not proof of success. Inspect the resulting permissions in the target environment. Changing ownership requires the corresponding authority. Symbolic host usernames do not establish numeric identities in a connected environment.
Administer accounts#
Account administration requires the appropriate administrator access for the target environment.
| Command | Behavior |
|---|---|
user_add(username, password: nil, uid: nil, home: nil) |
Creates an account. With the connected environment and no password argument, prompts for a new password twice. Optional uid and home select provisioned values. Returns a Boolean result. |
user_delete(username, remove_home: false) |
Prompts before deletion. The connected implementation refuses deletion of the root account. remove_home applies to the host-utility path; do not assume the same home-removal behavior for connected accounts. |
auth_who |
Displays connected authentication information for diagnosis. |
auth_users |
Lists connected accounts where access permits. |
When no connected environment is present, the account-creation and deletion commands can call privileged host utilities. These are consequential host operations, not offline simulations. Use the package's account-administration procedure, retain work that must survive account removal, and verify the target account after the change.
Diagnose an access failure#
Check the session identity, connection state, exact target path and whether the operation requires administrator access. For a managed path, changing host permissions on a similarly named path will not resolve the managed-file access problem. Report the account name and redacted error; never include a password or authentication token.