diff --git a/CHANGELOG.md b/CHANGELOG.md index 740bee0..6edce1d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Security + +- The daemon no longer prints the web token when it starts, so it stays out of `docker logs`. It + says where the token is kept instead: `[web] token` in config.toml. + ## [0.8.2] - 2026-09-19 ### Added diff --git a/src/main.rs b/src/main.rs index 4a0286d..c5e29eb 100644 --- a/src/main.rs +++ b/src/main.rs @@ -550,11 +550,16 @@ async fn start_web( // The token is config.toml's, not the database's: it decides who gets in. fresh.save_bootstrap(config_path)?; ctx.set_cfg(fresh.clone()); - println!("web ui token generated. Open:\n http://{bind}/?token={}", fresh.web.token); + // The token signs in as the admin, and whatever reads this process's output (docker logs, + // for one) is wider than who reads config.toml. So say where it is, never what it is. + println!( + "web ui token generated and saved to {} as [web] token. Open http://{bind}/?token=", + config_path.display() + ); } else { println!( - "web ui at http://{bind}/?token={}", - ctx.cfg().web.token + "web ui at http://{bind}/ (the sign-in token is [web] token in {})", + config_path.display() ); }