feat(server): randomize the seeded admin initial password (#172)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Yaowei Zheng
2026-08-04 16:50:46 +08:00
committed by GitHub
parent e05dea536b
commit 045ac250e0
35 changed files with 302 additions and 58 deletions
+1 -1
View File
@@ -108,7 +108,7 @@ Each family's latest generation only — the app's **Models** page lists every b
## Installation
Every route installs the same `penguin` command: `penguin web` launches the full Web experience (multi-session chat, agent/skill/model management, usage stats, Trace observability, evaluation center; first login admin / penguin-2026 — change the password right after), and models are configured on the in-app Models page. The online installers bundle their own Node runtime — unpack and run; upgrades and reinstalls never touch your data.
Every route installs the same `penguin` command: `penguin web` launches the full Web experience (multi-session chat, agent/skill/model management, usage stats, Trace observability, evaluation center; first login is `admin` with the initial password printed on the server's first start, of the form `penguin-1234` — change it right after), and models are configured on the in-app Models page. The online installers bundle their own Node runtime — unpack and run; upgrades and reinstalls never touch your data.
### 🐧 Linux (online install)
+1 -1
View File
@@ -108,7 +108,7 @@ https://github.com/user-attachments/assets/aec49ae9-b743-467b-b247-37bedfeaa36e
## 安装
每种方式装出的都是同一个 `penguin` 命令:`penguin web` 启动完整 Web 体验(多会话对话、Agent / 技能 / 模型管理、用量统计、轨迹观测、评估中心;首次登录 admin / penguin-2026,登录后请尽快修改密码),在应用内模型页配置模型后即可对话。在线安装器自带 Node 运行时,解压即用,升级与重装不触碰数据。
每种方式装出的都是同一个 `penguin` 命令:`penguin web` 启动完整 Web 体验(多会话对话、Agent / 技能 / 模型管理、用量统计、轨迹观测、评估中心;首次登录使用 `admin`,初始密码在服务端首次启动时打印,形如 `penguin-1234`,登录后请尽快修改密码),在应用内模型页配置模型后即可对话。在线安装器自带 Node 运行时,解压即用,升级与重装不触碰数据。
### 🐧 Linux(在线安装)
+1 -1
View File
@@ -442,5 +442,5 @@ if ($PathUpdateMessage) {
Write-Host ""
Write-Host "Get started:"
Write-Host " penguin --help # all commands"
Write-Host " penguin web # start the Web UI at http://127.0.0.1:7364 (initial login: admin / penguin-2026)"
Write-Host " penguin web # start the Web UI at http://127.0.0.1:7364 (login: admin, initial password printed on first start)"
Write-Host " penguin server # headless server (PORT / HOST to override)"
+1 -1
View File
@@ -441,5 +441,5 @@ fi
echo ""
echo "Get started:"
echo " penguin --help # all commands"
echo " penguin web # start the Web UI at http://127.0.0.1:7364 (initial login: admin / penguin-2026)"
echo " penguin web # start the Web UI at http://127.0.0.1:7364 (login: admin, initial password printed on first start)"
echo " penguin server # headless server (PORT / HOST to override)"
@@ -17,6 +17,7 @@ The CLI and the server automatically load a `.env` file from the working directo
| `PENGUIN_WEB_DB` | Server SQLite database path | `<root>/web.db` |
| `PENGUIN_WEB_DIST` | Front-end static assets directory | the npm server package falls back to its bundled web-dist |
| `PENGUIN_PREVIEW_ORIGIN` | Origin that serves Workspace HTML previews, e.g. `https://preview.example.com` | unset — the loopback counterpart is derived per request |
| `PENGUIN_SEED_ADMIN_PASSWORD` | Fixed initial password for the seeded built-in admin (automated tests / e2e) | unset — a random `penguin-<4 digits>` password is generated and printed once at seed time |
| `PENGUIN_LANG` | CLI language (`en` / `zh`), set via `penguin config lang` | `en` |
| `PENGUIN_UPDATE_CHECK` | `off` disables the web app's new-release check (the server's only outbound internet call) | enabled |
@@ -17,6 +17,7 @@ CLI 与服务端启动时会自动加载工作目录下的 `.env` 文件。
| `PENGUIN_WEB_DB` | 服务端 SQLite 数据库路径 | `<root>/web.db` |
| `PENGUIN_WEB_DIST` | 前端静态资源目录 | npm 安装的服务端包回退到内置 web-dist |
| `PENGUIN_PREVIEW_ORIGIN` | 提供 Workspace HTML 预览的独立源,如 `https://preview.example.com` | 未设置,按请求推导回环对应名 |
| `PENGUIN_SEED_ADMIN_PASSWORD` | 固定内置管理员的种子初始密码(自动化测试 / e2e 使用) | 未设置,种子时随机生成 `penguin-<四位数字>` 并打印一次 |
| `PENGUIN_LANG` | CLI 语言(`en` / `zh`),用 `penguin config lang` 设置 | `en` |
| `PENGUIN_UPDATE_CHECK` | 设为 `off` 关闭 Web 应用的新版本检查(服务端唯一的对外网络请求) | 开启 |
+1 -1
View File
@@ -30,7 +30,7 @@ penguin config model add --provider deepseek --model-id deepseek-v4-flash --api-
penguin web
```
The service runs at http://127.0.0.1:7364 and opens your browser (`--no-open` to skip). First login is `admin` / `penguin-2026` — change it right away. `penguin server` starts the same process headless.
The service runs at http://127.0.0.1:7364 and opens your browser (`--no-open` to skip). First login is `admin` — the server prints the initial password (of the form `penguin-1234`) on first start; change it right away. `penguin server` starts the same process headless.
