fix(setup): use /api/setup endpoint for admin creation

The admin setup form was calling /api/auth/register which creates a
regular user (role is hardcoded to User) and never sets the
system_initialized flag. Switch to /api/setup which creates an actual
admin and marks the system as initialized. Add setup token input field.
This commit is contained in:
Jared Wolff
2026-03-04 20:27:43 -05:00
parent 34e7b9dfa8
commit 4293a30d50
2 changed files with 32 additions and 3 deletions
+19 -3
View File
@@ -729,9 +729,25 @@ if (isLoginPage && adminSetupForm) {
}
try {
// Register admin account
const data = await register('admin', email, password, 'admin');
// Use the /api/setup endpoint which creates an admin and marks the system as initialized
const setupToken = document.getElementById('admin-setup-token').value;
const response = await fetch('/api/setup', {
method: 'POST',
headers: { 'Content-Type': 'application/json', ...getCsrfHeaders() },
credentials: 'same-origin',
body: JSON.stringify({
username: 'admin',
email,
password,
setup_token: setupToken
})
});
if (!response.ok) {
const err = await response.json().catch(() => ({}));
throw new Error(err.message || 'Setup failed');
}
const data = await response.json();
// Show success message in the GUI instead of alert
const successMsg = window.i18n ? window.i18n.t('auth.admin_success') : 'Admin account created successfully! You can now log in.';