Keep the web token out of the startup log

The daemon printed http://<bind>/?token=<token> at every start. The token
signs in as the admin, and in the container that line lands in docker
logs, readable by anyone with Docker access on Tower. It now says where
the token is kept instead; config.toml already has it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-19 14:27:06 +00:00
parent 680b5d4773
commit 3625cf48fb
2 changed files with 13 additions and 3 deletions

View File

@@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased] ## [Unreleased]
### Security
- The daemon no longer prints the web token when it starts, so it stays out of `docker logs`. It
says where the token is kept instead: `[web] token` in config.toml.
## [0.8.2] - 2026-09-19 ## [0.8.2] - 2026-09-19
### Added ### Added

View File

@@ -550,11 +550,16 @@ async fn start_web(
// The token is config.toml's, not the database's: it decides who gets in. // The token is config.toml's, not the database's: it decides who gets in.
fresh.save_bootstrap(config_path)?; fresh.save_bootstrap(config_path)?;
ctx.set_cfg(fresh.clone()); ctx.set_cfg(fresh.clone());
println!("web ui token generated. Open:\n http://{bind}/?token={}", fresh.web.token); // The token signs in as the admin, and whatever reads this process's output (docker logs,
// for one) is wider than who reads config.toml. So say where it is, never what it is.
println!(
"web ui token generated and saved to {} as [web] token. Open http://{bind}/?token=<that token>",
config_path.display()
);
} else { } else {
println!( println!(
"web ui at http://{bind}/?token={}", "web ui at http://{bind}/ (the sign-in token is [web] token in {})",
ctx.cfg().web.token config_path.display()
); );
} }