Account and operation · Chapter 29
The operator
The operator has the tab Server under Settings. Everything that concerns the whole server is there, in a second row of tabs. Members do not see it.
Accounts
The list shows every account with role, way of signing in, access, second factor and open links. For each there are Make operator or Make member, Set a password (made at random, shown once), Remove second factor, Sign out everywhere, Block and Delete. A blocked account gets in nowhere, not with a token either. Public pages and reviews it created stay open until you end them with Withdraw links.
Here you also find Invite into nexbrand for an account without a client, Every client and its access with the switch Members create clients, and Mail: server, port, encryption, user, password, sender and a test mail. nexbrand mails only invitations, review links and the test mail.
Sign-in
- OpenID Connect: Issuer, Client ID, Client secret, Name on the button. You enter the redirect address at the provider. New people get an account is off out of the box; then only invited or linked accounts get in.
- authentik in one step: the address of authentik and an API token that may create applications, then Set up. nexbrand creates the key, mapping, provider and application there itself and names each step. The token is used for that only and never stored. If you prefer to import it yourself, take Download blueprint instead.
- Sign-in with password can be switched off once a provider is set up; your own password stays with you.
- Require a second factor: every account with a password must set one up before it gets further. Set up your own first.
- Public address: for links in invitations and public pages, and the return from the provider.
The switches to the outside
| Tab | Switches, all off out of the box |
|---|---|
| Public pages | Allow public pages, for public pages and reviews |
| API | Accounts may create API tokens; below, every token with Block |
| Collecting and AI | Allow collecting from websites and GitHub repositories, a GitHub token for private repositories, Allow each account its own AI service and the machines in your own network for AI |
Files, languages, log
Under Files you set the Largest file (MB) and whether photos lose location and device. Under Languages you upload further languages as JSON, with a language code such as es; German and English are built in, and whatever a file lacks shows in English. The Log has four levels; Detailed and Everything switch themselves back after an hour. Client contents, passwords, keys and tokens never appear in it.
Version check and environment
On the page About nexbrand, Check once a day asks GitHub for the newest release, with no names, clients or settings. It is the only request nexbrand sends outside on its own. For running behind a proxy there are environment variables such as NEXBRAND_PUBLIC_URL, NEXBRAND_TRUSTED_PROXIES and NEXBRAND_OPERATOR_NETWORKS; they are described under Self-host.
Pavo saysLasting changes to other accounts ask for your own password once more. So an open browser alone is not enough to rebuild the server.