## One-shot run
+1 -1
View File
@@ -30,7 +30,7 @@ penguin config model add --provider deepseek --model-id deepseek-v4-flash --api-
penguin web
```
服务运行在 http://127.0.0.1:7364 并自动打开浏览器(`--no-open` 跳过)。首次登录使用 `admin` / `penguin-2026`,请立即修改密码。`penguin server` 启动同一进程的 headless 版本。
服务运行在 http://127.0.0.1:7364 并自动打开浏览器(`--no-open` 跳过)。首次登录使用 `admin`,初始密码(形如 `penguin-1234`)在服务端首次启动时打印,请立即修改密码。`penguin server` 启动同一进程的 headless 版本。
## 单次运行
+3 -2
View File
@@ -35,12 +35,13 @@ packages/server/src
- Cookie session: `penguin_session` (HttpOnly, SameSite=Lax), valid for 7 days with sliding renewal;
- Passwords are stored as scrypt hashes; the server keeps only the sha256 of the session token, never the plaintext;
- No open registration: the built-in admin `admin` / `penguin-2026` is seeded at startup, and all other accounts are created by an admin;
- No open registration: the built-in admin `admin` is seeded at startup with a random initial password (of the form `penguin-1234`) printed once to the server console — `PENGUIN_SEED_ADMIN_PASSWORD` pins it for automation — and all other accounts are created by an admin;
- Same-origin only — no CORS middleware is enabled.
```bash
# Use the initial password printed at first start (or your changed one).
curl -c cookies.txt -H "Content-Type: application/json" \
-d '{"userId":"admin","password":"penguin-2026"}' \
-d '{"userId":"admin","password":"penguin-1234"}' \
http://127.0.0.1:7364/api/auth/login
```
+3 -2
View File
@@ -35,12 +35,13 @@ packages/server/src
- Cookie 会话:`penguin_session`(HttpOnly、SameSite=Lax),有效期 7 天,滑动续期;
- 密码以 scrypt 哈希存储;服务端只保存会话 Token 的 sha256,不落明文;
- 不开放注册:启动时种子化内置管理员 `admin` / `penguin-2026`,其余账号由管理员创建;
- 不开放注册:启动时种子化内置管理员 `admin`,初始密码随机生成(形如 `penguin-1234`)并仅在种子当次打印到服务端控制台——自动化可用 `PENGUIN_SEED_ADMIN_PASSWORD` 固定——其余账号由管理员创建;
- 仅限同源访问,未启用 CORS 中间件。
```bash
# 密码用首次启动时打印的初始密码(或改过之后的密码)。
curl -c cookies.txt -H "Content-Type: application/json" \
-d '{"userId":"admin","password":"penguin-2026"}' \
-d '{"userId":"admin","password":"penguin-1234"}' \
http://127.0.0.1:7364/api/auth/login
```
+1 -1
View File
@@ -23,7 +23,7 @@ penguin web
# open http://127.0.0.1:7364
```
The initial account is `admin` / `penguin-2026`. There is no self-registration: accounts are created by an admin on the user-management page, and every new user automatically gets an independent initial Project named `<userId>-default_project`. While the initial password is still in use, a banner prompts the user to change it.
The initial account is `admin`; its initial password (of the form `penguin-1234`) is printed in the server startup output on first start. There is no self-registration: accounts are created by an admin on the user-management page, and every new user automatically gets an independent initial Project named `<userId>-default_project`. While the initial password is still in use, a banner prompts the user to change it.
Logins persist for 7 days with sliding renewal; an admin password reset invalidates all of that user's login sessions.
+1 -1
View File
@@ -23,7 +23,7 @@ penguin web
# 打开 http://127.0.0.1:7364
```
初始账号为 `admin` / `penguin-2026`。系统不开放自助注册:账号由管理员在用户管理页创建;每个新用户会自动获得一个独立的初始 Project,命名为 `<userId>-default_project`。仍在使用初始密码时,页面会以横幅提示尽快修改。
初始账号为 `admin`,初始密码(形如 `penguin-1234`)在服务端首次启动时打印。系统不开放自助注册:账号由管理员在用户管理页创建;每个新用户会自动获得一个独立的初始 Project,命名为 `<userId>-default_project`。仍在使用初始密码时,页面会以横幅提示尽快修改。
登录状态保持 7 天(滑动续期);管理员重置密码会使该用户的全部登录会话失效。
@@ -78,7 +78,7 @@ One install gives you all five rows of that first table, sharing one data direct
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # http://127.0.0.1:7364 — first login: admin / penguin-2026
penguin web # http://127.0.0.1:7364 — first login: admin, initial password printed on first start
```
Multi-session chat, agent and skill management, model configuration, usage and cost statistics, **Trace observability**, and an **evaluation center** — in the box, wired together, nothing to subscribe to and nothing to self-host separately. Every request, tool call and approval decision is already recorded; a session restores completely from its trace. There is no tracing SDK to install because there is no seam to instrument across.
