diff --git a/docs/per-user-linux-accounts.md b/docs/per-user-linux-accounts.md index 4fcef7f3..016376be 100644 --- a/docs/per-user-linux-accounts.md +++ b/docs/per-user-linux-accounts.md @@ -279,7 +279,12 @@ Three bugs surfaced only by running it: also *unreachable*. 3. **`platform/.env` was readable, and printing `JWT_SECRET` from a member's shell was confirmed.** This is the prerequisite above, demonstrated. It is now a boot check (`assertSecretsClosed`) that refuses to - start with `OFFICER_OS_USERS` on while any `.env` in the project root is group- or world-readable. + start while any `.env` in the project root is group- or world-readable. + + That check was itself conditional on `OFFICER_OS_USERS` until 2026-08-12, which meant the guarantee was + opt-in. The flag is gone and the check is unconditional: a security prerequisite that only holds when + somebody remembers to set a variable is not a prerequisite. Per-user Linux accounts are now simply what + the platform does, so there is nothing to enable and nothing to forget. **`cd $HOME/..` succeeding is correct and worth being precise about.** `711` grants traversal, so `cd` works while `ls` does not — they can stand in the directory and see nothing in it. Beyond that, a real diff --git a/src/apps/officer-web/Screens/Dashboard/Settings/UserManagement/UsersSection.tsx b/src/apps/officer-web/Screens/Dashboard/Settings/UserManagement/UsersSection.tsx index 9bc9bcd9..1f142494 100644 --- a/src/apps/officer-web/Screens/Dashboard/Settings/UserManagement/UsersSection.tsx +++ b/src/apps/officer-web/Screens/Dashboard/Settings/UserManagement/UsersSection.tsx @@ -32,8 +32,6 @@ type ManagedUser = { type UsersResponse = { users: ManagedUser[]; - /** False on a host without per-user Linux accounts, where those controls would only ever refuse. */ - osUsersEnabled: boolean; /** Every role, for displaying the owner's own value. */ roles: string[]; /** Roles the server will accept in a write. Excludes the owner role — both write paths refuse it. */ @@ -183,7 +181,7 @@ export const UsersSection = () => { {/* Create or repair the Linux side. Offered for anyone lacking an account (backfill) and for anyone who has one (retry after fixing a host problem, or replace their key) — the underlying operation is idempotent, so there is no state where pressing it is wrong. */} - {data.osUsersEnabled && !user.isOwner && ( + {!user.isOwner && (