DominaresTools

All tools / Security & hardening

whoanddo

Admin accounts, roles, signed sessions and an audit trail that names who was really signed in.

Buy whoanddo for $149

One payment of $149, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.

See it work

whoanddo 1.0.1real run
whoanddo scan whoanddo/examples
whoanddo/examples/handlers_before.py:7:5: audit.append(actor=...): reads request .headers: actor
whoanddo/examples/handlers_before.py:11:5: audit.append(actor=...): reads request .headers: request.headers['X-Admin-Username']
whoanddo/examples/handlers_before.py:15:5: audit.append(actor=...): a fixed name, not the signed operator: 'admin'
3 audit call(s) take their actor from something a caller can set.
Real output of whoanddo 1.0.1, run on 2026-10-05 on the tool's scanner run for real on the shipped example handlers on our test machine.

What it does

whoanddo gives an admin panel per-person accounts with roles, a pure method-and-path permission check, an ASGI guard, signed session cookies, a login throttle, an audit trail that cannot be handed a name, hashed scoped API keys and single-use reset and invite links, and it scans your code for audit calls whose actor a caller can set.

Accounts
One JSON file, PBKDF2 passwords, soft delete with restore, and a password change that ends every session the account holds. A store opened with other roles never deletes rows it cannot use.
Permission check
A pure decision from (method, path, role) against a rules table that is plain JSON you can review in a diff.
ASGI guard
401, 403 or 400 before your app runs, with the proven identity in scope. Dot-segment and doubled-slash paths are refused, so the guard and your router cannot read a path differently.
Login throttle
Attempts are counted before the password check, so simultaneous guesses are held to the threshold. Failed-login alerts are debounced.
An audit trail that cannot be handed a name
AuditLog.append takes the identity a verified session returns. Passing a string raises, and there is no default actor.
Audit scanner
whoanddo scan finds audit calls whose actor is request input, a fixed string or a hand-built identity, following the name through locals, constants, loops and with-blocks. It exits 2 on a mistyped path so it cannot pass by accident in CI.
API keys and single-use links
Hashed, scoped API keys and single-use reset and invite links.

What you get

whoanddo 1.0.1: the Python package and the whoanddo command (check, scan, accounts, keys, audit), examples, and the full test suite, with 320 automated tests.

A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.

Every update. New versions land in the same repository; git pull to get them.

Requirements

Python 3.10 or newer. Python 3.10 or newer, no runtime dependencies.

How buying works

  1. Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
  2. Pay $149, plus any sales tax shown at checkout, on Stripe's checkout page.
  3. Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at github.com/dominares-tools/whoanddo/invitations. Invitations expire after 7 days; you can get a new one any time.
  4. Clone and install:
    git clone https://github.com/dominares-tools/whoanddo.git

    Private repo: sign in to GitHub on this computer first. Run gh auth login and choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clone git@github.com:dominares-tools/whoanddo.git.

    python3 -m venv .venv && . .venv/bin/activate
    pip install ./whoanddo

Questions

Do I need GitHub?

Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.

Can I get a refund?

Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.

Who takes the payment?

Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.

Something wrong?

Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.