@@ -72,7 +72,7 @@ LangChain 自己也把遗留的 chain、retriever 和 hub 模块挪进了独立
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # http://127.0.0.1:7364 — 首次登录:admin / penguin-2026
penguin web # http://127.0.0.1:7364 — 首次登录:admin,初始密码见首次启动输出
```
多会话对话、Agent 与技能管理、模型配置、用量与成本统计、**Trace 可观测**、**评测中心**,开箱即有,彼此已经打通,**不用订阅什么,也不用另外自建什么**。每个请求、每次工具调用、每个审批决策都已经记下来了,会话可以从 Trace 完整恢复。**这里没有追踪 SDK 要接,因为根本不存在需要跨越的接缝。**
@@ -65,7 +65,7 @@ With the API key in hand, three steps:
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # opens http://127.0.0.1:7364 (first login: admin / penguin-2026)
penguin web # opens http://127.0.0.1:7364 (first login: admin, initial password printed on first start)
```
**2. Configure a Fireworks model**
@@ -65,7 +65,7 @@ AMD 会验证账户与申请资料,通常需要 **2–3 个工作日**;实
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # 打开 http://127.0.0.1:7364(首次登录:admin / penguin-2026)
penguin web # 打开 http://127.0.0.1:7364(首次登录:admin,初始密码见首次启动输出)
```
**2. 配置 Fireworks 模型**
@@ -92,7 +92,7 @@ Install with one command (Linux / macOS, x64 / arm64, bundled Node runtime), the
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # opens http://127.0.0.1:7364 (first login: admin / penguin-2026)
penguin web # opens http://127.0.0.1:7364 (first login: admin, initial password printed on first start)
```
Open the Models page, paste an API key under the DeepSeek or OpenRouter group and set it as default; then head back to Chat and hand the Agent its first task — e.g. "Analyze data.csv and summarize quarterly sales".
@@ -92,7 +92,7 @@ Token 与成本均为全套题目合计,不是单次均值。数据分析套
```bash
curl -fsSL https://penguin.ooo/install.sh | sh
penguin web # 打开 http://127.0.0.1:7364(首次登录:admin / penguin-2026)
penguin web # 打开 http://127.0.0.1:7364(首次登录:admin,初始密码见首次启动输出)
```
进入「模型仓库」页,在 DeepSeek 或 OpenRouter 分组里粘贴 API key 并设为默认;回到对话页,把第一个任务交给 Agent——例如「分析 data.csv,输出各季度销售额汇总」。
@@ -45,6 +45,8 @@ const ROOT = path.resolve(HERE, "../../..");
const OUT_DIR = path.resolve(HERE, "../.blog-assets");
const MOCK_PORT = 8953; // Distinct from capture-shots (8940/8941) and blog-shots (8944).
const SRV_PORT = 8952;
// Pins the otherwise-random seeded admin password (PENGUIN_SEED_ADMIN_PASSWORD below).
const ADMIN_PASSWORD = "penguin-0000";
// The App is canonically served on `localhost` (127.0.0.1 is the Workspace-preview host).
const BASE = `http://localhost:${SRV_PORT}`;
const MOCK = `http://127.0.0.1:${MOCK_PORT}`;
@@ -932,6 +934,7 @@ const srv = spawn("node", [path.join(ROOT, "packages/server/dist/index.js")], {
PENGUIN_WEB_DIST: path.join(ROOT, "packages/web/dist"),
PORT: String(SRV_PORT),
HOST: "127.0.0.1",
PENGUIN_SEED_ADMIN_PASSWORD: ADMIN_PASSWORD,
},
stdio: ["ignore", "pipe", "pipe"],
});
@@ -950,7 +953,7 @@ try {
await waitFor(`${BASE}/`);
console.log(`[blog-013] server ready on ${BASE}`);
const adminCookie = await login("admin", "penguin-2026");
const adminCookie = await login("admin", ADMIN_PASSWORD);
const browser = await chromium.launch();
// WebP encoder: Chromium re-encodes the PNG screenshot via canvas (capture-shots convention).
@@ -36,6 +36,8 @@ const ROOT = path.resolve(HERE, "../../..");
// Gitignored staging dir: these images are hosted in the community repo, not committed here.
const OUT_DIR = path.resolve(HERE, "../.blog-assets");
const SRV_PORT = 8944; // Distinct from capture-shots.mjs (8940/8941) so both can run.
// Pins the otherwise-random seeded admin password (PENGUIN_SEED_ADMIN_PASSWORD below).
const ADMIN_PASSWORD = "penguin-0000";
// On loopback binds the App is canonically served on `localhost`; the 127.0.0.1
// counterpart is the Workspace-preview host, where /api deliberately answers 401
// (see server app.ts's canonical-host guard).
@@ -113,6 +115,7 @@ const srv = spawn("node", [path.join(ROOT, "packages/server/dist/index.js")], {
PENGUIN_WEB_DIST: path.join(ROOT, "packages/web/dist"),
PORT: String(SRV_PORT),
HOST: "127.0.0.1",
PENGUIN_SEED_ADMIN_PASSWORD: ADMIN_PASSWORD,
},
stdio: ["ignore", "pipe", "pipe"],
});
@@ -127,7 +130,7 @@ try {
await waitFor(`${BASE}/`);
console.log(`[blog-shots] server ready on ${BASE}`);
const adminCookie = await login("admin", "penguin-2026");
const adminCookie = await login("admin", ADMIN_PASSWORD);
const browser = await chromium.launch();
// WebP encoder: Chromium re-encodes the PNG screenshot buffer via canvas (same
+4 -1
View File
@@ -27,6 +27,8 @@ const OUT_DIR = path.resolve(HERE, "../src/assets/shots");
const MOCK_PORT = 8941;
const SRV_PORT = 8940;
const BASE = `http://127.0.0.1:${SRV_PORT}`;
// Pins the otherwise-random seeded admin password (PENGUIN_SEED_ADMIN_PASSWORD below).
