SYSTEM LOG /
Secure account administration added for platform administrators
The platform now has a service API for securely managing local accounts. Platform administrators can search and list users, create accounts, update profiles and roles, enable or disable access, and reset passwords. Temporary passwords are generated safely, returned only once in non-cacheable responses, and require the user to set a permanent password.
The project adds an /admin/api/v1/users administration API that is available only to active platform administrators. Through it, administrators can search and filter users with pagination, read a safe account model without password or session data, create users, update profile and role, enable or disable accounts, and reset passwords. When creating an account or resetting a password, the system generates a cryptographically random temporary password; only its encoded hash is persisted, while the plain value is returned in a no-store response. Until a permanent password is set, the user's browser session is restricted to the password-change page, logout, and static resources. Creating a user also creates exactly one default personal project through the existing idempotent boundary without adding a direct security-to-project dependency. New updated_at and security_updated_at timestamps support audit trail; migration V35 backfills them for existing records without modifying passwords, and profile changes and security lifecycle changes are recorded separately. The change is covered by service, session filter, controller, and SQL migration contract tests.
← All system notes