← All requests
0

User Management, Password Management, Custom Roles, and Avatars

OpenShadowGaming100 (GitHub) · · edited

Problem Statement

Kaneo's user management and account customization could be expanded to make administration and user account management more flexible.

Administrators need a way to create users directly, manage user passwords, define custom global roles, and allow users and administrators to manage profile avatars.

Proposed Solution

Add the following functionality:

  • Create users

    • Allow administrators to create a new user from the admin interface.
    • Send the user an email containing a secure password-reset link so they can set their own password.
  • Regenerate password

    • Allow an administrator to trigger a new password-reset link for an existing user.
    • The user can then set a new password through the existing password-reset flow.
  • Custom global roles

    • Allow administrators to create custom global roles.
    • Custom roles should be configurable with the appropriate permissions rather than being limited to the built-in roles.
  • Avatar support

    • Add avatar support to user profiles.
    • Allow users to manage their avatar from the settings page.
    • Allow administrators to manage or set a user's avatar from the admin interface.

Alternative Solutions

An alternative would be to keep user creation, roles, passwords, and avatars limited to the existing built-in functionality. However, this would require administrators to rely on separate workflows or prevent customization that can be useful for self-hosted installations.

Relevant Context

These features are particularly useful for self-hosted Kaneo instances where administrators need to manage users without requiring every account to be created through the normal registration flow.

The password functionality should preferably use the existing password-reset mechanism rather than exposing or generating plaintext passwords for administrators.

Does this feature align with Kaneo's focus on simplicity?

Yes. These features can build on existing authentication, user-management, and settings flows while giving administrators the controls needed to manage a self-hosted instance without introducing unnecessary external systems.


Originally requested by @ShadowGaming100 on 2026-09-26. Original GitHub request #1813.

Issue #1813

Discussion 3

ShadowGaming100 (GitHub)

Additional Admin Features

  • User management

    • View all users
    • Search and filter users
    • View user status, role, email, and last activity
    • Create users
    • Edit user details
    • Disable/enable accounts
    • Delete users
    • Regenerate password/reset link
    • Force email verification
    • Revoke all active sessions
  • Role & permission management

    • Create custom global roles
    • Edit custom roles
    • Delete custom roles
    • Configure permissions for each role
    • Show which users are assigned to each role
    • Prevent deletion of roles that are still assigned to users
  • Workspace management

    • View all workspaces
    • View workspace members
    • Add/remove workspace members
    • Change workspace member roles
    • Disable or archive workspaces
    • Delete workspaces with an explicit confirmation
    • View workspace owner and member count
  • Account security

    • View active sessions
    • Revoke individual sessions
    • Revoke all sessions for a user
    • View authentication method used by an account
    • Show whether email verification is complete
    • Optional requirement for email verification
    • Optional restriction/disablement of public registration
  • Avatar/profile management

    • Upload/change avatar
    • Remove avatar
    • Admin ability to change/remove a user's avatar
    • Display avatars throughout the admin user list
  • API key management

    • View API keys belonging to users
    • Revoke API keys
    • Show creation and last-used dates
    • Never expose the actual secret after creation
  • System configuration

    • Instance name
    • Instance URL
    • Registration enabled/disabled
    • Email/SMTP status
    • Default user role
    • Default workspace settings
    • Authentication/SSO configuration status
  • Email administration

    • Show whether SMTP is configured
    • Send test email
    • View email configuration status
    • Resend verification email
    • Resend password-reset email
  • Audit log

    • Record important administrative actions
    • User created/deleted/disabled
    • Role created/changed/deleted
    • Permissions changed
    • Password reset requested
    • Sessions revoked
    • Workspace membership changed
    • API key revoked
    • Include actor, action, target, timestamp, and IP where appropriate
  • System information

    • Kaneo version
    • Database status
    • API status
    • WebSocket/realtime status
    • Redis status when configured
    • SMTP status
    • Storage/database information where available
  • Integrations

    • View configured integrations
    • Enable/disable integrations where supported
    • View integration connection status
    • Manage global webhooks/integration configuration

Admin Dashboard

Add a small overview page showing:

  • Total users
  • Active users
  • Disabled users
  • Total workspaces
  • Recent users
  • Recent administrative actions
  • System/service status
  • Configuration warnings

Original GitHub comment

wwojciechp (GitHub)

That’s fantastic—adding everything described above will significantly improve the application. I’m eagerly awaiting its implementation. Currently, the user management, SMTP, and global administration options are quite limited.

Original GitHub comment

Sign in to comment.

Keyboard shortcuts

Anywhere

Go to requests
gh
Go to changelog
gc
Go to notifications
gn
Next or previous page
norp
Leave a text field or close a menu
Esc
Show this list
?

Requests

Move to the next or previous request
jork
Open the selected request
oorEnter
Vote on the selected request
v
Search
/
New request
c

Request

Vote
v
Write a comment
c
Edit
e