From 61d2b87a3081babb45cd003b54de83714e174161 Mon Sep 17 00:00:00 2001 From: oliver Date: Wed, 6 May 2026 17:38:18 +0800 Subject: [PATCH] fix(auth): provide bootstrap default admin password when unset Fallback to a default bootstrap password for first login when env and stored secrets are empty, and document the behavior in system.env.example. Co-authored-by: Cursor --- _local/system.env.example | 1 + platform/config/passwords.py | 4 ++++ 2 files changed, 5 insertions(+) diff --git a/_local/system.env.example b/_local/system.env.example index 0a63dd12..95a90463 100644 --- a/_local/system.env.example +++ b/_local/system.env.example @@ -47,6 +47,7 @@ AIA_ASSISTANT_MASTER_KEY= # AIA_ASSISTANT_PASSWORD / OPS_ASSISTANT_PASSWORD 管理后台登录密码(旧名 OPS_* 兼容)。 # 【前端】登录表单;环境变量常用于自动化部署注入初始密码。 +# 若两者与数据库 secret(auth_password) 都未配置,系统会回落到默认初始密码:admin123(建议首次登录后立即改密)。 AIA_ASSISTANT_PASSWORD= OPS_ASSISTANT_PASSWORD= diff --git a/platform/config/passwords.py b/platform/config/passwords.py index c9adf7c2..f47dd2ad 100644 --- a/platform/config/passwords.py +++ b/platform/config/passwords.py @@ -6,6 +6,8 @@ import os from oclaw.platform.persistence.sqlite_store import SqliteStore +_DEFAULT_BOOTSTRAP_PASSWORD = "admin123" + def load_expected_password(store: SqliteStore, *, extra_candidate: str | None = None) -> str | None: pwd = (os.getenv("AIA_ASSISTANT_PASSWORD") or "").strip() @@ -15,6 +17,8 @@ def load_expected_password(store: SqliteStore, *, extra_candidate: str | None = pwd = extra_candidate.strip() if not pwd: pwd = (store.get_secret("auth_password") or "").strip() + if not pwd: + pwd = _DEFAULT_BOOTSTRAP_PASSWORD return pwd if pwd else None