Skip to main content

Module bootstrap

Module bootstrap 

Source
Expand description

The one-time code that, beside RECALL_TOKEN, registers the first passkey for /admin.

The token alone once did, at first deploy and again after every recall-server reset-passkeys. The token is long-lived and sits in more places than the server (a password manager, .env, every machine not yet enrolled as a device), so a leaked copy could plant a passkey that survived rotating the token. The code closes that: it is printed only where the server runs, in its log when it starts with no passkey and by reset-passkeys, it works for an hour, and it works once. The server keeps only its SHA-256.

Structs§

BootstrapCode
A code just issued, for printing: BootstrapCode::instructions.

Constants§

TTL
How long a code works for. Restarting a server that has no passkey, or running reset-passkeys again, prints a new one.

Functions§

issue
Makes a new code the only one, until TTL after now, with the server’s bootstrap_code leaf, which says until when and never the code.
reset
Removes every passkey and admin session, and makes a new code the only one: recall-server reset-passkeys. Answers how many passkeys went.
sha256
The SHA-256 the store knows a typed code by: case, dashes and spaces do not matter. None for anything that cannot be a code.