# D4 — R-694: what the app page shows as the password after a load or a restore **The case.** The unit never carries a `type: password` admin login (D5). A restore whose guest has no app.yaml — "Use my kept data", the restore of a removed app, a rebuilt guest — generates a new value (`generated replacement for [NEXTCLOUD_ADMIN_PASSWORD]`, `night-2026-09-26/E/E5-5-use.txt`). The app page then showed that value in the disabled password field, with the hint „Telepítéskor beállított kezdeti jelszó". **Measured per app (2026-09-26, from each image's entrypoint at the catalog's tag, read-only; sources in `upstream/`; two claims re-checked by hand: nextcloud `installed_version = 0.0.0.0` gate, code-server `--auth`):** | app | uses the env value | after such a restore the login is | |---|---|---| | code-server | every start (`PASSWORD` → `code-server --auth password`, nothing stored) | the NEW value (shown value works) | | crafty-controller | admin created only on a fresh install (`installer.is_fresh_install()`) | the OLD password in the data | | gokapi | template seeds `config.json` only if absent | OLD | | grafana | "can be changed before first start" (`defaults.ini`) | OLD | | kimai | `kimai:user:create` every start, but it only creates (unique username) | OLD | | nextcloud | only inside `if installed_version = 0.0.0.0` (first install) | OLD | | paperless-ngx | `manage_superuser` skips when the user / a superuser exists | OLD | **So the shown value was a password that does not work for six of the seven apps.** Not measured live (no per-app deploy/remove/load cycle); the verdicts are from the upstream sources, confidence high per the table. **Fix (controller v0.275.0).** `PersistUnitRedeployConfig` (the restore's app.yaml write) records in `restored_logins` the `type: password` fields the guest held no value for before the write — i.e. the ones the restore generated — except those in the code register `loginAppliedEveryStart` (code-server `PASSWORD`). The page renders no value for them and says: „Mentésből töltötted vissza: a belépéshez a mentés idején érvényes jelszavad kell. Az itt tárolt érték nem az, ezért nem mutatjuk." / "Restored from a backup: log in with the password that was valid when the backup was taken. The value stored here is not it, so it is not shown." Tests: `TestR694_ARestoreThatGeneratesTheLoginRecordsIt` (production write, 3 cases, red-proofed `RP-r694.txt`), `TestR694_TheDeployPageDoesNotOfferAGeneratedLogin` (both languages; the Hungarian parity fixtures unchanged).