32 lines
2.5 KiB
Markdown
32 lines
2.5 KiB
Markdown
# D4 — R-694: what the app page shows as the password after a load or a restore
|
|
|
|
**The case.** The unit never carries a `type: password` admin login (D5). A restore whose guest has no
|
|
app.yaml — "Use my kept data", the restore of a removed app, a rebuilt guest — generates a new value
|
|
(`generated replacement for [NEXTCLOUD_ADMIN_PASSWORD]`, `night-2026-09-26/E/E5-5-use.txt`). The app page then
|
|
showed that value in the disabled password field, with the hint „Telepítéskor beállított kezdeti jelszó".
|
|
|
|
**Measured per app (2026-09-26, from each image's entrypoint at the catalog's tag, read-only; sources in
|
|
`upstream/`; two claims re-checked by hand: nextcloud `installed_version = 0.0.0.0` gate, code-server `--auth`):**
|
|
|
|
| app | uses the env value | after such a restore the login is |
|
|
|---|---|---|
|
|
| code-server | every start (`PASSWORD` → `code-server --auth password`, nothing stored) | the NEW value (shown value works) |
|
|
| crafty-controller | admin created only on a fresh install (`installer.is_fresh_install()`) | the OLD password in the data |
|
|
| gokapi | template seeds `config.json` only if absent | OLD |
|
|
| grafana | "can be changed before first start" (`defaults.ini`) | OLD |
|
|
| kimai | `kimai:user:create` every start, but it only creates (unique username) | OLD |
|
|
| nextcloud | only inside `if installed_version = 0.0.0.0` (first install) | OLD |
|
|
| paperless-ngx | `manage_superuser` skips when the user / a superuser exists | OLD |
|
|
|
|
**So the shown value was a password that does not work for six of the seven apps.** Not measured live (no
|
|
per-app deploy/remove/load cycle); the verdicts are from the upstream sources, confidence high per the table.
|
|
|
|
**Fix (controller v0.275.0).** `PersistUnitRedeployConfig` (the restore's app.yaml write) records in
|
|
`restored_logins` the `type: password` fields the guest held no value for before the write — i.e. the ones the
|
|
restore generated — except those in the code register `loginAppliedEveryStart` (code-server `PASSWORD`). The page
|
|
renders no value for them and says: „Mentésből töltötted vissza: a belépéshez a mentés idején érvényes jelszavad
|
|
kell. Az itt tárolt érték nem az, ezért nem mutatjuk." / "Restored from a backup: log in with the password that
|
|
was valid when the backup was taken. The value stored here is not it, so it is not shown." Tests:
|
|
`TestR694_ARestoreThatGeneratesTheLoginRecordsIt` (production write, 3 cases, red-proofed `RP-r694.txt`),
|
|
`TestR694_TheDeployPageDoesNotOfferAGeneratedLogin` (both languages; the Hungarian parity fixtures unchanged).
|