The store has no user-list query. With registration = "open" an admin cannot enumerate accounts, see which are pending verification, which are disabled, or who holds admin.
Add SSH-only registry commands gated on IsAdmin, the pattern audit uses in internal/control/audit.go:
admin user list [--state active|pending|disabled|admin] [--limit] [--cursor]admin user show <name>: keys with last use, emails with how each was verified, orgs, repo count, API token count, open web sessions.
closed by commit 8f2ddee1da by cmc: admin: list and show accounts over SSH
2026-09-02 00:51 UTC