docs: correct the "default password123" claim — production nodes have none
The walkthrough told new users to log in with `password123` and said they'd
be "prompted to change this password immediately". Neither is true on a
release build:
- `AuthManager::ensure_default_user` is never called. `main.rs:356-362`
says so explicitly ("Don't auto-create default user — let onboarding flow
handle password setup via auth.setup"), and the function is `#[allow(dead_code)]`.
- The only `password123` login path is `api/rpc/auth.rs:36-46`, which is
`#[cfg(debug_assertions)]` AND `dev_mode` AND only fires *before* setup —
no release binary carries it.
- `Login.vue` calls `auth.isSetup` on mount and renders the "Set Up Your
Node" password-creation form when it returns false. That is the real
first-boot screen, and it is the only `auth.setup` caller in the frontend.
So there is nothing to be "prompted to change" — the user creates the
password themselves, and the doc's version taught them to look for a
default that does not exist.
Fixed in four places:
- user-walkthrough Step 8 rewritten as "Create Your Password"
- troubleshooting's "Default password is password123" solution replaced,
including the warning that deleting user.json does NOT recover a lost
password (the onboarding gate refuses auth.setup on a provisioned node)
- api-reference cURL example uses a placeholder, not the fake default
- 1.8.0 hardening plan's "kill default credentials" item now reflects that
the web half is done and only the SSH defaults still ship
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
e0cc41d31e
commit
e7d8dfb633
@@ -301,9 +301,14 @@ media (latest artifact only one minor behind).
|
||||
a failed regeneration keeps the baked keys instead of leaving the device keyless.
|
||||
**Unverified on hardware**: needs one RC-ISO install to confirm the service fires
|
||||
and sshd/nginx pick up the new keys.
|
||||
- [ ] 🟠 **Kill default credentials.** `archipelago`/`archipelago` (SSH+root), web `password123`,
|
||||
and SSH `PasswordAuthentication yes` (`:411`) all ship. Lock root, force credential
|
||||
creation in onboarding, disable SSH password auth (or force-change on first login).
|
||||
- [~] 🟠 **Kill default credentials.** The **web** default is GONE: no default account is
|
||||
ever created (`main.rs:356-362` deliberately does not call `AuthManager::ensure_default_user`),
|
||||
the login screen shows a password-creation form while `auth.isSetup` is false, and the
|
||||
`password123` pre-setup bypass is `#[cfg(debug_assertions)]` + `dev_mode` (`api/rpc/auth.rs:36-46`),
|
||||
so no release binary carries it. STILL SHIPPING: the SSH login
|
||||
`archipelago`/`archipelago` (`image-recipe/archipelago-scripts/install-to-disk.sh:205`)
|
||||
and SSH `PasswordAuthentication yes`. Lock root, disable SSH password auth (or
|
||||
force-change on first login).
|
||||
- [~] 🟠 **Sign + checksum the ISO.** Checksums DONE 2026-07-13 (`caf9e6d3`): the builder
|
||||
emits `<iso>.sha256` after xorriso, and `scripts/sign-iso-checksums.sh` signs
|
||||
`{artifact, sha256, size}` as a JSON doc with the release-root ceremony (verify with
|
||||
|
||||
@@ -381,10 +381,11 @@ All endpoints use JSON-RPC over HTTP POST to `/rpc/v1`.
|
||||
## Example: cURL
|
||||
|
||||
```bash
|
||||
# Login
|
||||
# Login (the password you created on the node's first-boot setup screen —
|
||||
# there is no default password)
|
||||
curl -c cookies.txt -X POST http://archipelago.local/rpc/v1 \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{"method":"auth.login","params":{"password":"password123"}}'
|
||||
-d '{"method":"auth.login","params":{"password":"YOUR_NODE_PASSWORD"}}'
|
||||
|
||||
# Get system stats (authenticated)
|
||||
curl -b cookies.txt -X POST http://archipelago.local/rpc/v1 \
|
||||
|
||||
@@ -46,7 +46,11 @@ curl -s -X POST http://localhost:5678/rpc/v1 \
|
||||
```
|
||||
|
||||
**Solutions**:
|
||||
- Default password is `password123` — change it after first login
|
||||
- There is no default password — the password is the one you created on this
|
||||
node's first-boot "Set Up Your Node" screen. Password recovery requires SSH
|
||||
access to the node; note that simply deleting `/var/lib/archipelago/user.json`
|
||||
does **not** work, because the onboarding gate refuses `auth.setup` once the
|
||||
node is provisioned
|
||||
- Clear browser cookies and try again (stale session cookie)
|
||||
- Restart the backend: `sudo systemctl restart archipelago`
|
||||
- Check if the database is accessible: `ls -la /var/lib/archipelago/`
|
||||
|
||||
@@ -91,13 +91,21 @@ The auto-installer handles everything:
|
||||
2. Tap or click anywhere to proceed
|
||||
3. A typing animation welcomes you: "Welcome, Noderunner"
|
||||
|
||||
### Step 8: Login Screen
|
||||
### Step 8: Create Your Password
|
||||
|
||||
> **Screenshot**: The login screen with a password field and glass-morphism design.
|
||||
> **Screenshot**: The "Set Up Your Node" screen with password and confirm-password fields, glass-morphism design.
|
||||
|
||||
1. Enter the default password: `password123`
|
||||
2. Click "Login"
|
||||
3. You'll be prompted to change this password immediately
|
||||
**There is no default web password.** A freshly installed node has no user
|
||||
account at all, so this screen shows a password-creation form rather than a
|
||||
login form:
|
||||
|
||||
1. Enter a password (minimum 8 characters)
|
||||
2. Confirm it in the second field
|
||||
3. Click "Set Up Node"
|
||||
|
||||
Every boot after this one shows the normal login form and asks for the password
|
||||
you chose here. Store it somewhere you can get back to — recovering it requires
|
||||
SSH access to the node.
|
||||
|
||||
### Step 9: Choose Your Path (Onboarding)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user