From e7d8dfb633636eb6f67b23f1835cbe50bdd117b2 Mon Sep 17 00:00:00 2001 From: archipelago Date: Fri, 7 Aug 2026 20:17:44 -0400 Subject: [PATCH] =?UTF-8?q?docs:=20correct=20the=20"default=20password123"?= =?UTF-8?q?=20claim=20=E2=80=94=20production=20nodes=20have=20none?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The walkthrough told new users to log in with `password123` and said they'd be "prompted to change this password immediately". Neither is true on a release build: - `AuthManager::ensure_default_user` is never called. `main.rs:356-362` says so explicitly ("Don't auto-create default user — let onboarding flow handle password setup via auth.setup"), and the function is `#[allow(dead_code)]`. - The only `password123` login path is `api/rpc/auth.rs:36-46`, which is `#[cfg(debug_assertions)]` AND `dev_mode` AND only fires *before* setup — no release binary carries it. - `Login.vue` calls `auth.isSetup` on mount and renders the "Set Up Your Node" password-creation form when it returns false. That is the real first-boot screen, and it is the only `auth.setup` caller in the frontend. So there is nothing to be "prompted to change" — the user creates the password themselves, and the doc's version taught them to look for a default that does not exist. Fixed in four places: - user-walkthrough Step 8 rewritten as "Create Your Password" - troubleshooting's "Default password is password123" solution replaced, including the warning that deleting user.json does NOT recover a lost password (the onboarding gate refuses auth.setup on a provisioned node) - api-reference cURL example uses a placeholder, not the fake default - 1.8.0 hardening plan's "kill default credentials" item now reflects that the web half is done and only the SSH defaults still ship Co-Authored-By: Claude Opus 5 (1M context) --- docs/1.8.0-RELEASE-HARDENING-PLAN.md | 11 ++++++++--- docs/api-reference.md | 5 +++-- docs/troubleshooting.md | 6 +++++- docs/user-walkthrough.md | 18 +++++++++++++----- 4 files changed, 29 insertions(+), 11 deletions(-) diff --git a/docs/1.8.0-RELEASE-HARDENING-PLAN.md b/docs/1.8.0-RELEASE-HARDENING-PLAN.md index 550c6e7b..ca50ecb6 100644 --- a/docs/1.8.0-RELEASE-HARDENING-PLAN.md +++ b/docs/1.8.0-RELEASE-HARDENING-PLAN.md @@ -301,9 +301,14 @@ media (latest artifact only one minor behind). a failed regeneration keeps the baked keys instead of leaving the device keyless. **Unverified on hardware**: needs one RC-ISO install to confirm the service fires and sshd/nginx pick up the new keys. -- [ ] 🟠 **Kill default credentials.** `archipelago`/`archipelago` (SSH+root), web `password123`, - and SSH `PasswordAuthentication yes` (`:411`) all ship. Lock root, force credential - creation in onboarding, disable SSH password auth (or force-change on first login). +- [~] 🟠 **Kill default credentials.** The **web** default is GONE: no default account is + ever created (`main.rs:356-362` deliberately does not call `AuthManager::ensure_default_user`), + the login screen shows a password-creation form while `auth.isSetup` is false, and the + `password123` pre-setup bypass is `#[cfg(debug_assertions)]` + `dev_mode` (`api/rpc/auth.rs:36-46`), + so no release binary carries it. STILL SHIPPING: the SSH login + `archipelago`/`archipelago` (`image-recipe/archipelago-scripts/install-to-disk.sh:205`) + and SSH `PasswordAuthentication yes`. Lock root, disable SSH password auth (or + force-change on first login). - [~] 🟠 **Sign + checksum the ISO.** Checksums DONE 2026-07-13 (`caf9e6d3`): the builder emits `.sha256` after xorriso, and `scripts/sign-iso-checksums.sh` signs `{artifact, sha256, size}` as a JSON doc with the release-root ceremony (verify with diff --git a/docs/api-reference.md b/docs/api-reference.md index b2657f1d..08567d82 100644 --- a/docs/api-reference.md +++ b/docs/api-reference.md @@ -381,10 +381,11 @@ All endpoints use JSON-RPC over HTTP POST to `/rpc/v1`. ## Example: cURL ```bash -# Login +# Login (the password you created on the node's first-boot setup screen — +# there is no default password) curl -c cookies.txt -X POST http://archipelago.local/rpc/v1 \ -H "Content-Type: application/json" \ - -d '{"method":"auth.login","params":{"password":"password123"}}' + -d '{"method":"auth.login","params":{"password":"YOUR_NODE_PASSWORD"}}' # Get system stats (authenticated) curl -b cookies.txt -X POST http://archipelago.local/rpc/v1 \ diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index 70079225..075fcd10 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -46,7 +46,11 @@ curl -s -X POST http://localhost:5678/rpc/v1 \ ``` **Solutions**: -- Default password is `password123` — change it after first login +- There is no default password — the password is the one you created on this + node's first-boot "Set Up Your Node" screen. Password recovery requires SSH + access to the node; note that simply deleting `/var/lib/archipelago/user.json` + does **not** work, because the onboarding gate refuses `auth.setup` once the + node is provisioned - Clear browser cookies and try again (stale session cookie) - Restart the backend: `sudo systemctl restart archipelago` - Check if the database is accessible: `ls -la /var/lib/archipelago/` diff --git a/docs/user-walkthrough.md b/docs/user-walkthrough.md index 502cce4f..b50b1860 100644 --- a/docs/user-walkthrough.md +++ b/docs/user-walkthrough.md @@ -91,13 +91,21 @@ The auto-installer handles everything: 2. Tap or click anywhere to proceed 3. A typing animation welcomes you: "Welcome, Noderunner" -### Step 8: Login Screen +### Step 8: Create Your Password -> **Screenshot**: The login screen with a password field and glass-morphism design. +> **Screenshot**: The "Set Up Your Node" screen with password and confirm-password fields, glass-morphism design. -1. Enter the default password: `password123` -2. Click "Login" -3. You'll be prompted to change this password immediately +**There is no default web password.** A freshly installed node has no user +account at all, so this screen shows a password-creation form rather than a +login form: + +1. Enter a password (minimum 8 characters) +2. Confirm it in the second field +3. Click "Set Up Node" + +Every boot after this one shows the normal login form and asks for the password +you chose here. Store it somewhere you can get back to — recovering it requires +SSH access to the node. ### Step 9: Choose Your Path (Onboarding)