Decision 46 recorded (setup gate spiked first); Part A: demo-hp bookstack + calibre-web admin passwords changed; R-710 filed
gates / gates (push) Successful in 26s

Passwords stored out-of-band (operator's credentials file); value scan clean before commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-29 08:07:37 +02:00
parent 58226e9abb
commit 2b1cb246cf
5 changed files with 58 additions and 0 deletions
@@ -0,0 +1,12 @@
== 2026-09-29T06:06:11Z BEFORE (the app's own login form, via traefik)
bookstack admin@admin.com / <catalog default> -> 302->/ | wrong control -> 302->/login
calibre-web admin / <catalog default> -> 302->/ | wrong control -> 200->
== bookstack: artisan bookstack:create-admin --initial (the app's own command; keeps email + name)
The default admin user has been updated with the provided details!
rc=0
== calibre-web: cps.py -s (the app's own command), as the app user abc
Password for user 'admin' changed
rc=0
== 2026-09-29T06:06:16Z AFTER
bookstack default -> 302->/login | new -> 302->/ | wrong control -> 302->/login
calibre-web default -> 200-> | new -> 302->/ | wrong control -> 200->
@@ -0,0 +1,13 @@
# demo-hp 9201, 2026-09-29 ~06:10Z, controller 0.279.0: the app page (GET /apps/<app>, logged in), searched with the ASCII
# fragment "ismert, k". Positive control: calibre-web/romm/mealie carry it. Negative control: bookstack does not.
bookstack bytes 43386 warning: None
calibre-web bytes 42081 warning: "ismert, közös jelszóval indul: admin / admin123. Telepítés után azonnal változtasd meg."
romm bytes 41671 warning: "ismert, közös jelszóval indul: admin / admin. ..." (stale note — Part D3)
mealie bytes 39898 warning: "ismert, közös jelszóval indul: changeme@example.com / MyPassword. ..."
FINDING (R-710): bookstack's page stopped warning BEFORE today's change. The catalog gained bookstack's after_install on
2026-09-28; the installed app has no after_install record, and known_login.go reads an absent record as "not run yet"
(line: `return cfg != nil && cfg.AfterInstall != nil && !cfg.AfterInstall.OK`). An app installed before its template
gained an after_install is never run and never warned — its default login was live and unannounced from the catalog
sync on 2026-09-28 until the change at 06:06Z today.
calibre-web still warns after the change: known_login.go only knows after_install records (brief Part A4).
@@ -0,0 +1,24 @@
# Part A (2026-09-29, operator ruling): change the admin passwords of demo-hp's INSTALLED bookstack and calibre-web
# through each app's own route. Passwords arrive on STDIN (line 1 bookstack, line 2 calibre-web); never printed.
set -u
DOM=enkisfelhom.hu; J=/tmp/partA-jar.$$
read -r PB; read -r PC
bs() { rm -f $J; T=$(curl -sk -c $J -b $J -H "Host: wiki.$DOM" https://127.0.0.1/login | grep -o 'name="_token" value="[^"]*"' | head -1 | sed 's/.*value="//;s/"$//')
curl -sk -o /dev/null -w '%{http_code}->%{redirect_url}' -c $J -b $J -H "Host: wiki.$DOM" -X POST --data-urlencode "_token=$T" --data-urlencode "email=admin@admin.com" --data-urlencode "password=$1" https://127.0.0.1/login | sed "s|https\?://[^/]*||"; }
cw() { rm -f $J; T=$(curl -sk -c $J -b $J -H "Host: books.$DOM" https://127.0.0.1/login | grep -o 'name="csrf_token" value="[^"]*"' | head -1 | sed 's/.*value="//;s/"$//')
curl -sk -o /dev/null -w '%{http_code}->%{redirect_url}' -c $J -b $J -H "Host: books.$DOM" -X POST --data-urlencode "csrf_token=$T" --data-urlencode "username=admin" --data-urlencode "password=$1" --data-urlencode "remember_me=on" https://127.0.0.1/login | sed "s|https\?://[^/]*||"; }
red() { sed -e "s/$(printf '%s' "$PB" | sed 's/[.[\*^$/]/\\&/g')/<redacted>/g" -e "s/$(printf '%s' "$PC" | sed 's/[.[\*^$/]/\\&/g')/<redacted>/g"; }
echo "== $(date -u +%FT%TZ) BEFORE (the app's own login form, via traefik)"
echo "bookstack admin@admin.com / <catalog default> -> $(bs password) | wrong control -> $(bs wrongxyz123)"
echo "calibre-web admin / <catalog default> -> $(cw admin123) | wrong control -> $(cw wrongxyz123)"
echo "== bookstack: artisan bookstack:create-admin --initial (the app's own command; keeps email + name)"
export NEWPW="$PB"
docker exec -e NEWPW bookstack sh -c 'php /app/www/artisan bookstack:create-admin --initial --email=admin@admin.com --name=Admin --password="$NEWPW"' 2>&1 | red; echo "rc=${PIPESTATUS[0]}"
echo "== calibre-web: cps.py -s (the app's own command), as the app user abc"
export NEWPW="$PC"
docker exec -u abc -e NEWPW calibre-web sh -c 'cd /app/calibre-web-automated && python3 cps.py -p /config/app.db -s "admin:$NEWPW"' 2>&1 | red | grep -viE 'ProxyFix|magic shelves|SESSION_COOKIE' ; echo "rc=${PIPESTATUS[0]}"
unset NEWPW
echo "== $(date -u +%FT%TZ) AFTER"
echo "bookstack default -> $(bs password) | new -> $(bs "$PB") | wrong control -> $(bs wrongxyz123)"
echo "calibre-web default -> $(cw admin123) | new -> $(cw "$PC") | wrong control -> $(cw wrongxyz123)"
unset PB PC; rm -f $J