const ADMIN_PASSWORD = "penguin-0000";
const MOCK = `http://127.0.0.1:${MOCK_PORT}`;
// ---------------------------------------------------------------------------
@@ -523,6 +525,7 @@ const srv = spawn("node", [path.join(ROOT, "packages/server/dist/index.js")], {
PENGUIN_WEB_DIST: path.join(ROOT, "packages/web/dist"),
PORT: String(SRV_PORT),
HOST: "127.0.0.1",
PENGUIN_SEED_ADMIN_PASSWORD: ADMIN_PASSWORD,
},
stdio: ["ignore", "pipe", "pipe"],
});
@@ -542,7 +545,7 @@ try {
await waitFor(`${BASE}/`);
console.log(`[shots] server ready on ${BASE}`);
const admin = await login("admin", "penguin-2026");
const admin = await login("admin", ADMIN_PASSWORD);
const browser = await chromium.launch();
// WebP encoder: Chromium re-encodes the PNG screenshot buffer via canvas, which
+1 -1
View File
@@ -172,7 +172,7 @@ export const en: Strings = {
tabCli: "CLI",
webStep2: "Open the web interface",
webStep2Desc:
"penguin web starts the local service and opens your browser; sign in with the built-in admin account admin / penguin-2026 (change the password right after).",
"penguin web starts the local service and opens your browser; sign in as the built-in admin “admin” with the initial password printed in the terminal on first start (looks like penguin-1234; change it right after).",
webCmd: "penguin web # opens http://127.0.0.1:7364",
webStep3: "Configure a model in the UI and start chatting",
webStep3Desc:
+1 -1
View File
@@ -176,7 +176,7 @@ export const zh = {
tabCli: "命令行",
webStep2: "启动 Web 界面",
webStep2Desc:
"penguin web 启动本地服务并打开浏览器,用内置管理员 admin / penguin-2026 登录(登录后请尽快修改密码)。",
"penguin web 启动本地服务并打开浏览器,用内置管理员 admin 登录——初始密码在服务端首次启动时打印到终端(形如 penguin-1234),登录后请尽快修改密码。",
webCmd: "penguin web # 打开 http://127.0.0.1:7364",
webStep3: "在界面里配置模型,开始对话",
webStep3Desc:
+2 -2
View File
@@ -36,8 +36,8 @@ pnpm --filter @prismshadow/penguin-server start # node dist/index.js
## Security notes (known MVP limits)
- **CSRF**: session cookie is `SameSite=Lax` and writes accept only `Content-Type: application/json`; no CSRF token yet.
- **No login rate limiting**: add throttling at a reverse proxy for public deployments.
- **Built-in admin starts as `admin` / `penguin-2026`**: change it immediately (a banner keeps reminding until you do).
- **Login throttling**: per-username exponential backoff after 5 consecutive failures (1s doubling to a 60s cap, `429 too_many_attempts` inside the window, reset on success; in-memory, so a restart clears it). Unknown usernames are throttled identically, so it is not an account-existence oracle. A reverse proxy can still add IP-level limits for public deployments.
- **Built-in admin `admin` starts with a random initial password** of the form `penguin-1234`, printed once to the server console at seed time (`PENGUIN_SEED_ADMIN_PASSWORD` pins it for tests/e2e): change it immediately (a banner keeps reminding until you do).
- Passwords use `node:crypto` scrypt (`scrypt$N$r$p$salt$hash`, timingSafeEqual); login sessions renew on a 7-day sliding window; the DB stores only the token's sha256.
- Model credentials live in the Project's hidden 0600 config file; the API always masks them.
- Behind a reverse proxy, disable response buffering for SSE paths (the server already sends `X-Accel-Buffering: no`) and forward `x-forwarded-proto` to enable Secure cookies.
+1
View File
@@ -214,6 +214,7 @@ export function buildAppDeps(config: ServerConfig, overrides: BuildDepsOverrides
authSessions: authSessionsRepo,
provisionInitialProject: (user, isAdmin) =>
projectService.provisionInitialProject(user, isAdmin),
seedAdminPassword: config.seedAdminPassword,
sessionTtlMs: config.authSessionTtlMs,
sessionRenewMs: config.authSessionRenewMs,
...(overrides.now ? { now: overrides.now } : {}),
+84 -9
View File
@@ -3,15 +3,16 @@
* login / logout / password change / session validation.
*
* - No open registration: on startup, if there are no users at all, the built-in
* admin `admin` is seeded (initial password penguin-2026), and it adopts
* `default_project`; all other users are created by an admin via the user
* backend (admin-service).
* admin `admin` is seeded with a random `penguin-<4 digits>` initial password
* (printed once by the startup entrypoint; PENGUIN_SEED_ADMIN_PASSWORD injects
* a fixed one for tests/e2e), and it adopts `default_project`; all other users
* are created by an admin via the user backend (admin-service).
* - An initial password (whether seeded or set by an admin) is flagged with
* password_is_initial, which the frontend uses to prompt for a password change soon.
* - Sessions: a 32-byte random token, with only its sha256 hash stored in the DB;
* valid for 7 days, with sliding renewal once less than 6 days remain.
*/
import { createHash, randomBytes } from "node:crypto";
import { createHash, randomBytes, randomInt } from "node:crypto";
import type { UserInfo } from "../api/types.js";
import { HttpError } from "../http/errors.js";
import type { AuthSessionsRepo } from "../db/repos/auth-sessions.js";
@@ -20,9 +21,37 @@ import { hashPassword, verifyPassword } from "./password.js";
export const MIN_PASSWORD_LENGTH = 8;
/** Built-in admin: user_id and initial password (matches the README and login-page hint). */
/** Built-in admin user_id. */
export const ADMIN_USER_ID = "admin";
export const ADMIN_INITIAL_PASSWORD = "penguin-2026";
/**
* Login throttling (per userId): the seeded initial password is `penguin-<4 digits>` —
* 10,000 combinations — so unthrottled guessing would enumerate it in minutes. After
* LOGIN_FREE_ATTEMPTS consecutive failures, the next attempt is admitted only after an
* exponentially growing delay from the last failure (1s, 2s, … capped at 60s; attempts
* inside the window are 429 `too_many_attempts` and do not extend it). Beyond ~40
* failures that is one guess per minute, so the 10k space stops being enumerable, while
* a legitimate user who mistyped a few times never waits more than the cap. A successful
* login clears the counter. Counters are process memory (a restart clears them —
* restarting is slower than waiting out the cap) and are kept for nonexistent userIds
* too, so throttling is not an account-existence oracle. Known limit: a concurrent burst
* can slip in before its first failure is recorded; the steady-state backoff still
* dominates the search space.
