[{"data":1,"prerenderedAt":187},["ShallowReactive",2],{"nav-docs":3,"nav-api":60,"docs-users":89},[4],{"title":5,"path":6,"stem":7,"children":8},"Docs","\u002Fdocs","docs",[9,12,16,20,24,28,32,36,40,44,48,52,56],{"title":10,"path":6,"stem":11},"Installation","docs\u002Findex",{"title":13,"path":14,"stem":15},"Sending files","\u002Fdocs\u002Fsending-files","docs\u002F02.sending-files",{"title":17,"path":18,"stem":19},"Receiving files","\u002Fdocs\u002Freceiving-files","docs\u002F03.receiving-files",{"title":21,"path":22,"stem":23},"Passwords, galleries and backgrounds","\u002Fdocs\u002Fshare-options","docs\u002F04.share-options",{"title":25,"path":26,"stem":27},"Expiry and deletion","\u002Fdocs\u002Fexpiry","docs\u002F05.expiry",{"title":29,"path":30,"stem":31},"Users","\u002Fdocs\u002Fusers","docs\u002F06.users",{"title":33,"path":34,"stem":35},"Configuration","\u002Fdocs\u002Fconfiguration","docs\u002F07.configuration",{"title":37,"path":38,"stem":39},"Colours and branding","\u002Fdocs\u002Fcolors","docs\u002F08.colors",{"title":41,"path":42,"stem":43},"Docker","\u002Fdocs\u002Fdocker","docs\u002F09.docker",{"title":45,"path":46,"stem":47},"API keys","\u002Fdocs\u002Fapi-keys","docs\u002F10.api-keys",{"title":49,"path":50,"stem":51},"MCP server","\u002Fdocs\u002Fmcp-server","docs\u002F11.mcp-server",{"title":53,"path":54,"stem":55},"Troubleshooting","\u002Fdocs\u002Ftroubleshooting","docs\u002F12.troubleshooting",{"title":57,"path":58,"stem":59},"Contributing","\u002Fdocs\u002Fcontributing","docs\u002F13.contributing",[61],{"title":62,"path":63,"stem":64,"children":65},"Api","\u002Fapi","api",[66,69,73,77,81,85],{"title":67,"path":63,"stem":68},"REST API","api\u002Findex",{"title":70,"path":71,"stem":72},"Transfers","\u002Fapi\u002Ftransfers","api\u002F02.transfers",{"title":74,"path":75,"stem":76},"Uploading files","\u002Fapi\u002Fupload","api\u002F03.upload",{"title":78,"path":79,"stem":80},"Sending a transfer","\u002Fapi\u002Fsend","api\u002F04.send",{"title":82,"path":83,"stem":84},"Downloading","\u002Fapi\u002Fdownload","api\u002F05.download",{"title":86,"path":87,"stem":88},"Recipients","\u002Fapi\u002Frecipients","api\u002F06.recipients",{"id":90,"title":29,"body":91,"description":101,"extension":182,"meta":183,"navigation":184,"path":30,"seo":185,"stem":31,"__hash__":186},"docs\u002Fdocs\u002F06.users.md",{"type":92,"value":93,"toc":174},"minimark",[94,98,102,107,118,124,128,134,142,146,153,156,164,168,171],[95,96,29],"h1",{"id":97},"users",[99,100,101],"p",{},"There is no public sign-up. Accounts exist because an administrator created\nthem, and that is the entire access-control model: anyone who can upload is\nsomeone you put on the list.",[103,104,106],"h2",{"id":105},"members-and-guests","Members and guests",[99,108,109,113,114,117],{},[110,111,112],"strong",{},"Members"," are your team. They sign in with a password, send transfers, and see\ntheir own dashboard. A member with the ",[110,115,116],{},"admin"," role can also manage users.",[99,119,120,123],{},[110,121,122],{},"Guests"," are outside contacts. They have no password, sign in only by\none-time link, and can do exactly one thing: upload files to a member they pick\nfrom a list. Every member-only endpoint excludes them explicitly — a guest's\nsession is an ordinary session, so being a guest has to be checked rather than\nassumed.",[103,125,127],{"id":126},"adding-someone","Adding someone",[99,129,130,133],{},[110,131,132],{},"Users → New user."," Name, address, and whether they are a member or a guest.\nA member can be given a password, or sent a welcome e-mail with one.",[99,135,136,137,141],{},"Adding a guest is the whole setup for ",[138,139,140],"a",{"href":18},"receiving files","\nfrom them. There is nothing else to configure.",[103,143,145],{"id":144},"deleting-someone","Deleting someone",[99,147,148,149,152],{},"Deleting a user deletes ",[110,150,151],{},"every transfer they ever sent",", files included. That\nis deliberate — an account's transfers are its data — but it is not what\neveryone expects, so the confirmation says so.",[99,154,155],{},"Their API keys go with them, as do their sessions and any outstanding magic\nlinks, so a link already sitting in an inbox cannot resurrect access.",[99,157,158,159,163],{},"What survives is any ",[160,161,162],"code",{},"transfer_recipients"," row that merely named their address\non somebody else's transfer. That is part of that transfer's history, not this\naccount's data.",[103,165,167],{"id":166},"passwords","Passwords",[99,169,170],{},"Account passwords are hashed with bcrypt in a table of their own. The minimum is\n8 characters and there is no character-class checklist — length beats a\nmandatory punctuation mark.",[99,172,173],{},"Sign-in, password reset and magic-link endpoints are rate limited per IP, and\nall of them answer identically for known and unknown addresses, so the app\ncannot be used to test whether someone has an account.",{"title":175,"searchDepth":176,"depth":176,"links":177},"",2,[178,179,180,181],{"id":105,"depth":176,"text":106},{"id":126,"depth":176,"text":127},{"id":144,"depth":176,"text":145},{"id":166,"depth":176,"text":167},"md",{},true,{"title":29,"description":101},"gEVYt3MvBmG3ee7qTKSAoHdl2DHfJAjMPBELfbC3gyo",1790104591923]