v0.4.0
Who has access
Account → Users, for an admin. Add someone, see who holds a way in,
revoke every credential one account has, or remove it entirely.
The API for all of this has been there since the first release with
nothing in the dashboard reaching it — this is the screen.
Adding somebody hands back an API key, shown once, and no password.
The key is what gets them in; the password is theirs to set, and this
instance only ever keeps hashes of either.
Two things it refuses, and it says so before you click rather than
after: the account you are signed in as, and the last admin. Nothing in
the API can make an admin without one.
It is an admin's screen including the reading. What the list says is who
can get in, which is not something a member needs and is exactly what
somebody probing would want.
Seven palettes
Account → Appearance. Cubeship, Mono, Hacker, Red, Orange, Pink,
Purple.
Every one of them is dark, and that is a decision: this is a console for
a machine, read beside a terminal, and a light one would be the only
screen on that desk that is. Each changes colour and nothing else —
the layout, the type and the square corners are the product.
Your choice is saved to your account rather than to the browser, so it
follows you to another machine instead of leaving one person with two
different-looking instances.
Your settings are yours
/account is tabs now — how you sign in, what it looks like to you, and
who else can get in — and it is reached from the menu under your name
rather than from the sidebar. That sidebar section held one item, and
what is yours is not what the instance is made of.
Settings in the sidebar is still the instance's: its domain, its
contact address, when it updates itself. Nothing moved there.