From 04767080a1d259748e8cef691394d82950ae638f Mon Sep 17 00:00:00 2001 From: Padreug Date: Sun, 20 Sep 2026 14:11:38 +0200 Subject: [PATCH] fix(access): dev unlock defaults OFF ACCESS_DEV_UNLOCK was opt-out (anything but 'false' enabled it) and access.example.json shipped it on, so a gated production machine would render a visible gate-bypass button on the lock screen by default. Flip to opt-in (=== 'true'), update the example file and the provisioning schema comment to match. Co-Authored-By: Claude Fable 5.1 --- apps/machine/.env.example | 6 +++--- apps/machine/electron/main.ts | 5 +++-- deploy/nixos/access.example.json | 2 +- deploy/nixos/provision-access.sh | 2 +- 4 files changed, 8 insertions(+), 7 deletions(-) diff --git a/apps/machine/.env.example b/apps/machine/.env.example index 8748c21..8a62105 100644 --- a/apps/machine/.env.example +++ b/apps/machine/.env.example @@ -108,9 +108,9 @@ VITE_SPIRE_SEED= # Turn OFF once a real allow-list (/var/lib/bitspire/access.json) is provisioned. # ACCESS_OPEN_ENROLLMENT=true -# Allow the on-screen runtime dev/operator unlock button (default: allowed when -# the gate is on). Set to 'false' to hide it on a locked-down deployment. -# ACCESS_DEV_UNLOCK=false +# Show the on-screen runtime dev/operator unlock button on the locked screen. +# Default OFF — it bypasses the gate, so enable only on a bench/dev machine. +# ACCESS_DEV_UNLOCK=true # Per-machine salt for hashing credentials/PINs. Provision a real value in # production (or in access.json); a fixed default is used if unset. diff --git a/apps/machine/electron/main.ts b/apps/machine/electron/main.ts index 736d89d..018cef6 100644 --- a/apps/machine/electron/main.ts +++ b/apps/machine/electron/main.ts @@ -181,8 +181,9 @@ function loadAccessControl() { // deployed machine by dropping a file + restarting the service, with no image // rebuild. Defaults OFF. let enabled = process.env.ACCESS_CONTROL_ENABLED === 'true' - // Dev unlock allowed by default when the gate is on; opt out explicitly. - let devUnlock = process.env.ACCESS_DEV_UNLOCK !== 'false' + // Dev unlock is OFF unless explicitly enabled: a gated machine must not ship + // a visible bypass button by default. + let devUnlock = process.env.ACCESS_DEV_UNLOCK === 'true' let openEnrollment = process.env.ACCESS_OPEN_ENROLLMENT === 'true' let salt = process.env.ACCESS_SALT || '' let allowList: AccessAllowListEntry[] = [] diff --git a/deploy/nixos/access.example.json b/deploy/nixos/access.example.json index 7f20fcf..2001e5d 100644 --- a/deploy/nixos/access.example.json +++ b/deploy/nixos/access.example.json @@ -1,5 +1,5 @@ { "enabled": true, "openEnrollment": true, - "devUnlock": true + "devUnlock": false } diff --git a/deploy/nixos/provision-access.sh b/deploy/nixos/provision-access.sh index 72dd12b..6eeb357 100755 --- a/deploy/nixos/provision-access.sh +++ b/deploy/nixos/provision-access.sh @@ -13,7 +13,7 @@ # { # "enabled": true, // master switch for the gate # "openEnrollment": true, // prototype: admit any valid npub -# "devUnlock": true, // allow the on-screen dev/operator unlock +# "devUnlock": false, // on-screen dev/operator unlock (bypasses the gate; default off) # "salt": "per-machine", // hashing salt (provision a real one for prod) # "allowList": [ // authorized identities (hashed); empty in open mode # { "idHash": "", "role": "user", "pinHash": "" }