*/
const LOGIN_FREE_ATTEMPTS = 5;
const LOGIN_BACKOFF_START_MS = 1000;
const LOGIN_BACKOFF_CAP_MS = 60_000;
/** Failure entries idle longer than this are swept (bounds the map; far above the cap). */
const LOGIN_FAILURE_IDLE_MS = 15 * 60_000;
/**
* Random initial password for the seeded admin: `penguin-<4 digits>` — brand-related and
* easy to type, shown once in the server startup output (the README, docs and login-page
* hint all describe this form).
*/
export function generateInitialAdminPassword(): string {
return "penguin-" + String(randomInt(0, 10000)).padStart(4, "0");
}
function sha256Hex(value: string): string {
return createHash("sha256").update(value).digest("hex");
@@ -42,6 +71,8 @@ export interface AuthServiceDeps {
authSessions: AuthSessionsRepo;
/** Provisions the initial Project at signup (injected by project-service, to avoid a circular dependency). */
provisionInitialProject: (user: UserRow, isAdmin: boolean) => Promise<void>;
/** Fixed initial password for the seeded admin (config.seedAdminPassword); null generates a random one at seed time. */
seedAdminPassword: string | null;
sessionTtlMs: number;
sessionRenewMs: number;
now?: () => Date;
@@ -58,12 +89,25 @@ export class AuthService {
* Startup seeding (idempotent): creates the built-in admin and adopts
* default_project when the users table is empty; if the initial Project fails,
* the user row is rolled back and the server retries on next startup.
* Returns the initial password when it actually seeded — the caller prints it,
* the only place a generated password is ever shown — and null when users
* already exist.
*/
async seedAdmin(): Promise<void> {
if (this.deps.users.count() > 0) return;
async seedAdmin(): Promise<string | null> {
if (this.deps.users.count() > 0) return null;
const password = this.deps.seedAdminPassword ?? generateInitialAdminPassword();
// The override (PENGUIN_SEED_ADMIN_PASSWORD) must meet the same policy as every
// other initial/reset password; rejecting it here, before any insert, keeps a
// configuration typo from creating a trivially weak privileged account. Generated
// passwords are always 12 characters and never trip this.
if (password.length < MIN_PASSWORD_LENGTH) {
throw new Error(
`PENGUIN_SEED_ADMIN_PASSWORD must be at least ${MIN_PASSWORD_LENGTH} characters.`,
);
}
const user: UserRow = {
userId: ADMIN_USER_ID,
passwordHash: await hashPassword(ADMIN_INITIAL_PASSWORD),
passwordHash: await hashPassword(password),
isAdmin: true,
passwordIsInitial: true,
createdAt: this.now().toISOString(),
@@ -75,14 +119,45 @@ export class AuthService {
this.deps.users.delete(user.userId);
throw err;
}
return password;
}
/** Consecutive login failures per userId (see the throttling comment on the constants). */
private readonly loginFailures = new Map<string, { failures: number; lastFailureAt: number }>();
/** The wait imposed after `failures` consecutive failures (0 while within the free attempts). */
private loginDelayMs(failures: number): number {
const excess = failures - LOGIN_FREE_ATTEMPTS;
if (excess <= 0) return 0;
return Math.min(LOGIN_BACKOFF_START_MS * 2 ** (excess - 1), LOGIN_BACKOFF_CAP_MS);
}
async login(userId: string, password: string): Promise<{ user: UserInfo; token: string }> {
const nowMs = this.now().getTime();
for (const [key, entry] of this.loginFailures) {
if (nowMs - entry.lastFailureAt > LOGIN_FAILURE_IDLE_MS) this.loginFailures.delete(key);
}
const failed = this.loginFailures.get(userId);
if (failed) {
const readyAt = failed.lastFailureAt + this.loginDelayMs(failed.failures);
if (nowMs < readyAt) {
throw new HttpError(
429,
"too_many_attempts",
`Too many failed sign-in attempts. Try again in ${Math.ceil((readyAt - nowMs) / 1000)}s.`,
);
}
}
const row = this.deps.users.findById(userId);
const ok = row !== null && (await verifyPassword(password, row.passwordHash));
if (!row || !ok) {
this.loginFailures.set(userId, {
failures: (failed?.failures ?? 0) + 1,
lastFailureAt: this.now().getTime(),
});
throw new HttpError(401, "invalid_credentials", "Incorrect username or password.");
}
this.loginFailures.delete(userId);
this.deps.authSessions.deleteExpired(this.now().toISOString());
return { user: toUserInfo(row), token: this.issueSession(row.userId) };
}
+9 -1
View File
@@ -32,6 +32,12 @@ export interface ServerConfig {
* derived per request instead. See design § "Workspace 文件预览".
*/
previewOrigin: string | null;
/**
* Fixed initial password for the seeded built-in admin (PENGUIN_SEED_ADMIN_PASSWORD),
* used by automated tests and e2e; null (the norm) makes the seed generate a random
* `penguin-<4 digits>` password, printed once to the server console.
*/
seedAdminPassword: string | null;
/** Login session validity period (7 days). */
authSessionTtlMs: number;
/** Sliding renewal threshold: if the remaining validity is below this value when validation succeeds, it's renewed to the full TTL (renews under 6 days). */
@@ -73,7 +79,7 @@ function normalizePreviewOrigin(raw: string | undefined): string | null {
return url.origin;
}
/** Parses server config from environment variables (PORT / HOST / PENGUIN_HOME / PENGUIN_WEB_DIST / PENGUIN_WEB_DB / PENGUIN_PREVIEW_ORIGIN). */
/** Parses server config from environment variables (PORT / HOST / PENGUIN_HOME / PENGUIN_WEB_DIST / PENGUIN_WEB_DB / PENGUIN_PREVIEW_ORIGIN / PENGUIN_SEED_ADMIN_PASSWORD). */
export function resolveServerConfig(env: NodeJS.ProcessEnv = process.env): ServerConfig {
const root = env.PENGUIN_HOME ?? resolveRoot();
// An empty PORT string is treated as unset (the common `.env` case of an empty
@@ -90,6 +96,8 @@ export function resolveServerConfig(env: NodeJS.ProcessEnv = process.env): Serve
dbPath: env.PENGUIN_WEB_DB ?? path.join(root, "web.db"),
webDist: env.PENGUIN_WEB_DIST ?? defaultWebDist(),
previewOrigin: normalizePreviewOrigin(env.PENGUIN_PREVIEW_ORIGIN),
// An empty/whitespace value is treated as unset (→ random seed password).
seedAdminPassword: env.PENGUIN_SEED_ADMIN_PASSWORD?.trim() || null,
authSessionTtlMs: 7 * DAY_MS,
authSessionRenewMs: 6 * DAY_MS,
};
+9 -2
View File
@@ -21,8 +21,15 @@ const config = resolveServerConfig();
const deps = buildAppDeps(config);
const app = createApp(deps);
// Built-in admin seed (idempotent): creates admin (initial password penguin-2026) and adopts default_project when the users table is empty.
await deps.authService.seedAdmin();
// Built-in admin seed (idempotent): creates admin and adopts default_project when the
// users table is empty. The returned initial password (random unless pinned via
// PENGUIN_SEED_ADMIN_PASSWORD) is printed here once — the only place it is ever shown.
const seededAdminPassword = await deps.authService.seedAdmin();
if (seededAdminPassword !== null) {
console.log(
`Seeded built-in admin "admin" — initial password: ${seededAdminPassword} (change it after first sign-in)`,
);
}
// Schedule scheduler: startup reconciliation (missed, don't backfill) + periodic scan; only active while the server is running.
await deps.scheduler.start();
+106 -3
View File
@@ -6,7 +6,18 @@ import fs from "node:fs/promises";
import path from "node:path";
import { afterEach, beforeEach, describe, expect, it } from "vitest";
import type { MeResponse, ProjectsResponse } from "../src/api/types.js";
import { apiClient, createTestApp, loginAdmin, loginUser, provisionUser } from "./helpers.js";
import { buildAppDeps } from "../src/app.js";
import { generateInitialAdminPassword } from "../src/auth/service.js";
import {
apiClient,
createTestApp,
loginAdmin,
loginUser,
makeTempRoot,
provisionUser,
TEST_ADMIN_PASSWORD,
testConfig,
} from "./helpers.js";
import type { TestApp } from "./helpers.js";
describe("auth", () => {
@@ -55,8 +66,8 @@ describe("auth", () => {
await expect(
fs.access(path.join(t.root, "default_project", "agents", "default_agent", "agent_state")),
).resolves.toBeUndefined();
// Seeding is idempotent: re-seeding does not create a duplicate account.
await t.deps.authService.seedAdmin();
// Seeding is idempotent: re-seeding returns null and does not create a duplicate account.
expect(await t.deps.authService.seedAdmin()).toBeNull();
expect(t.deps.db.prepare("SELECT COUNT(*) AS n FROM users").get()?.n).toBe(1);
});
@@ -159,6 +170,98 @@ describe("auth", () => {
expect(got.prefs.theme).toBe("dark");
});
it("seedAdmin without an injected password generates penguin-<4 digits> and returns it", async () => {
// Bypass the fixed test password: null matches the production default (random generation).
const fresh = await createTestApp({ config: { seedAdminPassword: null } });
try {
expect(fresh.adminPassword).toMatch(/^penguin-\d{4}$/);
// The returned password is the one that actually logs in.
await loginUser(fresh.app, "admin", fresh.adminPassword);
// Users exist now: re-seeding reports that nothing was seeded.
expect(await fresh.deps.authService.seedAdmin()).toBeNull();
} finally {
await fresh.cleanup();
}
});
it("seedAdmin honors the injected seedAdminPassword", async () => {
const fresh = await createTestApp({ config: { seedAdminPassword: "penguin-7777" } });
try {
expect(fresh.adminPassword).toBe("penguin-7777");
await loginUser(fresh.app, "admin", "penguin-7777");
} finally {
await fresh.cleanup();
}
});
it("seedAdmin rejects an override below the password policy before creating the account", async () => {
const root = await makeTempRoot();
const deps = buildAppDeps({ ...testConfig(root), seedAdminPassword: "x" }, { log: () => {} });
try {
await expect(deps.authService.seedAdmin()).rejects.toThrow(/at least 8 characters/);
// Rejected before any insert: no half-created privileged account to retry around.
expect(deps.db.prepare("SELECT COUNT(*) AS n FROM users").get()?.n).toBe(0);
} finally {
deps.channels.dispose();
deps.db.close();
await fs.rm(root, { recursive: true, force: true, maxRetries: 10, retryDelay: 100 });
}
});
it("throttles login failures per username with exponential backoff and resets on success", async () => {
let clock = Date.parse("2026-08-03T00:00:00Z");
const fresh = await createTestApp({ now: () => new Date(clock) });
try {
const attempt = (password: string) =>
fresh.app.request("/api/auth/login", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ userId: "admin", password }),
});
// Five free failures, and the sixth still reaches verification (backoff starts after it).
