cfd337a673
The admin password field is gone from both the create-user and
edit-user forms. Three flows now generate a password and mail it
instead of letting an admin type one:
- create_user(): password generated, welcome email sent
(login/password/portal link) right after the row commits
- new POST /api/admin/users/{id}/reset-password: generates a new
password, saves it, emails it - the only way a password changes now
- assign_rdp_slot(): sending a user their first grant on a pilot
(not every later tweak of an existing grant's expiry - guarded by
an is_new_grant check) sends a short "you have pilot access" email,
no credentials since the account already exists
If an email fails to send, the plaintext password comes back in the
API response as a one-time fallback so the admin isn't locked out of
handing it over by hand - the frontend only shows it then, never on
a successful send.
Added two small helpers (_build_light_email, _credentials_table) so
these three new templates share the light-theme card shell instead
of re-typing it; the existing access-approval emails keep their own
inline copies untouched.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>