docs: correct the "default password123" claim — production nodes have none

The walkthrough told new users to log in with `password123` and said they'd
be "prompted to change this password immediately". Neither is true on a
release build:

- `AuthManager::ensure_default_user` is never called. `main.rs:356-362`
  says so explicitly ("Don't auto-create default user — let onboarding flow
  handle password setup via auth.setup"), and the function is `#[allow(dead_code)]`.
- The only `password123` login path is `api/rpc/auth.rs:36-46`, which is
  `#[cfg(debug_assertions)]` AND `dev_mode` AND only fires *before* setup —
  no release binary carries it.
- `Login.vue` calls `auth.isSetup` on mount and renders the "Set Up Your
  Node" password-creation form when it returns false. That is the real
  first-boot screen, and it is the only `auth.setup` caller in the frontend.

So there is nothing to be "prompted to change" — the user creates the
password themselves, and the doc's version taught them to look for a
default that does not exist.

Fixed in four places:
- user-walkthrough Step 8 rewritten as "Create Your Password"
- troubleshooting's "Default password is password123" solution replaced,
  including the warning that deleting user.json does NOT recover a lost
  password (the onboarding gate refuses auth.setup on a provisioned node)
- api-reference cURL example uses a placeholder, not the fake default
- 1.8.0 hardening plan's "kill default credentials" item now reflects that
  the web half is done and only the SSH defaults still ship

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
archipelago
2026-08-07 20:17:44 -04:00
co-authored by Claude Opus 5
parent e0cc41d31e
commit e7d8dfb633
4 changed files with 29 additions and 11 deletions
+13 -5
View File
@@ -91,13 +91,21 @@ The auto-installer handles everything:
2. Tap or click anywhere to proceed
3. A typing animation welcomes you: "Welcome, Noderunner"
### Step 8: Login Screen
### Step 8: Create Your Password
> **Screenshot**: The login screen with a password field and glass-morphism design.
> **Screenshot**: The "Set Up Your Node" screen with password and confirm-password fields, glass-morphism design.
1. Enter the default password: `password123`
2. Click "Login"
3. You'll be prompted to change this password immediately
**There is no default web password.** A freshly installed node has no user
account at all, so this screen shows a password-creation form rather than a
login form:
1. Enter a password (minimum 8 characters)
2. Confirm it in the second field
3. Click "Set Up Node"
Every boot after this one shows the normal login form and asks for the password
you chose here. Store it somewhere you can get back to — recovering it requires
SSH access to the node.
### Step 9: Choose Your Path (Onboarding)