fix(auth): provide bootstrap default admin password when unset

Fallback to a default bootstrap password for first login when env and stored secrets are empty, and document the behavior in system.env.example.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-05-06 17:38:18 +08:00
parent 9f4fa3d319
commit 61d2b87a30
2 changed files with 5 additions and 0 deletions

View file

@ -6,6 +6,8 @@ import os
from oclaw.platform.persistence.sqlite_store import SqliteStore
_DEFAULT_BOOTSTRAP_PASSWORD = "admin123"
def load_expected_password(store: SqliteStore, *, extra_candidate: str | None = None) -> str | None:
pwd = (os.getenv("AIA_ASSISTANT_PASSWORD") or "").strip()
@ -15,6 +17,8 @@ def load_expected_password(store: SqliteStore, *, extra_candidate: str | None =
pwd = extra_candidate.strip()
if not pwd:
pwd = (store.get_secret("auth_password") or "").strip()
if not pwd:
pwd = _DEFAULT_BOOTSTRAP_PASSWORD
return pwd if pwd else None