Add Certificates page and Traefik API frontend client
This commit is contained in:
parent
9e4c612dcb
commit
7fc90524b5
40 changed files with 6585 additions and 359 deletions
|
|
@ -1,11 +1,13 @@
|
|||
package database
|
||||
|
||||
import (
|
||||
"context"
|
||||
"database/sql"
|
||||
"fmt"
|
||||
"log"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"time"
|
||||
|
||||
_ "github.com/mattn/go-sqlite3"
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
|
|
@ -102,7 +104,7 @@ func (d *DB) ensureAdminUser() error {
|
|||
|
||||
// EnsureAdminPasswordViaEnv enforces production password policy.
|
||||
// If envPassword is set, it must be >=12 chars; it will create or update the admin user.
|
||||
// If devMode is false and the default admin/changeme is still in use, it logs a warning.
|
||||
// In production (devMode=false) without envPassword, startup fails if default password is still in use.
|
||||
func (d *DB) EnsureAdminPasswordViaEnv(envPassword string, devMode bool) error {
|
||||
if envPassword != "" {
|
||||
if len(envPassword) < 12 {
|
||||
|
|
@ -126,19 +128,38 @@ func (d *DB) EnsureAdminPasswordViaEnv(envPassword string, devMode bool) error {
|
|||
}
|
||||
|
||||
if !devMode {
|
||||
// Check if default password still in use
|
||||
// Fail startup if default password still in use — production must set GUI_ADMIN_PASSWORD
|
||||
var hash string
|
||||
err := d.QueryRow(`SELECT password_hash FROM users WHERE username='admin'`).Scan(&hash)
|
||||
if err == nil {
|
||||
// Compare against known dev hash
|
||||
if hash == "$2a$10$KsL.67hxLy.jwc50Uk7b3.dEmO1LNE3atnfUjNskAKlh9raiug4ju" {
|
||||
log.Println("WARNING: default admin password 'changeme' is in use — set GUI_ADMIN_PASSWORD (min 12 chars) for production")
|
||||
return fmt.Errorf("default admin password 'changeme' is not allowed in production: set GUI_ADMIN_PASSWORD (min 12 chars) or run with --dev")
|
||||
}
|
||||
// Also try bcrypt check in case hash was regenerated for same password
|
||||
if bcrypt.CompareHashAndPassword([]byte(hash), []byte("changeme")) == nil {
|
||||
log.Println("WARNING: admin password is still 'changeme' — change it or set GUI_ADMIN_PASSWORD for production")
|
||||
return fmt.Errorf("admin password is still 'changeme' in production: set GUI_ADMIN_PASSWORD (min 12 chars) or run with --dev")
|
||||
}
|
||||
} else if err != sql.ErrNoRows {
|
||||
return fmt.Errorf("check admin password: %w", err)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// StartSessionCleanup starts a background goroutine that periodically deletes expired sessions.
|
||||
// It uses the interval passed (typically auth.SessionCleanupInterval). The goroutine stops when ctx is cancelled.
|
||||
func (d *DB) StartSessionCleanup(ctx context.Context, interval time.Duration) {
|
||||
go func() {
|
||||
ticker := time.NewTicker(interval)
|
||||
defer ticker.Stop()
|
||||
// Run once at startup
|
||||
_, _ = d.Exec(`DELETE FROM sessions WHERE expires_at < ?`, time.Now())
|
||||
for {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return
|
||||
case <-ticker.C:
|
||||
_, _ = d.Exec(`DELETE FROM sessions WHERE expires_at < ?`, time.Now())
|
||||
}
|
||||
}
|
||||
}()
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue