Keep the web token out of the startup log
The daemon printed http://<bind>/?token=<token> at every start. The token signs in as the admin, and in the container that line lands in docker logs, readable by anyone with Docker access on Tower. It now says where the token is kept instead; config.toml already has it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
### Security
|
||||
|
||||
- The daemon no longer prints the web token when it starts, so it stays out of `docker logs`. It
|
||||
says where the token is kept instead: `[web] token` in config.toml.
|
||||
|
||||
## [0.8.2] - 2026-09-19
|
||||
|
||||
### Added
|
||||
|
||||
11
src/main.rs
11
src/main.rs
@@ -550,11 +550,16 @@ async fn start_web(
|
||||
// The token is config.toml's, not the database's: it decides who gets in.
|
||||
fresh.save_bootstrap(config_path)?;
|
||||
ctx.set_cfg(fresh.clone());
|
||||
println!("web ui token generated. Open:\n http://{bind}/?token={}", fresh.web.token);
|
||||
// The token signs in as the admin, and whatever reads this process's output (docker logs,
|
||||
// for one) is wider than who reads config.toml. So say where it is, never what it is.
|
||||
println!(
|
||||
"web ui token generated and saved to {} as [web] token. Open http://{bind}/?token=<that token>",
|
||||
config_path.display()
|
||||
);
|
||||
} else {
|
||||
println!(
|
||||
"web ui at http://{bind}/?token={}",
|
||||
ctx.cfg().web.token
|
||||
"web ui at http://{bind}/ (the sign-in token is [web] token in {})",
|
||||
config_path.display()
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user