Skip to content

fix: remove CLI credential timeout and password complexity limits - #20

Merged
MengMengCode merged 1 commit into
masterfrom
fix/cli-admin-timeout
Aug 14, 2026
Merged

MengMengCode merged 1 commit into
masterfrom
fix/cli-admin-timeout

Conversation

@MengMengCode

@MengMengCode MengMengCode commented Aug 14, 2026 •

Copy link
Copy Markdown
Owner

remove CLI credential timeout and password complexity limits

Copilot AI lite review requested due to automatic review settings August 14, 2026 14:45
@MengMengCode
MengMengCode merged commit 1ef928d into master Aug 14, 2026
8 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the previous CLI/admin password length/complexity constraints and fixes bcrypt’s 72-byte input limitation by introducing a tagged SHA-256 pre-hash for longer passwords, ensuring long passwords can still be used and verified safely.

Changes:

  • Replace legacy password length checks with an ErrEmptyPassword sentinel and accept short/long passwords.
  • Add hashPassword / comparePassword helpers to support passwords longer than bcrypt’s 72-byte limit via a tagged SHA-256 pre-hash.
  • Remove the CLI menu’s 30s timeout for the reset-credentials flow and update prompts accordingly; extend tests to cover new accepted password shapes.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
internal/server/general_api.go Maps empty-password errors via errors.Is instead of fragile substring matching.
internal/auth/service.go Removes old length rules; introduces tagged pre-hash + compare helpers for long passwords; adds ErrEmptyPassword.
internal/auth/service_test.go Adds coverage to ensure short and long passwords are accepted and can authenticate.
cmd/vocat/menu.go Removes the 30s timeout for reset-admin flow and updates password prompt text.
cmd/vocat/bootstrap_admin.go Removes length validation and the stdin read limit while bootstrapping admin credentials.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +26 to 34
reader := bufio.NewReader(os.Stdin)
password, err := reader.ReadString('\n')
if err != nil && !errors.Is(err, io.EOF) {
return fmt.Errorf("read password: %w", err)
}
password = strings.TrimSuffix(strings.TrimSuffix(password, "\n"), "\r")
if len(password) < 6 || len(password) > 1024 {
return errors.New("bootstrap password must contain between 6 and 1024 characters")
if password == "" {
return errors.New("bootstrap password cannot be empty")
}
@MengMengCode
MengMengCode deleted the fix/cli-admin-timeout branch August 14, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants