oclaw/platform/config/passwords.py
oliver 61d2b87a30 fix(auth): provide bootstrap default admin password when unset
Fallback to a default bootstrap password for first login when env and stored secrets are empty, and document the behavior in system.env.example.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-06 17:38:18 +08:00

25 lines
787 B
Python
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

"""访问密码解析(环境变量 + 数据库);Streamlit secrets 在认证模块中处理。"""
from __future__ import annotations
import os
from oclaw.platform.persistence.sqlite_store import SqliteStore
_DEFAULT_BOOTSTRAP_PASSWORD = "admin123"
def load_expected_password(store: SqliteStore, *, extra_candidate: str | None = None) -> str | None:
pwd = (os.getenv("AIA_ASSISTANT_PASSWORD") or "").strip()
if not pwd:
pwd = (os.getenv("OPS_ASSISTANT_PASSWORD") or "").strip()
if not pwd and extra_candidate:
pwd = extra_candidate.strip()
if not pwd:
pwd = (store.get_secret("auth_password") or "").strip()
if not pwd:
pwd = _DEFAULT_BOOTSTRAP_PASSWORD
return pwd if pwd else None
__all__ = ["load_expected_password"]