Skip to content

feat(hoocloak): allow default password for users without hash - #16

Merged
wakemeup0 merged 1 commit into
mainfrom
feat/default-user-password
Sep 29, 2026
Merged

wakemeup0 merged 1 commit into
mainfrom
feat/default-user-password

Conversation

@wakemeup0

Copy link
Copy Markdown
Contributor

Change

  • Accept users with an omitted or empty password_hash and authenticate them with hoo.
  • Keep configured bcrypt hashes authoritative and reject the default password for those users.
  • Document the behavior and cover omitted/empty config, valid and invalid logins, and unknown users.

Closes #15.

Compatibility and security

  • Existing users with a configured hash keep the same authentication behavior.
  • Every user without a hash has a publicly known shared password. This is intended for development deployments; operators requiring individual credentials must configure hashes.
  • Unknown users still run a bcrypt check and fail. All password logins continue through the existing credential-check slot limit.

Deployment and rollback

  • No config migration is needed. Deploy by updating the Hoocloak image; rollback to the prior image restores the previous requirement for a hash, so configs that omit it will then fail validation.

Validation

  • go test -tags no_otel ./... passed locally using Go 1.26.4 in Docker.
  • git diff --check passed.

@wakemeup0
wakemeup0 merged commit 6f871f8 into main Sep 29, 2026
9 checks passed
@wakemeup0
wakemeup0 deleted the feat/default-user-password branch September 29, 2026 10:04
wakemeup0 added a commit that referenced this pull request Sep 29, 2026
Publish Hoocloak 2.1.0 after the successful CI run for main commit
6f871f8.

- Bump the provider and Helm chart versions to 2.1.0.
- Add changelog entries including the default-password behavior from
#16.
- Compatibility/security impact: users without `password_hash` can sign
in with the shared password `hoo`; configured hashes remain
authoritative. Operators requiring individual credentials must set
hashes for all users.
- Deployment: release artifacts are built and published by the protected
release workflow after this PR merges and the release commit passes CI.
- Rollback: deploy the prior image/chart version; configs with omitted
hashes must first restore valid hashes for that version.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
wakemeup0 added a commit that referenced this pull request Sep 29, 2026
Complete the prepared Hoocloak 2.1.0 release after the release workflow
failed on the protected main branch.

The failed run attempted to rewrite `main` and create `v2.2.0`, which
repository rules rejected. This change tags the already reviewed release
commit after its main CI succeeds, verifies the tag points to that
commit, and feeds the existing image, chart, and GitHub Release jobs. It
also accepts GitHub's squash-merge PR suffix for a release commit and
for a manual publication retry.

- Compatibility: no change to Hoocloak runtime behavior beyond #16.
- Security: the default `hoo` password remains limited to users without
a configured hash, as documented in #16. Tag creation still requires
successful CI on the exact release commit.
- Deployment: merge with the PR title shown here so the existing release
workflow recognizes the release commit.
- Rollback: no runtime rollback is needed for this CI-only change; the
`v2.1.0` tag is checked for commit identity and never moved.

Validation: Bash subject matching was checked for exact, PR-suffixed,
and incorrect versions; `git diff --check` passed. The full GitHub CI
remains the release gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Allow default password for users without password_hash

1 participant