fix(access): dev unlock defaults OFF

ACCESS_DEV_UNLOCK was opt-out (anything but 'false' enabled it) and
access.example.json shipped it on, so a gated production machine would
render a visible gate-bypass button on the lock screen by default. Flip
to opt-in (=== 'true'), update the example file and the provisioning
schema comment to match.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Padreug 2026-09-20 14:11:38 +02:00
commit 04767080a1
4 changed files with 8 additions and 7 deletions

View file

@ -1,5 +1,5 @@
{
"enabled": true,
"openEnrollment": true,
"devUnlock": true
"devUnlock": false
}

View file

@ -13,7 +13,7 @@
# {
# "enabled": true, // master switch for the gate
# "openEnrollment": true, // prototype: admit any valid npub
# "devUnlock": true, // allow the on-screen dev/operator unlock
# "devUnlock": false, // on-screen dev/operator unlock (bypasses the gate; default off)
# "salt": "per-machine", // hashing salt (provision a real one for prod)
# "allowList": [ // authorized identities (hashed); empty in open mode
# { "idHash": "<hashId(hexpubkey,salt)>", "role": "user", "pinHash": "<hashPin(pin,salt)>" }