# B.1 FileBrowser Quantum admin-password spike — 2026-09-15, scratch LXC 9202 on demo-hp
# Throwaway containers fbspike-fresh / fbspike-existing on 127.0.0.1:18089 inside the guest; config rendered like RenderFileBrowserConfig; same entrypoint wrapper as RenderFileBrowserCompose.
# Generated passwords redacted: only length printed. Login probe = POST /api/auth/login?username=admin, header X-Password.
# 'tr: write error: Broken pipe' lines are the password generator (harmless).

2026-09-15T07:36:38Z
image: gtstef/filebrowser:1.3.3-stable
sha256:095fd20d87be10c175a5fa614aa1d0a94aa07eafa80f251a3069640e0a7c51f7
== A1 FRESH db, config key auth.adminPassword
tr: write error: Broken pipe
  pw len=16
  admin/admin -> 401
  admin/<P1> -> 200
  admin/wrong -> 401
2026/09/15 07:36:39 [INFO ] Auth Methods             : [password]
2026/09/15 07:36:39 [INFO ] Resetting admin user to default username and password.
2026/09/15 07:36:40[33m POST    | 401 | 172.17.0.1      | N/A          | 72ms         | "/api/auth/login?username=admin"[0m
2026/09/15 07:36:40 POST    | 200 | 172.17.0.1      | N/A          | 80ms         | "/api/auth/login?username=admin"
2026/09/15 07:36:40[33m POST    | 401 | 172.17.0.1      | N/A          | 63ms         | "/api/auth/login?username=admin"[0m
== A2 FRESH db, env FILEBROWSER_ADMIN_PASSWORD (no config key)
tr: write error: Broken pipe
  pw len=16
  admin/admin -> 401
  admin/<P2> -> 200
== A3 FRESH db, NO key, NO env (today's controller shape)
  admin/admin -> 200
  admin/wrong -> 401
== A4 short password via config key (length rule)
  (not ready)
2026/09/15 07:36:45 [INFO ] cache directory setup successfully: tmp
2026/09/15 07:36:45[31m [FATAL] store.Users.Save: password must be at least 5 characters long[0m
2026/09/15 07:36:45 [DEBUG] Default SQLite driver initialized
2026/09/15 07:36:45 [WARN ] database file could not be found. If this is unexpected, please set the FILEBROWSER_DATABASE environment variable to the correct path.
  admin/abc -> 000
  admin/admin -> 000
2026/09/15 07:36:45[31m [FATAL] store.Users.Save: password must be at least 5 characters long[0m
== B0 EXISTING db: create with defaults
  admin/admin -> 200  (baseline, expect 200)
== B1 EXISTING db + config key added, restart
tr: write error: Broken pipe
  pw len=16
  admin/admin -> 401
  admin/<P3> -> 200
== B2 EXISTING db + env var, restart (config key removed)
tr: write error: Broken pipe
  admin/admin -> 401
  admin/<P3> -> 401
  admin/<P3E env> -> 200
== B3 EXISTING db: CLI 'set -u admin,<pw>' with container stopped
tr: write error: Broken pipe
2026/09/15 07:37:51 [DEBUG] Default SQLite driver initialized
2026/09/15 07:37:51 [INFO ] cache directory setup successfully: tmp
successfully updated user: admin
  rc=0
  admin/admin -> 401
  admin/<P3> -> 401
  admin/<P3E> -> 401
  admin/<P4> -> 200
== B4 EXISTING db: CLI 'set' via docker exec on RUNNING container
tr: write error: Broken pipe
2026/09/15 07:37:53 [DEBUG] Default SQLite driver initialized
2026/09/15 07:37:54 [INFO ] cache directory setup successfully: tmp
2026/09/15 07:37:54[31m the database is locked, please close all other instances of filebrowser before starting.[0m
  admin/<P4> -> 200
  admin/<P5> -> 401
  after restart: admin/<P4> -> 200
  admin/<P5> -> 401
== C OVERWRITE: hand-set pw (current db state) + config key with a DIFFERENT value, restart
  (db currently holds whichever of P4/P5 answered 200 above)
tr: write error: Broken pipe
  admin/<P4> -> 401
  admin/<P5> -> 401
  admin/<P6 config> -> 200
  admin/admin -> 401
== C2 same via env var with a DIFFERENT value
tr: write error: Broken pipe
  admin/<P5> -> 401
  admin/<P6> -> 401
  admin/<P7 env> -> 200
== TEARDOWN
0
ls: cannot access '/tmp/fbspike': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:38:07Z

