feat: auto-persist JWT secret, remove setup token requirement

- JWT secret auto-generates and persists to <STORAGE_PATH>/.jwt_secret
- Remove setup token: first admin setup is open until system initialized
- Fix schema.sql: move CREATE EXTENSION pg_trgm/ltree to top
- Update login UI and auth.js to remove setup token fields
This commit is contained in:
Dionisio
2026-03-05 22:12:21 +01:00
parent c77ce202c6
commit f2d35ca792
336 changed files with 104 additions and 114 deletions
View File
View File
View File
View File
View File
View File
View File
Regular → Executable
View File
View File
View File
Regular → Executable
View File
Regular → Executable
View File
View File
View File
View File
View File
View File
View File
Regular → Executable
+1 -2
View File
@@ -49,13 +49,12 @@ pub struct RegisterDto {
}
/// DTO for the one-time initial admin setup endpoint (`/api/setup`).
/// Requires the setup token printed to the server log on first boot.
/// Available only when the system is not yet initialized (no admin exists).
#[derive(Debug, Serialize, Deserialize, Clone)]
pub struct SetupAdminDto {
pub username: String,
pub email: String,
pub password: String,
pub setup_token: String,
}
#[derive(Debug, Clone, Serialize, Deserialize)]