claper: after_install replaces the seeded admin@claper.co / claper password with a generated one (decision 45, R-702)

Proven on 9202 with controller 0.279.0 (drill catalog c4cfb83): the default no longer authenticates, the
generated first password from the app page does, a wrong one does not; a restore keeps it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-28 18:47:37 +02:00
parent 82da54415c
commit 9dc8a0531d
+29 -2
View File
@@ -47,6 +47,16 @@ deploy_fields:
generate: "password:24"
locked_after_deploy: true
# `09` §3 decision 45 (R-702): claper seeds admin@claper.co / claper at every first start. The box replaces
# that password with this generated one right after the install (after_install below), and the app page
# shows it as the first password.
- env_var: ADMIN_PASSWORD
label: "Admin jelszó (admin@claper.co)"
type: password
generate: "password:24"
description: "Az első bejelentkezéshez: admin@claper.co és ez a jelszó. Utána a fiókodban módosítható."
locked_after_deploy: true
# --- App info (info page content) ---
app_info:
tagline: "Interaktív prezentáció - szavazás, kérdések és reakciók élőben"
@@ -59,13 +69,26 @@ app_info:
- 'PDF prezentációk feltöltése és megosztása'
- 'QR kód a közönség gyors csatlakozásához'
default_creds: "admin@claper.co / claper"
first_steps:
- 'Nyisd meg a present.DOMAIN címet a böngészőben'
- 'Hozd létre a fiókodat'
- 'Lépj be az admin@claper.co fiókkal és a Beállítások oldalon látható első jelszóval'
- 'Tölts fel egy PDF prezentációt'
- 'Oszd meg a kódot a közönséggel'
# --- After a fresh install (controller >= 0.279.0, decision 45) ---
# claper's OWN release CLI, in the running node: the seeded default admin's password becomes ADMIN_PASSWORD.
# Measured on 9202 2026-09-28: afterwards `admin@claper.co / claper` no longer authenticates.
after_install:
service: claper
env: [ADMIN_PASSWORD]
command:
- /app/bin/claper
- rpc
- 'u = Claper.Accounts.get_user_by_email("admin@claper.co"); r = if u, do: Claper.Accounts.update_user_password(u, "claper", %{password: "${ADMIN_PASSWORD}", password_confirmation: "${ADMIN_PASSWORD}"}), else: :no_default_admin; case r do {:ok, _} -> IO.puts("FELHOM_AFTER_INSTALL_OK"); other -> IO.puts("FELHOM_AFTER_INSTALL_FAILED #{inspect(other, limit: 3)}") end'
success: FELHOM_AFTER_INSTALL_OK
# --- Controller-side health probe ---
healthcheck:
checks:
@@ -86,9 +109,10 @@ i18n:
- 'Reactions and feedback as you go'
- 'Upload and share PDF presentations'
- 'A QR code, so the room can join quickly'
default_creds: 'admin@claper.co / claper'
first_steps:
- 'Open present.DOMAIN in your browser'
- 'Create your account'
- 'Sign in as admin@claper.co with the first password shown on the settings page'
- 'Upload a PDF presentation'
- 'Share the code with the room'
deploy_fields:
@@ -102,6 +126,9 @@ i18n:
label: 'Database password'
- env_var: SECRET_KEY_BASE
label: 'Encryption key'
- env_var: ADMIN_PASSWORD
label: 'Admin password (admin@claper.co)'
description: 'For the first sign-in: admin@claper.co and this password. Change it in your account afterwards.'
# update_ladder — the test record: one tested step per line, oldest first (JSON flow mappings,
# `09-update-architecture.md` §6.4 part 4). WRITTEN BY scripts/upgrade-test.py, never by hand;