user
user
Type: Directory
Router administration user accounts. Each user belongs to exactly one group that grants the rights (policies) the user has. See User for the full guide.
| Flag | Name | Description |
|---|---|---|
| E | expired | Password expired with /user/expire-password. At the next interactive login the user is asked to set a new password; setting a new password clears the flag. |
| X | disabled | User account is disabled and cannot log in. |
| Argument | Type | Description |
|---|---|---|
| name ( mandatory ) | string | Login user name. Letters, digits and the characters _ . # - @ are allowed; the name must end with a letter or a digit and cannot start with . or -. |
| group ( mandatory ) | enum | User group that grants the rights (policies) the user has. |
| password ( mandatory ) | string | Login password. Any characters are accepted, including spaces, symbols and UTF-8. An explicitly empty value (password="") allows logging in with a blank password. The complexity policy from /user/settings applies when set. |
| inactivity-timeout | time | Idle time after which inactivity-policy is applied to an interactive console session. Range 00:01:00 to 1d00:00:00. Default: 10m. |
| inactivity-policy | enum (none | logout | lockscreen) | Action taken when
|
| address | object { address: alt { address: ipPrefix , address: ip6Prefix } } | IP address with mask or IPv6 prefix. When set, the user may log in only from matching source addresses; logins from other addresses are refused. |
| Read-only Argument | Type | Description |
|---|---|---|
| last-logged-in | date | Date and time of the user's last login. |