From 9c5eae999980c67726a20b93e67f42d49764b3bf Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Thu, 1 Oct 2026 13:29:50 +0200 Subject: [PATCH] CHANGELOG + REPORT: calibre-web generated login name (decision 61); an installed app's template is not frozen (R-757) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CHANGELOG.md | 5 +++-- REPORT.md | 20 ++++++++++---------- 2 files changed, 13 insertions(+), 12 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a00d703..66a4a03 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,8 +8,9 @@ success line. Both values are their own arguments. Copy (hu + en) updated; the Hungarian freeze re-captured for these five strings only. Proven on 9202: name + password sign in (form and OPDS), `admin` refused, 40 wrong tries on `admin` and the household still in at once; the install hold covered the window (0 of 31 stranger tries). The lock itself stays. - An installed calibre-web is NOT renamed by this (its template is frozen until an Update, and `after_install` runs only - after a fresh install): demo-hp's was renamed by hand. + An installed calibre-web is NOT renamed by this (`after_install` runs only after a fresh install), and — corrected + the same day — its template is NOT frozen: it syncs, and the box then INVENTS an `ADMIN_USER` for it (R-757). demo-hp's + app was renamed by hand to the box's recorded name. ## Strangers cannot lock a whole household out of wger; three other apps measured (2026-10-01, afternoon) diff --git a/REPORT.md b/REPORT.md index ffe7794..b466502 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,12 +1,12 @@ -# REPORT — strangers and lockouts: wger fixed, three apps measured (2026-10-01, afternoon) +# REPORT — calibre-web's admin login name is generated at install (2026-10-01, late afternoon) -Full session report: `felhom.eu/REPORT-lockouts-2026-10-01.md`. +Full session report: `felhom.eu/REPORT-calibre-name-and-prune-2026-10-01.md`. -- **wger** `82fff32` (decision 58, decided by CC unattended — operator may reverse): axes by username, 5 min, database - handler. 9202: control — the second member locked by a stranger's 10 tries on `admin`; fixed — the second member fine, - admin in again at 7.5 min after one retry; a wrong password still refused. -- **BookStack, Grafana**: measured 1.0 and 5.0 min — unchanged (decisions 59, 60). -- **calibre-web-automated**: 40 wrong tries a day per name lock the form for the day (measured; a restart clears it) — - operator decision (a generated login name, or the limiter off). -- Found, not changed: wger runs `manage.py runserver` (no `WGER_USE_GUNICORN`) — R-755. -- Gates: `catalog_gates.py --fast wger` OK; pushed through the pre-push gates (no `--no-verify`). +- **`09` §3 decision 61** (operator) — catalog `e9f50b5`: `ADMIN_USER` (`type: secret`, `generate: "hex:5"`); `after_install` + renames `admin` in `app.db` (Calibre-Web has no rename command), sets the password with its own `cps.py -s`, proves both. + hu + en copy; the Hungarian freeze re-captured for the five changed calibre-web strings only; FIRST-ADMIN updated. +- **9202:** a stranger got in 0 of 31 times during the install hold; 40 wrong tries on `admin` → the household in at once + with its own name (form and OPDS); `admin` refused. +- **demo-hp:** renamed by hand; the box then injected its own `ADMIN_USER` for the installed app (R-757) — renamed again to + that value; the name is in the operator's credentials file only. +- Gates: `catalog_gates.py --fast calibre-web` OK; pushed through the pre-push gates (no `--no-verify`).