Public users and user groups
Public users are the people who sign in to your website. User groups are labels you attach to them, such as "members" or "staff". This page explains how they fit together so you know what you can build with them and what you cannot.
Public users compared with administrators
| Public user | Administrator | |
|---|---|---|
| Signs in at | Your website, under /account/login | The admin at /raytha |
| Can use the admin | No | Yes, as far as their roles allow |
| Managed under | People > Users | People > Admins |
| Grouped by | User groups | Roles |
Both kinds are the same kind of account underneath, with one shared set of email addresses. That is why administrators also appear in the Users list, and why an address can only be used once.
How people get an account
- You create them. See Create or edit a public user.
- They register themselves. The page at
/account/createasks for a name, email and password. It exists only while the built-in Email address and password sign-in is enabled for users. New accounts are active immediately and belong to no group. - Single sign-on creates them. When someone signs in through a JWT or SAML scheme, Raytha creates the account if it does not exist and keeps the name and email up to date. See Enable different authentications and single sign-on.
The sign-in pages visitors see
| Path on your site | Purpose |
|---|---|
/account/login | The main login page, with a button for each other enabled method. It redirects straight to your identity provider when the only enabled scheme is single sign-on, and to the magic-link page when magic link is the only built-in method. |
/account/login/magic-link | Asks for an email address and sends a one-time code. |
/account/login/forgot-password/begin | Sends a password reset link. |
/account/create | Self-registration. |
/account/logout | Signs out. |
Add ?returnUrl=/members to a login link to send people to a local path after they sign in. Absolute URLs are ignored.
These pages are rendered from templates you can change under Design > Themes. See Overview of the built-in templates.
User groups
A user group has a Label for people and a Developer name for templates and code, for example "Premium members" and premium_members. A user can belong to any number of groups.
Create a group
- Open People > Users and switch to the User groups tab.
- Click New group.
- Enter a Label. The Developer name is filled in from it as lowercase letters, numbers and underscores. Change it now if you want something else.
- Click Create.
On a group's page you can change the Label and click Save. The developer name is fixed once the group exists, because templates refer to it.
Put people in a group
- By hand. Open the user, tick the group under User groups, and click Save changes. You can also tick groups when you create the user. A group's own page does not list its members.
- From single sign-on. A JWT carries group developer names in a
groupsclaim, and SAML responses can carry them too. Raytha matches each name to an existing group. If at least one matches, the user's groups are replaced with exactly the matches, so a person removed from a group at your identity provider is removed in Raytha on their next sign-in. Names that match no group are ignored, and if none match, the user's groups are left alone.
Delete a group
Click Delete group on the group's page. Raytha refuses while any user is still in it ("Users are still assigned to this group. Unassign these users before deleting this group."). Remove the members first.
What groups do and do not do
A group is only a fact about a person. Raytha has no setting that says "this page is for the members group", and publishing a page makes it public to everyone. Groups matter in two places:
- Templates. Liquid can read
CurrentUser.IsAuthenticatedandCurrentUser.UserGroupsand show or hide parts of a page. - Raytha Functions. JavaScript can read the same
CurrentUserand refuse a request.
The next page shows how, including the limits. See Set up user groups for advanced public page access.
Gotchas
- Groups are read on each request. After you change someone's groups, their next page load reflects it. They do not need to sign out.
- Deleting a user does not delete a group, and deleting a group never deletes users.
- Turning off Email address and password for users also closes self-registration and password reset on the website. Single sign-on users are not affected.