Project
QDBAuth
Central login/2FA service for the QDB ecosystem, owning the only username/password and TOTP checks used by QDBAdmin, the CMS (Appsmith), Troyen Data (TD), and the QDB data migration tool.
D:\Github\QDBAuth
Overview
Replaced the outdated "Site-specific roles" section (hardcoded ROLE_GROUPS) with the 2026-09-06/07 database-backed role model and role-based dashboard access, and added a Site Clients section.
Administrator User Guide
Added sections for the 5-tier role model, the new Roles management page, Site Clients, My Account self-service, and bulk-delete/search-fix behavior from the 2026-09-06/07 deliveries.
API Reference
Initial API reference for consuming apps integrating against QDBAuth's JSON API, derived from apps/auth/static/auth/openapi.yaml and apps/auth/views.py
Changelog
Added 2026-09-06 and 2026-09-07 entries: role-based dashboard access, self-service account page, 8 QA bug fixes, Site Clients, and per-site role management
Known Limitations & Security Notes
Added the temporary CMS-New TOTP test-code bypass (open, needs removal), the resolved group member-count bug, and updated the one-role-column limitation to reference the new site_roles table.
Authentication, MFA & Token Internals
Corrected an error from the previous version: no dash_* session key was actually renamed (that was part of the dropped site-to-Organization rename). The only session change on 2026-09-06 was a new dash_is_admin key.
Roles, Permissions & Multi-Tenancy
Rewrote the Roles section for the 2026-09-06/07 changes: the 5-tier Super Admin/Admin/Developer/Support Lead/User model, is_admin-flag-based access checks, and the site_roles DB table replacing the hardcoded ROLE_GROUPS dict. Added Site Clients to the multi-tenancy/client comparison.