Decision 46 recorded (setup gate spiked first); Part A: demo-hp bookstack + calibre-web admin passwords changed; R-710 filed
gates / gates (push) Successful in 26s
gates / gates (push) Successful in 26s
Passwords stored out-of-band (operator's credentials file); value scan clean before commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
== 2026-09-29T06:06:11Z BEFORE (the app's own login form, via traefik)
|
||||
bookstack admin@admin.com / <catalog default> -> 302->/ | wrong control -> 302->/login
|
||||
calibre-web admin / <catalog default> -> 302->/ | wrong control -> 200->
|
||||
== bookstack: artisan bookstack:create-admin --initial (the app's own command; keeps email + name)
|
||||
The default admin user has been updated with the provided details!
|
||||
rc=0
|
||||
== calibre-web: cps.py -s (the app's own command), as the app user abc
|
||||
Password for user 'admin' changed
|
||||
rc=0
|
||||
== 2026-09-29T06:06:16Z AFTER
|
||||
bookstack default -> 302->/login | new -> 302->/ | wrong control -> 302->/login
|
||||
calibre-web default -> 200-> | new -> 302->/ | wrong control -> 200->
|
||||
@@ -0,0 +1,13 @@
|
||||
# demo-hp 9201, 2026-09-29 ~06:10Z, controller 0.279.0: the app page (GET /apps/<app>, logged in), searched with the ASCII
|
||||
# fragment "ismert, k". Positive control: calibre-web/romm/mealie carry it. Negative control: bookstack does not.
|
||||
bookstack bytes 43386 warning: None
|
||||
calibre-web bytes 42081 warning: "ismert, közös jelszóval indul: admin / admin123. Telepítés után azonnal változtasd meg."
|
||||
romm bytes 41671 warning: "ismert, közös jelszóval indul: admin / admin. ..." (stale note — Part D3)
|
||||
mealie bytes 39898 warning: "ismert, közös jelszóval indul: changeme@example.com / MyPassword. ..."
|
||||
|
||||
FINDING (R-710): bookstack's page stopped warning BEFORE today's change. The catalog gained bookstack's after_install on
|
||||
2026-09-28; the installed app has no after_install record, and known_login.go reads an absent record as "not run yet"
|
||||
(line: `return cfg != nil && cfg.AfterInstall != nil && !cfg.AfterInstall.OK`). An app installed before its template
|
||||
gained an after_install is never run and never warned — its default login was live and unannounced from the catalog
|
||||
sync on 2026-09-28 until the change at 06:06Z today.
|
||||
calibre-web still warns after the change: known_login.go only knows after_install records (brief Part A4).
|
||||
@@ -0,0 +1,24 @@
|
||||
# Part A (2026-09-29, operator ruling): change the admin passwords of demo-hp's INSTALLED bookstack and calibre-web
|
||||
# through each app's own route. Passwords arrive on STDIN (line 1 bookstack, line 2 calibre-web); never printed.
|
||||
set -u
|
||||
DOM=enkisfelhom.hu; J=/tmp/partA-jar.$$
|
||||
read -r PB; read -r PC
|
||||
bs() { rm -f $J; T=$(curl -sk -c $J -b $J -H "Host: wiki.$DOM" https://127.0.0.1/login | grep -o 'name="_token" value="[^"]*"' | head -1 | sed 's/.*value="//;s/"$//')
|
||||
curl -sk -o /dev/null -w '%{http_code}->%{redirect_url}' -c $J -b $J -H "Host: wiki.$DOM" -X POST --data-urlencode "_token=$T" --data-urlencode "email=admin@admin.com" --data-urlencode "password=$1" https://127.0.0.1/login | sed "s|https\?://[^/]*||"; }
|
||||
cw() { rm -f $J; T=$(curl -sk -c $J -b $J -H "Host: books.$DOM" https://127.0.0.1/login | grep -o 'name="csrf_token" value="[^"]*"' | head -1 | sed 's/.*value="//;s/"$//')
|
||||
curl -sk -o /dev/null -w '%{http_code}->%{redirect_url}' -c $J -b $J -H "Host: books.$DOM" -X POST --data-urlencode "csrf_token=$T" --data-urlencode "username=admin" --data-urlencode "password=$1" --data-urlencode "remember_me=on" https://127.0.0.1/login | sed "s|https\?://[^/]*||"; }
|
||||
red() { sed -e "s/$(printf '%s' "$PB" | sed 's/[.[\*^$/]/\\&/g')/<redacted>/g" -e "s/$(printf '%s' "$PC" | sed 's/[.[\*^$/]/\\&/g')/<redacted>/g"; }
|
||||
echo "== $(date -u +%FT%TZ) BEFORE (the app's own login form, via traefik)"
|
||||
echo "bookstack admin@admin.com / <catalog default> -> $(bs password) | wrong control -> $(bs wrongxyz123)"
|
||||
echo "calibre-web admin / <catalog default> -> $(cw admin123) | wrong control -> $(cw wrongxyz123)"
|
||||
echo "== bookstack: artisan bookstack:create-admin --initial (the app's own command; keeps email + name)"
|
||||
export NEWPW="$PB"
|
||||
docker exec -e NEWPW bookstack sh -c 'php /app/www/artisan bookstack:create-admin --initial --email=admin@admin.com --name=Admin --password="$NEWPW"' 2>&1 | red; echo "rc=${PIPESTATUS[0]}"
|
||||
echo "== calibre-web: cps.py -s (the app's own command), as the app user abc"
|
||||
export NEWPW="$PC"
|
||||
docker exec -u abc -e NEWPW calibre-web sh -c 'cd /app/calibre-web-automated && python3 cps.py -p /config/app.db -s "admin:$NEWPW"' 2>&1 | red | grep -viE 'ProxyFix|magic shelves|SESSION_COOKIE' ; echo "rc=${PIPESTATUS[0]}"
|
||||
unset NEWPW
|
||||
echo "== $(date -u +%FT%TZ) AFTER"
|
||||
echo "bookstack default -> $(bs password) | new -> $(bs "$PB") | wrong control -> $(bs wrongxyz123)"
|
||||
echo "calibre-web default -> $(cw admin123) | new -> $(cw "$PC") | wrong control -> $(cw wrongxyz123)"
|
||||
unset PB PC; rm -f $J
|
||||
Reference in New Issue
Block a user