[Auth] Make first-run account creation easy (no registration page, no default account) #3
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Current behaviour
On first start there is no local account and no registration flow. Authentication is via OIDC or local login, but the first local user must be created manually from inside the container using the CLI (
app/cli.py, a "create user" command that callsapp/auth.py:create_local_user). There is no registration page inlogin.htmland no default account is created. This forces someone to exec into the container and run commands before the web UI can be used, which is neither obvious nor convenient.Desired behaviour
Make initial bootstrap clear and frictionless, without requiring shell access into the container:
Goals
admins, as the first authentication already does perAGENTS.md: "The first-ever login ... is promoted to admins automatically").admins/users), the Argon2id hashes, and the rest of the auth flow intact.login.html,app/static/app.css).[Auth] Facilitar la creación de la primera cuenta al arrancar (sin login de registro ni cuenta por defecto)to [Auth] Make first-run account creation easy (no registration page, no default account)Branch preview deployed by CI.
feat/first-run-setupbf20c8be913e69dd1c994828d7af9800de49b9eaAuto-generated by
.forgejo/workflows/dev-deploy.yml.Merged via #14. First-run account creation is now available from the web UI: on a clean install the login page shows a "Create the first account" panel (POST /auth/setup) that creates the initial admin; the flow is gated by a DATA_DIR/.firstrun marker (created on boot only when the users table is empty, deleted after the first admin is created), so the external seed can coexist without interfering. No insecure default credential is ever created; password is Argon2id-hashed, preserving the admins/users role model. See PR #14 for full details and tests.