for (let i = 0; i < 6; i++) expect((await attempt("wrong-password")).status).toBe(401);
// Inside the 1s window: rejected without touching credentials — even the CORRECT password.
const throttled = await attempt("wrong-password");
expect(throttled.status).toBe(429);
const body = (await throttled.json()) as { error: { code: string } };
expect(body.error.code).toBe("too_many_attempts");
expect((await attempt(TEST_ADMIN_PASSWORD)).status).toBe(429);
// Past the window, the correct password signs in and clears the counter…
clock += 1100;
await loginUser(fresh.app, "admin", TEST_ADMIN_PASSWORD);
// …so the next failure is an ordinary 401 again, not a 429.
expect((await attempt("wrong-password")).status).toBe(401);
} finally {
await fresh.cleanup();
}
});
it("throttles unknown usernames identically (no account-existence oracle)", async () => {
let clock = Date.parse("2026-08-03T00:00:00Z");
const fresh = await createTestApp({ now: () => new Date(clock) });
try {
const attempt = () =>
fresh.app.request("/api/auth/login", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ userId: "ghost", password: "whatever-123" }),
});
for (let i = 0; i < 6; i++) expect((await attempt()).status).toBe(401);
expect((await attempt()).status).toBe(429);
// The window expires on the same schedule as for real accounts.
clock += 1100;
expect((await attempt()).status).toBe(401);
} finally {
await fresh.cleanup();
}
});
it("generateInitialAdminPassword matches penguin-<4 digits>", () => {
for (let i = 0; i < 32; i++) {
expect(generateInitialAdminPassword()).toMatch(/^penguin-\d{4}$/);
}
});
it("PUT prefs shallow-merges without clobbering other writers' fields", async () => {
const { cookie } = await provisionUser(t.app, "fred");
const api = apiClient(t.app, cookie);
+24 -5
View File
@@ -1,9 +1,12 @@
/**
* resolveServerConfig PORT parsing tests: both the default (missing) and empty string
* (the common `PORT=` empty value in `.env`) fall back to 7364 — Number("") === 0 used
* to make the empty string pass range validation and bind to a random port; explicit
* "0" is preserved (explicit semantics for a random available port); invalid values
* throw. This matches the CLI's resolvePort semantics (packages/cli serve).
* resolveServerConfig parsing tests.
*
* PORT: both the default (missing) and empty string (the common `PORT=` empty value in
* `.env`) fall back to 7364 — Number("") === 0 used to make the empty string pass range
* validation and bind to a random port; explicit "0" is preserved (explicit semantics
* for a random available port); invalid values throw. This matches the CLI's
* resolvePort semantics (packages/cli serve).
* PENGUIN_SEED_ADMIN_PASSWORD: unset/empty/whitespace → null (random seed password).
*/
import { describe, expect, it } from "vitest";
import { resolveServerConfig } from "../src/config.js";
@@ -27,3 +30,19 @@ describe("resolveServerConfig: PORT parsing", () => {
}
});
});
describe("resolveServerConfig: PENGUIN_SEED_ADMIN_PASSWORD parsing", () => {
it("unset/empty/whitespace → null; a value is kept trimmed", () => {
expect(resolveServerConfig({ ...base }).seedAdminPassword).toBeNull();
expect(
resolveServerConfig({ ...base, PENGUIN_SEED_ADMIN_PASSWORD: "" }).seedAdminPassword,
).toBeNull();
expect(
resolveServerConfig({ ...base, PENGUIN_SEED_ADMIN_PASSWORD: " " }).seedAdminPassword,
).toBeNull();
expect(
resolveServerConfig({ ...base, PENGUIN_SEED_ADMIN_PASSWORD: " penguin-9999 " })
.seedAdminPassword,
).toBe("penguin-9999");
});
});
+14 -5
View File
@@ -11,7 +11,7 @@ import type { OmniMessage } from "@prismshadow/penguin-core";
import { buildAppDeps, createApp } from "../src/app.js";
import type { AppDeps, BuildDepsOverrides } from "../src/app.js";
import type { AppEnv } from "../src/auth/middleware.js";
import { ADMIN_INITIAL_PASSWORD, ADMIN_USER_ID } from "../src/auth/service.js";
import { ADMIN_USER_ID } from "../src/auth/service.js";
import type { ServerConfig } from "../src/config.js";
import type { UserInfo } from "../src/api/types.js";
@@ -21,6 +21,9 @@ export async function makeTempRoot(): Promise<string> {
const DAY_MS = 24 * 60 * 60 * 1000;
/** Fixed seeded-admin password injected into every test app (in production the seed generates a random one). */
export const TEST_ADMIN_PASSWORD = "penguin-0000";
export function testConfig(root: string): ServerConfig {
return {
root,
@@ -32,6 +35,8 @@ export function testConfig(root: string): ServerConfig {
previewOrigin: null,
// Points to a nonexistent directory: static hosting is disabled in tests.
webDist: path.join(root, "__no_web_dist__"),
// Fixed seed password so loginAdmin needs no seed-time capture.
