fix(access): dev unlock defaults OFF
ACCESS_DEV_UNLOCK was opt-out (anything but 'false' enabled it) and access.example.json shipped it on, so a gated production machine would render a visible gate-bypass button on the lock screen by default. Flip to opt-in (=== 'true'), update the example file and the provisioning schema comment to match. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
5114619fce
commit
04767080a1
4 changed files with 8 additions and 7 deletions
|
|
@ -108,9 +108,9 @@ VITE_SPIRE_SEED=
|
|||
# Turn OFF once a real allow-list (/var/lib/bitspire/access.json) is provisioned.
|
||||
# ACCESS_OPEN_ENROLLMENT=true
|
||||
|
||||
# Allow the on-screen runtime dev/operator unlock button (default: allowed when
|
||||
# the gate is on). Set to 'false' to hide it on a locked-down deployment.
|
||||
# ACCESS_DEV_UNLOCK=false
|
||||
# Show the on-screen runtime dev/operator unlock button on the locked screen.
|
||||
# Default OFF — it bypasses the gate, so enable only on a bench/dev machine.
|
||||
# ACCESS_DEV_UNLOCK=true
|
||||
|
||||
# Per-machine salt for hashing credentials/PINs. Provision a real value in
|
||||
# production (or in access.json); a fixed default is used if unset.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue