a94b0015c41bbc4a6d849a779414b03ff657d804
Add the insert-only Operator-creation path to the break-glass console (felis breakGlass). An Operator is an additional staff admin: role=admin with must_change_password=true, identical in shape to the Owner, since Felis has no separate operator DB role (migration 0003). Unlike the Owner upsert, provisioning is insert-only -- a username already taken returns ErrConflict (ON CONFLICT DO NOTHING + zero RowsAffected) rather than silently resetting a live account, so adding an Operator can never clobber the Owner's or another Operator's credential. A typed password is used as-is; an empty one is replaced with a generated one-time credential returned for display. Operator-add does not touch local_auth_enabled -- that global gate belongs to the Owner thread alone. Accountability is recorded best-effort under a break_glass.operator_create audit action, written only after a successful provision. The TUI menu router that reaches this path is deferred; this lands the fully unit-testable logic layer (provisionOperator, performAddOperator, auditAddOperator) with the PGRepo insert kept integration-only.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%