Repository navigation
Commit ac819fd
committed
fix: stop inventing an Arcane password and keep the seeded login
The role minted its own admin password, so the credentials on a provisioned
box matched neither upstream's documentation nor anything a developer would
guess. The login is now exactly what Arcane ships with, and the role sets
neither the username nor the password.
What it still does is retire the forced first-login prompt, which is the part
worth automating. That needs a password submitted, because only a COMPLETED
change clears the flag -- an admin-side user update sets the password and
leaves it standing. So the change submits the seeded password as both the old
and the new value: the flag drops and the credentials do not move.
Upstream's default `strong` policy rejects its own seeded password (twelve
characters, but no uppercase and no digit), so the policy is relaxed to `basic`
first. Eight characters remains the floor regardless -- the request schema
rejects anything shorter with a 422 before the policy is read, which is why a
short password is not reachable by configuration at all.
The admin is now located by its global-admin flag rather than by the name
`arcane`, so a host whose admin was renamed is still found.
soe_arcane_admin_password is gone. The one knob left is
soe_arcane_password_policy, for putting the character-class requirements back.
Verified by destroying the container, its volume and the stack directory on
three hosts and installing clean. Each came up with username `arcane`,
failed=0 and rescued=0, and a real login as arcane/arcane-admin returns 200
with requiresPasswordChange false from /api/auth/me -- the endpoint the UI
itself calls, and the flag its root layout gates the change dialog on.1 parent 12733eb commit ac819fd
3 files changed
Lines changed: 27 additions & 27 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
175 | 175 | | |
176 | 176 | | |
177 | 177 | | |
178 | | - | |
| 178 | + | |
179 | 179 | | |
180 | 180 | | |
181 | 181 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
| 43 | + | |
43 | 44 | | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
57 | 51 | | |
58 | 52 | | |
59 | 53 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
176 | 176 | | |
177 | 177 | | |
178 | 178 | | |
| 179 | + | |
| 180 | + | |
179 | 181 | | |
180 | 182 | | |
181 | 183 | | |
182 | 184 | | |
183 | 185 | | |
184 | | - | |
| 186 | + | |
| 187 | + | |
185 | 188 | | |
186 | 189 | | |
187 | 190 | | |
188 | | - | |
189 | | - | |
190 | | - | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
191 | 194 | | |
192 | | - | |
| 195 | + | |
193 | 196 | | |
194 | 197 | | |
195 | 198 | | |
196 | 199 | | |
197 | 200 | | |
198 | | - | |
| 201 | + | |
199 | 202 | | |
200 | | - | |
201 | | - | |
202 | | - | |
| 203 | + | |
| 204 | + | |
203 | 205 | | |
204 | 206 | | |
205 | 207 | | |
206 | 208 | | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
207 | 214 | | |
208 | 215 | | |
209 | 216 | | |
| |||
212 | 219 | | |
213 | 220 | | |
214 | 221 | | |
215 | | - | |
216 | | - | |
| 222 | + | |
| 223 | + | |
217 | 224 | | |
218 | 225 | | |
219 | 226 | | |
220 | | - | |
221 | 227 | | |
222 | 228 | | |
223 | 229 | | |
| |||
0 commit comments