######## PART 2 — REST API change attempt WITHOUT X-Password (refused), restart survival
2026-09-15T07:38:40Z
== D0 existing db, defaults
  admin/admin -> 200
  token len=355
  GET /api/users?id=self -> {"editorQuickSave":false,"hideSidebarFileActions":false,"disableQuickToggles":false,"disableSearchOptions":false,"deleteWithoutConfirming":false,"preview":{"disableHideSidebar":false,"image":true,"video":true,"audio":true,"motionVideoPreview":true,"office":true,"popup":true,"autoplayMedia":true,"defaultMediaPlayer":false,"folder":true,"models":true},"stickySidebar":true,"darkMode":true,"locale":"e
  new pw len=13
  PUT form1 /api/users?id=1 -> 401 {"status":401,"message":"X-Password header is required to confirm your password"}
    admin/admin -> 200  admin/<new> -> 401
  PUT form2 /api/users?id=1 -> 401 {"status":401,"message":"X-Password header is required to confirm your password"}
    admin/admin -> 200  admin/<new> -> 401
  PUT form3 /api/users?id=self -> 400 {"status":400,"message":"no user not found, please provide a valid id or username"}
    admin/admin -> 200  admin/<new> -> 401
== D1 restart with NO key, NO env: does the API-set password survive?
  admin/admin -> 200  admin/<new> -> 401
2026/09/15 07:38:40 [INFO ] Resetting admin user to default username and password.
== TEARDOWN
0
ls: cannot access '/tmp/fbspike2': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:38:44Z

######## PART 3 — REST API change WITH X-Password: <current>, restart with no key, then key with different value
# (the 'Resetting admin user' line under D1 is from the container's FIRST start — docker logs keeps history across restart; the measured logins show no reset)
2026-09-15T07:39:00Z
== D0 existing db, defaults
  admin/admin -> 200
  token len=355
  GET /api/users?id=self -> {"editorQuickSave":false,"hideSidebarFileActions":false,"disableQuickToggles":false,"disableSearchOptions":false,"deleteWithoutConfirming":false,"preview":{"disableHideSidebar":false,"image":true,"video":true,"audio":true,"motionVideoPreview":true,"office":true,"popup":true,"autoplayMedia":true,"defaultMediaPlayer":false,"folder":true,"models":true},"stickySidebar":true,"darkMode":true,"locale":"e
  new pw len=16
  PUT form1 /api/users?id=1 -> 204 
    admin/admin -> 401  admin/<new> -> 200
== D1 restart with NO key, NO env (hand-set via API): does the API-set password survive?
  admin/admin -> 401  admin/<new> -> 200
2026/09/15 07:39:01 [INFO ] Resetting admin user to default username and password.
== D2 same db, now add config key with DIFFERENT value, restart (operator hand-set vs key)
  key pw len=16
  admin/<hand-set> -> 401  admin/<key> -> 200  admin/admin -> 401
== TEARDOWN
0
ls: cannot access '/tmp/fbspike2': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:39:06Z

######## SUMMARY (measured, image gtstef/filebrowser:1.3.3-stable)
(a) FRESH db: config.yaml `auth: adminPassword: <pw>` (A1) OR env FILEBROWSER_ADMIN_PASSWORD (A2) sets it at first start: admin/admin 401, <pw> 200. No key/no env (today's shape, A3): admin/admin 200.
(b) EXISTING db (admin/admin 200 proven): the SAME config key (B1) or env var (B2) re-applies on restart: admin/admin 401, new 200. CLI `filebrowser set -u admin,<pw> -a` works only with the container STOPPED (B3: 200); on a running container it fails "database is locked" (B4, no change). REST: PUT /api/users?id=1 {"which":["password"],"data":{"id":1,"username":"admin","password":"<pw>"}} with Bearer token AND header X-Password: <current password> -> 204 (D0); without X-Password -> 401 "X-Password header is required".
OVERWRITE: with the key (C, D2) or env (C2) present, EVERY start resets the admin password to the configured value — a hand-set password (CLI or API) is overwritten (hand-set 401, key 200). With NO key/env, a hand-set password survives restart (B3->B4 restart, D1).
Length rule: min 5 chars; a shorter configured value is FATAL at start ("store.Users.Save: password must be at least 5 characters long", container never serves — A4). 16-char alphanumeric accepted.
TEARDOWN: fbspike-* containers removed, /tmp/fbspike* removed in 9202 (0 fbspike containers listed); 9202's own `filebrowser` untouched (Up 35 hours throughout).
