Decision 46 recorded (setup gate spiked first); Part A: demo-hp bookstack + calibre-web admin passwords changed; R-710 filed
gates / gates (push) Successful in 26s
gates / gates (push) Successful in 26s
Passwords stored out-of-band (operator's credentials file); value scan clean before commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -497,6 +497,14 @@ R-636's louder repeated alarm.
|
||||
controller v0.279.0). Where it cannot, the app stays in the catalog; the install dialog and the app page say what
|
||||
the default login is and to change it at once. Operator: *"I don't think we should exclude apps if we can't change
|
||||
the first PW."* The per-app audit and status: `app-catalog-felhom.eu/FIRST-ADMIN.md`.
|
||||
46. **A setup gate for open-first-run apps is SPIKED before it is built** — *operator ruling 2026-09-29 ("I was leaning
|
||||
towards B, but let's test A").* The 34 class-4 apps let the first visitor create the admin. Option A: while such an
|
||||
app is not yet set up, the box lets only a person logged in to the household's dashboard reach it; the gate opens
|
||||
when the app's own status says an admin exists, or when the household presses "Done, I set it up". Option B: one
|
||||
fix per app (route (b), R-707). A is built only if the spike passes its exit test in writing; otherwise B continues
|
||||
and the spike's result is the recorded reason. Outcome: *(filled in by the 2026-09-29 session)*.
|
||||
Same day, operator: CC changes the admin passwords of demo-hp's installed bookstack and calibre-web and stores them
|
||||
in the operator's credentials file (not in any repo).
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user