All tools / Security & hardening
whoanddo
Admin accounts, roles, signed sessions and an audit trail that names who was really signed in.
Buy whoanddo for $149One payment of $149, plus sales tax where it applies, and every future update. Delivered as a private GitHub repository you're invited to.
See it work
whoanddo scan whoanddo/examples
whoanddo/examples/handlers_before.py:7:5: audit.append(actor=...): reads request .headers: actor
whoanddo/examples/handlers_before.py:11:5: audit.append(actor=...): reads request .headers: request.headers['X-Admin-Username']
whoanddo/examples/handlers_before.py:15:5: audit.append(actor=...): a fixed name, not the signed operator: 'admin'
3 audit call(s) take their actor from something a caller can set.
What it does
whoanddo gives an admin panel per-person accounts with roles, a pure method-and-path permission check, an ASGI guard, signed session cookies, a login throttle, an audit trail that cannot be handed a name, hashed scoped API keys and single-use reset and invite links, and it scans your code for audit calls whose actor a caller can set.
- Accounts
- One JSON file, PBKDF2 passwords, soft delete with restore, and a password change that ends every session the account holds. A store opened with other roles never deletes rows it cannot use.
- Permission check
- A pure decision from (method, path, role) against a rules table that is plain JSON you can review in a diff.
- ASGI guard
- 401, 403 or 400 before your app runs, with the proven identity in scope. Dot-segment and doubled-slash paths are refused, so the guard and your router cannot read a path differently.
- Login throttle
- Attempts are counted before the password check, so simultaneous guesses are held to the threshold. Failed-login alerts are debounced.
- An audit trail that cannot be handed a name
- AuditLog.append takes the identity a verified session returns. Passing a string raises, and there is no default actor.
- Audit scanner
- whoanddo scan finds audit calls whose actor is request input, a fixed string or a hand-built identity, following the name through locals, constants, loops and with-blocks. It exits 2 on a mistyped path so it cannot pass by accident in CI.
- API keys and single-use links
- Hashed, scoped API keys and single-use reset and invite links.
What you get
whoanddo 1.0.1: the Python package and the whoanddo command (check, scan, accounts, keys, audit), examples, and the full test suite, with 320 automated tests.
A commercial license. Use it and change it in your own projects and your clients' projects. Don't share or resell the source. Read the license.
Every update. New versions land in the same repository; git pull to get them.
Requirements
Python 3.10 or newer. Python 3.10 or newer, no runtime dependencies.
How buying works
- Enter your GitHub username. You'll see the account before you pay, so you can check it's yours.
- Pay $149, plus any sales tax shown at checkout, on Stripe's checkout page.
- Accept the invitation GitHub emails you. Signed in as that account, you'll also find it at
github.com/dominares-tools/whoanddo/invitations. Invitations expire after 7 days; you can get a new one any time. - Clone and install:
git clone https://github.com/dominares-tools/whoanddo.gitPrivate repo: sign in to GitHub on this computer first. Run
gh auth loginand choose HTTPS, or give git a personal access token when it asks for a password. To use an SSH key instead, clonegit@github.com:dominares-tools/whoanddo.git.python3 -m venv .venv && . .venv/bin/activate pip install ./whoanddo
Questions
Do I need GitHub?
Yes. Access is a read-only invitation to a private repository, sent to the GitHub account you choose.
Can I get a refund?
Yes, within 14 days, no questions asked. Access ends when the refund goes through. Refund policy.
Who takes the payment?
Payments are handled by Stripe, which works out sales tax. Your receipt and card statement show Link (LINK.COM*), Stripe's checkout service.
Something wrong?
Email support@dominares.org. Every buyer of a tool shares its repository, so support happens by email rather than in GitHub issues.