Follow what the live server does with tenants and domains
A run on the production server with throwaway tenants, a role, lists and a domain, all removed, found three things the source reading had not: - Something in a tenant has to be on a domain in that tenant (a list in a tenant on an unassigned domain is invalidForeignKey), while something in no tenant may be on a tenant's domain. The account panel's tenant choice offered every tenant; it offers only the domain's now, and a new account starts in the tenant of the domain it is made on. The domain list reads memberTenantId for it. - A domain created in a tenant puts its DKIM keys there too, and they keep the tenant from being deleted. They are counted with the rest, so Delete is not offered while any remain. - Stalwart lets a domain leave a tenant while the tenant still has accounts on it, stranding them. The panel asks first and refuses while any are there. The refusal to delete a tenant that holds anything was confirmed, as were tenant create, quota pointers, logo and rename. The mock follows the domain rule, filters DKIM keys by tenant, and KNOWN-ISSUES records the run. The non-Enterprise notice is now just "Tenants are a Stalwart Enterprise feature." Two sentences were reworded and one plural added, in all nine catalogues, and the old sentences are gone.
This commit is contained in:
+8
-4
@@ -1278,14 +1278,18 @@ under Access:
|
||||
- **The tenant's role** is the most anyone inside it can be allowed: their own
|
||||
roles are cut down to it.
|
||||
- **What it holds** is counted, each against its limit. Stalwart keeps no list
|
||||
on the tenant; each account, group, domain, list and role names its tenant,
|
||||
so the counts are queries for those.
|
||||
on the tenant; each account, group, domain, list, role and DKIM key names its
|
||||
tenant, so the counts are queries for those. A domain created in a tenant
|
||||
brings its keys with it.
|
||||
- **Domains** are added to a tenant, or taken out, from its panel. Only a domain
|
||||
in no tenant can be added, and the accounts already on it stay where they
|
||||
are.
|
||||
are. A domain comes out only once none of the tenant's accounts are on it —
|
||||
Stalwart would allow it, and strand them.
|
||||
- **An account's tenant** is chosen on the account's own panel, which is how a
|
||||
tenant gets its first administrator: an Administrator inside a tenant
|
||||
administers that tenant.
|
||||
administers that tenant. Stalwart puts something in a tenant only on a domain
|
||||
in that tenant, so the choice is between no tenant and the domain's own, and
|
||||
a new account starts in its domain's tenant.
|
||||
- **Delete** is offered once the tenant holds nothing.
|
||||
|
||||
Only an administrator outside every tenant can put anything into one; Stalwart
|
||||
|
||||
Reference in New Issue
Block a user