'Changing these requires the `write:tags` permission, on the page as it stands and as the tags leave it. Sending the tags the page already carries asks nothing, which is what lets somebody without it save a tagged page.'
'The module configuration, declared in its `definition.yml`: each entry carries a `type`, `title`, `hint`, `default` and the display hints the admin area renders a control from. A `readOnly` prop is shown but cannot be changed, and is silently kept at its stored value when written to.'
'The module configuration, declared in its `definition.yml`: each entry carries a `type`, `title`, `hint`, `default` and the display hints the admin area renders a control from. A `readOnly` prop is shown but cannot be changed, and is silently kept at its stored value when written to.\n\n`localPath` says that a prop holds a path on this server, and what may be put in it: `data` is confined to the wiki data directory, `system` is anywhere on the machine. Without `manage:system` a `system` path also reads back as `readOnly`, since there is no value such a caller could set.'
'Values for the module props. Validated against what the module declares: an unknown key is dropped, a wrong type is refused, and a read-only prop keeps its stored value. A sensitive prop sent back as the mask it was read as keeps its stored value too; send a new value to replace the secret, or an empty string to remove it.'
'Values for the module props. Validated against what the module declares: an unknown key is dropped, a wrong type is refused, and a read-only prop keeps its stored value. A sensitive prop sent back as the mask it was read as keeps its stored value too; send a new value to replace the secret, or an empty string to remove it.\n\nA prop declaring `localPath` is refused rather than dropped when the caller may not point it where they asked: without `manage:system`, a `data` path must resolve inside the wiki data directory and a `system` path cannot be set at all. Sending back the value that is already stored is always accepted, so a caller who may not change a path can still save every other field of the target.'
@ -161,7 +167,8 @@ async function routes(app: FastifyInstance) {
'/',
{
config:{
permissions:['create:sites','manage:sites']
// -> `create:sites` stood beside this one and matched nobody; see the note on the listing above
permissions:['manage:sites']
},
schema:{
summary:'Create a new site',
@ -291,7 +298,6 @@ async function routes(app: FastifyInstance) {
showMenu?: boolean
}
robots?: Record<string,any>
theme?: Record<string,any>
uploads?: Record<string,any>
}
}>(
@ -302,6 +308,8 @@ async function routes(app: FastifyInstance) {
},
schema:{
summary:'Update a site',
description:
'Every site setting except its theme, which has a route of its own because `manage:theme` grants it without granting the rest of this — see `PUT /sites/{siteId}/theme`.',
tags:['Sites'],
params:{
type:'object',
@ -382,9 +390,6 @@ async function routes(app: FastifyInstance) {
robots:{
$ref:'Site#/properties/robots'
},
theme:{
$ref:'Site#/properties/theme'
},
uploads:{
$ref:'Site#/properties/uploads'
}
@ -530,6 +535,81 @@ async function routes(app: FastifyInstance) {
// -> `manage:sites` too: whoever administers the site holds everything in it, and this route
// is the only way the theme is written now that the general update has given it up
permissions:['manage:sites','manage:theme']
},
schema:{
summary:"Update a site's theme",
description:
"The site's appearance: its colors, fonts, layout choices and the raw CSS, head and body it injects into every page. Merged onto what is stored, so a partial body leaves the rest alone.\n\nThe three `inject*` fields are served into the document as written — that is what they are for — so this route is a trust boundary, and `manage:theme` is a permission to hand out on that understanding.",
"admin.audit.actions.updateSecurity":"Changed the security configuration",
"admin.audit.actions.updateSite":"Updated a site",
"admin.audit.actions.updateSiteImage":"Uploaded a site image",
"admin.audit.actions.updateSiteTheme":"Updated a site theme",
"admin.audit.actions.updateStorage":"Updated the storage configuration",
"admin.audit.actions.updateUser":"Updated a user",
"admin.audit.actions.updateUserDefaults":"Changed the user defaults",
@ -631,6 +632,9 @@
"admin.groups.selectedLocales":"Any Locale | {n} locale only | {count} locales selected",
"admin.groups.selectedSites":"Any Site | 1 site selected | {count} sites selected",
"admin.groups.subtitle":"Manage user groups and permissions",
"admin.groups.systemPermission":"Full Access",
"admin.groups.systemPermissionWarn":"This grants access to everything on this wiki.",
"admin.groups.systemPermissionWarnHint":"A member of this group can read, change and delete anything on every site, including other administrators and this group itself. Every permission beside it stops mattering. Grant it only to the people who run this instance.",
"admin.groups.title":"Groups",
"admin.groups.unassignUser":"Unassign User",
"admin.groups.unassignUserConfirm":"Are you sure you want to unassign {userName} from this group?",
hint:Absolute path to the key. The key must NOT be passphrase-protected.
icon:key
order:12
localPath:system
if:
- {key: 'authType', eq:'ssh'}
- {key: 'sshPrivateKeyMode', eq:'path'}
@ -129,6 +130,7 @@ props:
hint:Where the working copy is kept. Give each site its own path unless you turn on Add Site ID Prefix under Configuration, since two sites sharing a repository would otherwise write over each other. Relative paths are resolved from the Wiki.js install directory.
icon:symlink-directory
order:32
localPath:data
gitBinaryPath:
type:String
title:Git Binary Path
@ -136,6 +138,7 @@ props:
hint:Optional - Absolute path to the Git binary, when not available in PATH. Leave empty to use the default PATH location (recommended).
hint:'Can view users, but not create or modify them.',
warning:false,
restrictedForSystem:true,
disabled:false
hint:'Can access the administration and view the dashboard. Cannot perform any other action unless other permissions are also granted.'
},
{
permission:'manage:users',
hint:'Can create / manage users (but not users with manage:system permissions)',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'manage:sites',
hint:'Can create / manage sites, and every setting bound to one: general, analytics, approvals, comments, content blocks, editors, locale, login, storage and theme.'
},
{
permission:'read:groups',
hint:'Can view groups and their permissions, but not create or modify them.',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'manage:theme',
hint:'Can modify site theme settings, including the CSS, head and body injected into every page.'
},
{
permission:'manage:groups',
hint:'Can create / manage groups and assign permissions (but not manage:system) / page rules',
warning:true,
restrictedForSystem:true,
disabled:false
permission:'manage:navigation',
hint:'Can manage site navigation'
},
{
permission:'read:audit',
hint:'Can read the audit log, i.e. the record of what everybody on this wiki has done.',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'read:users',
hint:'Can view users, but not create or modify them.'
},
{
permission:'read:metrics',
hint:'Can scrape the Prometheus metrics endpoint from an address it is not open to anonymously.',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'manage:users',
hint:'Can create / manage users (but not users with manage:system permissions)'
},
{
permission:'manage:navigation',
hint:'Can manage site navigation',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'read:groups',
hint:'Can view groups and their permissions, but not create or modify them.'
},
{
permission:'manage:theme',
hint:'Can modify site theme settings',
warning:false,
restrictedForSystem:true,
disabled:false
permission:'manage:groups',
hint:'Can create / manage groups and assign permissions (but not manage:system) / page rules'
},
{
permission:'manage:sites',
hint:'Can create / manage sites',
warning:true,
restrictedForSystem:true,
disabled:false
permission:'read:audit',
hint:'Can read the audit log, i.e. the record of what everybody on this wiki has done.'
},
{
permission:'manage:system',
hint:'Can manage and access everything. Root administrator.',
warning:true,
restrictedForSystem:true,
disabled:true
permission:'read:metrics',
hint:'Can scrape the Prometheus metrics endpoint from an address it is not open to anonymously.'