seedAdminPassword: TEST_ADMIN_PASSWORD,
authSessionTtlMs: 7 * DAY_MS,
authSessionRenewMs: 6 * DAY_MS,
};
@@ -41,6 +46,8 @@ export interface TestApp {
app: Hono<AppEnv>;
deps: AppDeps;
root: string;
/** Initial password of the seeded admin (TEST_ADMIN_PASSWORD unless overridden via `config.seedAdminPassword`). */
adminPassword: string;
cleanup(): Promise<void>;
}
@@ -56,13 +63,15 @@ export async function createTestApp(options: TestAppOptions = {}): Promise<TestA
const root = await makeTempRoot();
if (beforeSeed) await beforeSeed(root);
const deps = buildAppDeps({ ...testConfig(root), ...config }, { log: () => {}, ...overrides });
// Consistent with the startup entrypoint: seed the built-in admin (owning default_project).
await deps.authService.seedAdmin();
// Consistent with the startup entrypoint: seed the built-in admin (owning default_project),
// keeping the password it returns (only null if a beforeSeed hook ever pre-created users).
const adminPassword = (await deps.authService.seedAdmin()) ?? TEST_ADMIN_PASSWORD;
const app = createApp(deps);
return {
app,
deps,
root,
adminPassword,
cleanup: async () => {
deps.channels.dispose();
deps.db.close();
@@ -95,9 +104,9 @@ export async function loginUser(
return { cookie: setCookie.split(";")[0]!, user: body.user };
}
/** Logs in as the seeded admin. */
/** Logs in as the seeded admin (every test app seeds with TEST_ADMIN_PASSWORD). */
export function loginAdmin(app: Hono<AppEnv>): Promise<{ cookie: string; user: UserInfo }> {
return loginUser(app, ADMIN_USER_ID, ADMIN_INITIAL_PASSWORD);
return loginUser(app, ADMIN_USER_ID, TEST_ADMIN_PASSWORD);
}
/** Admin creates the account and logs in as that user (the only way to create test users while registration is closed). */
+6 -4
View File
@@ -1,9 +1,11 @@
/**
* e2e auth helper: with signup disabled, test users are always provisioned via
* the built-in admin account, then logged in. The server seeds an admin
* (admin / penguin-2026) on startup; a single e2e run shares one data root, and
* provisioning is idempotent (reuses the user if it already exists) so a
* single spec can be rerun on its own.
* the built-in admin account, then logged in. The seeded admin password is
* random in production; run.sh starts the e2e server with
* PENGUIN_SEED_ADMIN_PASSWORD=penguin-2026 to pin it to the constant below.
* A single e2e run shares one data root, and provisioning is idempotent
* (reuses the user if it already exists) so a single spec can be rerun on its
* own.
*/
import { request } from "@playwright/test";
+3
View File
@@ -32,8 +32,11 @@ MOCK_PORT=$MOCK_PORT node "$HERE/mock-llm.mjs" &
MOCK_PID=$!
echo "== start server =="
# PENGUIN_SEED_ADMIN_PASSWORD pins the otherwise-random seeded admin password to the
# constant the specs use (ADMIN_PASSWORD in auth.mjs).
PENGUIN_HOME="$DATA" PORT=$SRV_PORT HOST=127.0.0.1 PENGUIN_WEB_DB="$DATA/web.db" \
PENGUIN_WEB_DIST="$ROOT/packages/web/dist" \
PENGUIN_SEED_ADMIN_PASSWORD=penguin-2026 \
node "$ROOT/packages/server/dist/index.js" &
SRV_PID=$!
+4 -2
View File
@@ -130,13 +130,14 @@ export const en: Strings = {
logout: "Sign out",
admin: "Admin",
defaultAdminNote:
"First run: sign in as the built-in admin (admin / penguin-2026), then change the password soon",
"First run: sign in as the built-in admin “admin” with the initial password printed in the server startup output (looks like penguin-1234), then change it soon",
},
account: {
changePassword: "Change password",
oldPassword: "Current password",
oldPasswordHint: "The built-in admin's default initial password is penguin-2026",
oldPasswordHint:
"The built-in admin's initial password is printed in the server startup output (looks like penguin-1234)",
newPassword: "New password",
confirmPassword: "Confirm new password",
passwordMismatch: "New passwords do not match",
@@ -1061,6 +1062,7 @@ Scenarios:
/** Localized text for the common server error codes (server error messages are English-only); looked up by ApiError.code in apiErrorText, falling back to the raw message for unmapped codes. */
byCode: {
invalid_credentials: "Incorrect username or password.",
too_many_attempts: "Too many failed sign-in attempts. Try again shortly.",
password_mismatch: "The current password is incorrect.",
invalid_password: "Password must be at least 8 characters.",
admin_required: "Only an admin can perform this operation.",
+4 -2
View File
@@ -127,13 +127,14 @@ export const zh = {
login: "登录",
logout: "登出",
admin: "管理员",
defaultAdminNote: "首次使用请以内置管理员登录:admin / penguin-2026,登录后请尽快修改密码",
defaultAdminNote:
"首次使用请以内置管理员 admin 登录,初始密码在服务端首次启动时打印(形如 penguin-1234),登录后请尽快修改密码",
},
account: {
changePassword: "修改密码",
oldPassword: "当前密码",
oldPasswordHint: "内置管理员的默认初始密码为 penguin-2026",
oldPasswordHint: "内置管理员的初始密码在服务端首次启动时打印(形如 penguin-1234)",
newPassword: "新密码",
confirmPassword: "确认新密码",
passwordMismatch: "两次输入的新密码不一致",
@@ -1040,6 +1041,7 @@ Benchmark:
/** Localized text for the common server error codes (server error messages are English-only); looked up by ApiError.code in apiErrorText, falling back to the raw message for unmapped codes. */
byCode: {
invalid_credentials: "用户名或密码错误。",
too_many_attempts: "登录失败次数过多,请稍后重试。",
password_mismatch: "当前密码不正确。",
invalid_password: "密码至少 8 位。",
admin_required: "仅管理员可执行此操作。",