mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 04:40:45 +08:00
fix(auth): provide bootstrap default admin password when unset
Fallback to a default bootstrap password for first login when env and stored secrets are empty, and document the behavior in system.env.example. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
9f4fa3d319
commit
61d2b87a30
2 changed files with 5 additions and 0 deletions
|
|
@ -47,6 +47,7 @@ AIA_ASSISTANT_MASTER_KEY=
|
|||
|
||||
# AIA_ASSISTANT_PASSWORD / OPS_ASSISTANT_PASSWORD 管理后台登录密码(旧名 OPS_* 兼容)。
|
||||
# 【前端】登录表单;环境变量常用于自动化部署注入初始密码。
|
||||
# 若两者与数据库 secret(auth_password) 都未配置,系统会回落到默认初始密码:admin123(建议首次登录后立即改密)。
|
||||
AIA_ASSISTANT_PASSWORD=
|
||||
OPS_ASSISTANT_PASSWORD=
|
||||
|
||||
|
|
|
|||
|
|
@ -6,6 +6,8 @@ import os
|
|||
|
||||
from oclaw.platform.persistence.sqlite_store import SqliteStore
|
||||
|
||||
_DEFAULT_BOOTSTRAP_PASSWORD = "admin123"
|
||||
|
||||
|
||||
def load_expected_password(store: SqliteStore, *, extra_candidate: str | None = None) -> str | None:
|
||||
pwd = (os.getenv("AIA_ASSISTANT_PASSWORD") or "").strip()
|
||||
|
|
@ -15,6 +17,8 @@ def load_expected_password(store: SqliteStore, *, extra_candidate: str | None =
|
|||
pwd = extra_candidate.strip()
|
||||
if not pwd:
|
||||
pwd = (store.get_secret("auth_password") or "").strip()
|
||||
if not pwd:
|
||||
pwd = _DEFAULT_BOOTSTRAP_PASSWORD
|
||||
return pwd if pwd else None
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue