feat(auth): first-run account setup via .firstrun marker (refs #3) #14
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/first-run-setup"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Issue #3 - Make first-run account creation easy
Implements a guided, web-only first-run flow to create the initial admin account, with no container exec and no insecure default credential.
Approach: explicit setup gate (not "users table empty")
The seed (runs in the Forgejo deploy pipeline) may preload an admin, so basing the flow on count(User) == 0 would never trigger in seeded environments and is fragile on clean prod. Instead the app uses an explicit signal:
This lets the seed coexist: leave .firstrun absent to use the seeded account, or drop an empty DATA_DIR/.firstrun to force the guided flow for E2E testing on a seeded box.
Changes
Tests
No insecure default is created; the password is supplied through the form and hashed with Argon2id, preserving the admins/users role model.