diff --git a/docs/1.8.0-RELEASE-HARDENING-PLAN.md b/docs/1.8.0-RELEASE-HARDENING-PLAN.md index 550c6e7b..ca50ecb6 100644 --- a/docs/1.8.0-RELEASE-HARDENING-PLAN.md +++ b/docs/1.8.0-RELEASE-HARDENING-PLAN.md @@ -301,9 +301,14 @@ media (latest artifact only one minor behind). a failed regeneration keeps the baked keys instead of leaving the device keyless. **Unverified on hardware**: needs one RC-ISO install to confirm the service fires and sshd/nginx pick up the new keys. -- [ ] 🟠 **Kill default credentials.** `archipelago`/`archipelago` (SSH+root), web `password123`, - and SSH `PasswordAuthentication yes` (`:411`) all ship. Lock root, force credential - creation in onboarding, disable SSH password auth (or force-change on first login). +- [~] 🟠 **Kill default credentials.** The **web** default is GONE: no default account is + ever created (`main.rs:356-362` deliberately does not call `AuthManager::ensure_default_user`), + the login screen shows a password-creation form while `auth.isSetup` is false, and the + `password123` pre-setup bypass is `#[cfg(debug_assertions)]` + `dev_mode` (`api/rpc/auth.rs:36-46`), + so no release binary carries it. STILL SHIPPING: the SSH login + `archipelago`/`archipelago` (`image-recipe/archipelago-scripts/install-to-disk.sh:205`) + and SSH `PasswordAuthentication yes`. Lock root, disable SSH password auth (or + force-change on first login). - [~] 🟠 **Sign + checksum the ISO.** Checksums DONE 2026-07-13 (`caf9e6d3`): the builder emits `.sha256` after xorriso, and `scripts/sign-iso-checksums.sh` signs `{artifact, sha256, size}` as a JSON doc with the release-root ceremony (verify with diff --git a/docs/api-reference.md b/docs/api-reference.md index b2657f1d..08567d82 100644 --- a/docs/api-reference.md +++ b/docs/api-reference.md @@ -381,10 +381,11 @@ All endpoints use JSON-RPC over HTTP POST to `/rpc/v1`. ## Example: cURL ```bash -# Login +# Login (the password you created on the node's first-boot setup screen — +# there is no default password) curl -c cookies.txt -X POST http://archipelago.local/rpc/v1 \ -H "Content-Type: application/json" \ - -d '{"method":"auth.login","params":{"password":"password123"}}' + -d '{"method":"auth.login","params":{"password":"YOUR_NODE_PASSWORD"}}' # Get system stats (authenticated) curl -b cookies.txt -X POST http://archipelago.local/rpc/v1 \ diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index 70079225..075fcd10 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -46,7 +46,11 @@ curl -s -X POST http://localhost:5678/rpc/v1 \ ``` **Solutions**: -- Default password is `password123` — change it after first login +- There is no default password — the password is the one you created on this + node's first-boot "Set Up Your Node" screen. Password recovery requires SSH + access to the node; note that simply deleting `/var/lib/archipelago/user.json` + does **not** work, because the onboarding gate refuses `auth.setup` once the + node is provisioned - Clear browser cookies and try again (stale session cookie) - Restart the backend: `sudo systemctl restart archipelago` - Check if the database is accessible: `ls -la /var/lib/archipelago/` diff --git a/docs/user-walkthrough.md b/docs/user-walkthrough.md index 502cce4f..b50b1860 100644 --- a/docs/user-walkthrough.md +++ b/docs/user-walkthrough.md @@ -91,13 +91,21 @@ The auto-installer handles everything: 2. Tap or click anywhere to proceed 3. A typing animation welcomes you: "Welcome, Noderunner" -### Step 8: Login Screen +### Step 8: Create Your Password -> **Screenshot**: The login screen with a password field and glass-morphism design. +> **Screenshot**: The "Set Up Your Node" screen with password and confirm-password fields, glass-morphism design. -1. Enter the default password: `password123` -2. Click "Login" -3. You'll be prompted to change this password immediately +**There is no default web password.** A freshly installed node has no user +account at all, so this screen shows a password-creation form rather than a +login form: + +1. Enter a password (minimum 8 characters) +2. Confirm it in the second field +3. Click "Set Up Node" + +Every boot after this one shows the normal login form and asks for the password +you chose here. Store it somewhere you can get back to — recovering it requires +SSH access to the node. ### Step 9: Choose Your Path (Onboarding)