docs: correct the "default password123" claim — production nodes have none

The walkthrough told new users to log in with `password123` and said they'd
be "prompted to change this password immediately". Neither is true on a
release build:

- `AuthManager::ensure_default_user` is never called. `main.rs:356-362`
  says so explicitly ("Don't auto-create default user — let onboarding flow
  handle password setup via auth.setup"), and the function is `#[allow(dead_code)]`.
- The only `password123` login path is `api/rpc/auth.rs:36-46`, which is
  `#[cfg(debug_assertions)]` AND `dev_mode` AND only fires *before* setup —
  no release binary carries it.
- `Login.vue` calls `auth.isSetup` on mount and renders the "Set Up Your
  Node" password-creation form when it returns false. That is the real
  first-boot screen, and it is the only `auth.setup` caller in the frontend.

So there is nothing to be "prompted to change" — the user creates the
password themselves, and the doc's version taught them to look for a
default that does not exist.

Fixed in four places:
- user-walkthrough Step 8 rewritten as "Create Your Password"
- troubleshooting's "Default password is password123" solution replaced,
  including the warning that deleting user.json does NOT recover a lost
  password (the onboarding gate refuses auth.setup on a provisioned node)
- api-reference cURL example uses a placeholder, not the fake default
- 1.8.0 hardening plan's "kill default credentials" item now reflects that
  the web half is done and only the SSH defaults still ship

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-08-07 20:17:44 -04:00
co-authored by Claude Opus 5
parent e0cc41d31e
commit e7d8dfb633
4 changed files with 29 additions and 11 deletions
+8 -3
View File
@@ -301,9 +301,14 @@ media (latest artifact only one minor behind).
a failed regeneration keeps the baked keys instead of leaving the device keyless.
**Unverified on hardware**: needs one RC-ISO install to confirm the service fires
and sshd/nginx pick up the new keys.
- [ ] 🟠 **Kill default credentials.** `archipelago`/`archipelago` (SSH+root), web `password123`,
and SSH `PasswordAuthentication yes` (`:411`) all ship. Lock root, force credential
creation in onboarding, disable SSH password auth (or force-change on first login).
- [~] 🟠 **Kill default credentials.** The **web** default is GONE: no default account is
ever created (`main.rs:356-362` deliberately does not call `AuthManager::ensure_default_user`),
the login screen shows a password-creation form while `auth.isSetup` is false, and the
`password123` pre-setup bypass is `#[cfg(debug_assertions)]` + `dev_mode` (`api/rpc/auth.rs:36-46`),
so no release binary carries it. STILL SHIPPING: the SSH login
`archipelago`/`archipelago` (`image-recipe/archipelago-scripts/install-to-disk.sh:205`)
and SSH `PasswordAuthentication yes`. Lock root, disable SSH password auth (or
force-change on first login).
- [~] 🟠 **Sign + checksum the ISO.** Checksums DONE 2026-07-13 (`caf9e6d3`): the builder
emits `<iso>.sha256` after xorriso, and `scripts/sign-iso-checksums.sh` signs
`{artifact, sha256, size}` as a JSON doc with the release-root ceremony (verify with
+3 -2
View File
@@ -381,10 +381,11 @@ All endpoints use JSON-RPC over HTTP POST to `/rpc/v1`.
## Example: cURL
```bash
# Login
# Login (the password you created on the node's first-boot setup screen —
# there is no default password)
curl -c cookies.txt -X POST http://archipelago.local/rpc/v1 \
-H "Content-Type: application/json" \
-d '{"method":"auth.login","params":{"password":"password123"}}'
-d '{"method":"auth.login","params":{"password":"YOUR_NODE_PASSWORD"}}'
# Get system stats (authenticated)
curl -b cookies.txt -X POST http://archipelago.local/rpc/v1 \
+5 -1
View File
@@ -46,7 +46,11 @@ curl -s -X POST http://localhost:5678/rpc/v1 \
```
**Solutions**:
- Default password is `password123` — change it after first login
- There is no default password — the password is the one you created on this
node's first-boot "Set Up Your Node" screen. Password recovery requires SSH
access to the node; note that simply deleting `/var/lib/archipelago/user.json`
does **not** work, because the onboarding gate refuses `auth.setup` once the
node is provisioned
- Clear browser cookies and try again (stale session cookie)
- Restart the backend: `sudo systemctl restart archipelago`
- Check if the database is accessible: `ls -la /var/lib/archipelago/`
+13 -5
View File
@@ -91,13 +91,21 @@ The auto-installer handles everything:
2. Tap or click anywhere to proceed
3. A typing animation welcomes you: "Welcome, Noderunner"
### Step 8: Login Screen
### Step 8: Create Your Password
> **Screenshot**: The login screen with a password field and glass-morphism design.
> **Screenshot**: The "Set Up Your Node" screen with password and confirm-password fields, glass-morphism design.
1. Enter the default password: `password123`
2. Click "Login"
3. You'll be prompted to change this password immediately
**There is no default web password.** A freshly installed node has no user
account at all, so this screen shows a password-creation form rather than a
login form:
1. Enter a password (minimum 8 characters)
2. Confirm it in the second field
3. Click "Set Up Node"
Every boot after this one shows the normal login form and asks for the password
you chose here. Store it somewhere you can get back to — recovering it requires
SSH access to the node.
### Step 9: Choose Your Path (Onboarding)