Use interactive password prompt for argon2 hash generation
The bootstrap and add-user docs passed --password 'plaintext' on the docker compose run command line, leaking the plaintext into shell history (~/.bash_history, ~/.zsh_history) and the process list (ps aux). Switched all three call sites to the interactive form (no --password flag), which makes Authelia prompt for the password and a confirmation without echoing. Affected: - README.md "Create your first user" step - README.md "Add a user" section - authelia/users_database.yml.example header comment https://claude.ai/code/session_013XZ1vmgk78k2PEQ5DmJhF3
This commit is contained in:
@@ -386,10 +386,14 @@ Fill in `username`, `email`, and `displayname`. Then generate the password hash:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker compose run --rm authelia \
|
docker compose run --rm authelia \
|
||||||
authelia crypto hash generate argon2 --password 'your-real-password'
|
authelia crypto hash generate argon2
|
||||||
```
|
```
|
||||||
|
|
||||||
Copy the `$argon2id$...` line and paste it as the `password:` value in `users_database.yml`.
|
Authelia prompts for the password and a confirmation without echoing --
|
||||||
|
the plaintext never hits your shell history or `ps aux`. Copy the
|
||||||
|
`Digest: $argon2id$...` line from the output and paste the digest
|
||||||
|
(everything from `$argon2id` onward) as the `password:` value in
|
||||||
|
`users_database.yml`.
|
||||||
|
|
||||||
### 6. Pre-create the Authelia log file
|
### 6. Pre-create the Authelia log file
|
||||||
|
|
||||||
@@ -551,9 +555,10 @@ Verify in a private browser window: `https://cam.yourdomain.com` should go to Au
|
|||||||
Append to `authelia/users_database.yml`, generate a hash:
|
Append to `authelia/users_database.yml`, generate a hash:
|
||||||
```bash
|
```bash
|
||||||
docker compose run --rm authelia \
|
docker compose run --rm authelia \
|
||||||
authelia crypto hash generate argon2 --password 'new-password'
|
authelia crypto hash generate argon2
|
||||||
```
|
```
|
||||||
Paste the hash as `password:`. Restart or wait 5 minutes for auto-reload.
|
Authelia prompts for the password (no echo, not in shell history). Paste
|
||||||
|
the printed digest as `password:`. Restart or wait 5 minutes for auto-reload.
|
||||||
|
|
||||||
### Disable a user
|
### Disable a user
|
||||||
|
|
||||||
|
|||||||
@@ -2,13 +2,17 @@
|
|||||||
###############################################################################
|
###############################################################################
|
||||||
# Authelia users database
|
# Authelia users database
|
||||||
#
|
#
|
||||||
# Copy this to users_database.yml (gitignored) and edit. Generate the
|
# Copy this to users_database.yml (gitignored) and edit. Generate each
|
||||||
# password hash with:
|
# password hash with:
|
||||||
#
|
#
|
||||||
# docker compose run --rm authelia \
|
# docker compose run --rm authelia \
|
||||||
# authelia crypto hash generate argon2 --password 'your-plaintext-pass'
|
# authelia crypto hash generate argon2
|
||||||
|
#
|
||||||
|
# Authelia prompts for the password and a confirmation without echoing,
|
||||||
|
# so the plaintext never hits shell history or `ps aux`. Output ends
|
||||||
|
# with `Digest: $argon2id$v=19$m=...`. Paste the digest (everything from
|
||||||
|
# `$argon2id` onward) as the `password:` value below.
|
||||||
#
|
#
|
||||||
# Paste the resulting `$argon2id$v=19$m=...` string as the `password:` value.
|
|
||||||
# Restart Authelia for changes to take effect (or wait refresh_interval).
|
# Restart Authelia for changes to take effect (or wait refresh_interval).
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user