Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1.5 KiB
Web App: random seeded admin password and login throttling
The built-in admin's fixed, publicly documented initial password (penguin-2026) is gone.
Random seed password
On first start the server now seeds admin with a random penguin-<4 digits> password and prints it exactly once to the startup console (Seeded built-in admin "admin" — initial password: penguin-1234 …); the login page and change-password dialog point at the startup output instead of naming a constant, and the READMEs, docs, installer next-steps and blog posts follow. PENGUIN_SEED_ADMIN_PASSWORD pins the seed for automated tests and e2e, and is subject to the same ≥ 8 characters policy as every other initial/reset password — a configuration typo cannot create a trivially weak privileged account.
Login throttling
The login endpoint gains per-username throttling so the 10,000-value password shape stays a convenience, not an attack surface: after 5 consecutive failures, the next attempt is admitted only after an exponentially growing delay from the last failure (1s doubling to a 60s cap; attempts inside the window get 429 too_many_attempts — localized in the UI — and do not extend it), and a successful login clears the counter. Past ~40 failures an attacker gets one guess per minute, while a mistyping user never waits more than the cap. Unknown usernames are throttled identically, so the throttle is not an account-existence oracle. Counters live in process memory; a restart clears them.