[Auth] Make first-run account creation easy (no registration page, no default account) #3

Closed
opened 2026-08-23 11:04:31 +02:00 by vmruiz · 2 comments
Owner

Current behaviour

On first start there is no local account and no registration flow. Authentication is via OIDC or local login, but the first local user must be created manually from inside the container using the CLI (app/cli.py, a "create user" command that calls app/auth.py:create_local_user). There is no registration page in login.html and no default account is created. This forces someone to exec into the container and run commands before the web UI can be used, which is neither obvious nor convenient.

Desired behaviour

Make initial bootstrap clear and frictionless, without requiring shell access into the container:

  • Provide a guided path from the web to create the first account (username/password) when no user exists, or
  • Document and reliably automate creation of an initial default account on first start.

Goals

  • When the database has no users, show a "first-run" flow in the login page that lets the user create the first account (which must also be promoted to admins, as the first authentication already does per AGENTS.md: "The first-ever login ... is promoted to admins automatically").
  • Keep the current role model (admins/users), the Argon2id hashes, and the rest of the auth flow intact.
  • Do not leave an insecure default credential; the first account must be created unambiguously and safely.
  • Update the documentation (README) to describe the first-run flow.
  • Follow the UI conventions (login.html, app/static/app.css).
## Current behaviour On first start there is no local account and no registration flow. Authentication is via OIDC or local login, but the first local user must be created **manually from inside the container** using the CLI (`app/cli.py`, a "create user" command that calls `app/auth.py:create_local_user`). There is no registration page in `login.html` and no default account is created. This forces someone to exec into the container and run commands before the web UI can be used, which is neither obvious nor convenient. ## Desired behaviour Make initial bootstrap clear and frictionless, without requiring shell access into the container: - Provide a guided path from the web to create the first account (username/password) when no user exists, or - Document and reliably automate creation of an initial default account on first start. ## Goals - When the database has no users, show a "first-run" flow in the login page that lets the user create the first account (which must also be promoted to `admins`, as the first authentication already does per `AGENTS.md`: "The first-ever login ... is promoted to admins automatically"). - Keep the current role model (`admins`/`users`), the Argon2id hashes, and the rest of the auth flow intact. - Do not leave an insecure default credential; the first account must be created unambiguously and safely. - Update the documentation (README) to describe the first-run flow. - Follow the UI conventions (`login.html`, `app/static/app.css`).
vmruiz changed title from [Auth] Facilitar la creación de la primera cuenta al arrancar (sin login de registro ni cuenta por defecto) to [Auth] Make first-run account creation easy (no registration page, no default account) 2026-08-23 11:04:56 +02:00

Branch preview deployed by CI.

Auto-generated by .forgejo/workflows/dev-deploy.yml.

Branch preview deployed by CI. - Branch: `feat/first-run-setup` - Commit: `bf20c8be913e69dd1c994828d7af9800de49b9ea` - Endpoint: https://telegramarr-fa1036712.celor.es/ _Auto-generated by `.forgejo/workflows/dev-deploy.yml`._
Author
Owner

Merged via #14. First-run account creation is now available from the web UI: on a clean install the login page shows a "Create the first account" panel (POST /auth/setup) that creates the initial admin; the flow is gated by a DATA_DIR/.firstrun marker (created on boot only when the users table is empty, deleted after the first admin is created), so the external seed can coexist without interfering. No insecure default credential is ever created; password is Argon2id-hashed, preserving the admins/users role model. See PR #14 for full details and tests.

Merged via #14. First-run account creation is now available from the web UI: on a clean install the login page shows a "Create the first account" panel (POST /auth/setup) that creates the initial admin; the flow is gated by a DATA_DIR/.firstrun marker (created on boot only when the users table is empty, deleted after the first admin is created), so the external seed can coexist without interfering. No insecure default credential is ever created; password is Argon2id-hashed, preserving the admins/users role model. See PR #14 for full details and tests.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
vmruiz/telegramarr#3
No description provided.