Using Timber
Users & roles
Timber has accounts for the people who run the site — not for members or subscribers. The public site has no sign-up and no visitor accounts. Everyone signs in at /padmin with an email and password.
The three roles#
| Administrator | Editor | Read-only | |
|---|---|---|---|
| Dashboard | ✅ full | ✅ their posts | ✅ full (view) |
| Posts — write, edit, publish, schedule, delete | ✅ | ✅ | 👁 view |
| Media — upload and add alt text | ✅ | ✅ | 👁 view |
| Delete media files | ✅ | — | — |
| Pages, Playground (designs), Forms, Menus, Blocks | ✅ | — | 👁 view |
| Design, SEO, Privacy, Site settings, Redirects | ✅ | — | 👁 view |
| Emails, Integrations, Data, Files, Code editor, Migrator | ✅ | — | — |
| Users — add, change roles, disable, delete | ✅ | — | — |
| Their own profile and password | ✅ | ✅ | ✅ |
- Administrator can do everything.
- Editor can only manage posts (and upload the images those posts need). They can't touch pages, design, forms, settings or other people's accounts.
- Read-only can look around — dashboard, posts, pages, designs, form submissions, SEO and other settings screens — but every change is switched off, both in the screens and on the server. Perfect for a stakeholder, an auditor or a client who wants to see but not touch. They can't open screens that expose raw data or secrets (Emails, Integrations, Data, Files, Code editor).
Managing users#
Admin → Users (also under Admin Tools):
- Add user: name, email, role and a starting password. Use Generate a strong password, then share it with them securely. They can change it from Your profile.
- Edit: change name, email or role, set a new password, or disable the account to block sign-in without deleting it.
- Delete: removes the account.
Safeguards#
- There is always at least one active administrator: you can't demote, disable or delete the last one.
- You can't disable or delete yourself.
- Emails are unique.
- Changing someone's password (or yours) signs that account out everywhere else. Disabling an account ends its sessions immediately.
Signing in#
- Email + password at
/padmin, with the same throttling as before: 5 wrong tries from an IP locks sign-in for 10 minutes. - Sessions last up to 8 hours idle or 7 days total.
- Your profile (bottom of the sidebar) lets everyone change their name, email and password.
Upgrading from a single-passcode install#
If you had a site from before accounts existed, nothing breaks. The first time Timber runs it converts your old passcode into one Administrator account: the email is your admin/site email from the settings, and the password is your existing passcode. Sign in with that, then add colleagues.
Locked out?#
On the server:
php _dev/reset-password.php "new password" # first active administrator
php _dev/reset-password.php [email protected] "new password" # a specific account
php _dev/reset-password.php --add-admin [email protected] "password" # create an administratorWhat roles don't cover#
Roles are about the admin. They don't (yet) support per-page permissions, "authors can only edit their own posts", approval workflows or an audit log. See the roadmap.