pastilhasandClaude Opus 5 b6feca8350 owner can reset a member's platform password
The gap at the other end of create-user.ts: the owner could set a password once, at
creation, and never again. Losing it meant a hand-written UPDATE with an argon2
hash — the same "edit Postgres by hand" hole that creating accounts used to have.

POST /api/users/:id/password, owner-gated, with a button on the row.

GENERATED, not typed. The failure this exists for is "I created the account and
forgot to copy the password down", and an owner typing a replacement can lose it the
same way on the second go. Shown once in a dialog built to be copied — a dialog and
not a toast, because a toast that times out while somebody finds a pen loses the one
thing they came for.

The generator satisfies validatePassword BY CONSTRUCTION rather than by luck: one
character drawn from each of the four required classes, the rest from the union,
then Fisher-Yates shuffled so the first four positions are not always
lower/upper/digit/special. Rejection sampling throughout — `% n` on a byte biases
the early characters. Then it runs validatePassword on its own output, so if the
rules ever gain a requirement the alphabets do not cover it throws at the one call
site instead of minting passwords the login form rejects. Measured: 20,000
generations, all four classes present every time.

l, I, 1, O and 0 are absent from the alphabets. This gets read off a screen and
typed somewhere else.

Signs them out everywhere, as asked: passwordChangedAt = now, and userMiddleware
already refuses any token whose iat predates it. That overwrites the null
create-user leaves to mean "the owner chose this, not them" — checked, nothing reads
that column except the token check.

The Linux account is deliberately untouched, and the dialog says so. Members have no
Linux password and never had one: ensureOsUser runs useradd with no -p, so it is
created locked. Their terminal goes through setpriv, which does not authenticate;
their SSH is the key the owner pasted; `su - <member>` as root does not ask. And
machine-setup sets PasswordAuthentication no — verified on this host — so one could
not be used to log in even if it existed. Setting one would be a new way in, not a
repair.

The owner is excluded: they have change-password, which asks for the current one,
and resetting themselves here would end the session doing it.

Verified: transpiles, all lucide icons exist, 20k generator runs. tsgo next.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 12:07:43 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-22 03:35:26 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00

The documentation, triaged

2026-08-13. A map of what is in here, what it is for, and what should happen to it. Made because there are 42 documents and 13,000 lines, and no way to tell from the filenames which describe the system as it is and which are a record of an afternoon in July.

How much I verified: the classifications below are from filenames, status lines, and greps for things that changed on 2026-08-13. Where I actually read the document or checked the code, it says so. The rest is a starting point for a conversation, not a verdict.


Living — these describe the system and must stay true

doc state
working-on-officer.md updated 2026-08-13. Operational guide.
secret-store.md updated 2026-08-13. Built; rotation still open.
install-variants.md new. The branch tree, for discussion.
http-secure-context-audit.md new. What breaks over plain http.
install-container-testing.md new. First container pass and its findings.
per-user-linux-accounts.md partly updated. OFFICER_OS_USERS is gone; check the rest.
navigation-audit.md authoritative on routing. Unverified against tonight's route removals.
workspace-panels.md + workspace-panel-todo.md the panel framework. 1,300 lines combined — likely the biggest cleanup here.
agent-coordination.md the north star for panel work.
deprovision-os-account.md implemented; the 'disabled' stage it may mention was deleted tonight.

Stale — describe things that changed on 2026-08-13

Each of these references something that no longer exists. Not yet corrected.

  • sidecar-topology.md — "ecosystem.config.cjs is the source of truth". It is generated now, and holds six processes.
  • sidecar-app-store.md — derives the catalogue from full light. Those files are gone, and catalogue.test.ts was rewritten.
  • sidecar-bootstrapping.md — "20 PM2 entries, 18 sidecar dirs". Six entries now.
  • mobile-api-keys.md — partly corrected; recheck the origin-checking claims.
  • wallet-key-custody.mdVAULT_STORE_KEY is now the per-purpose wallet key.
  • push-notifications.md — "agreed design, 2026-07-31". Notify is a plugin and unmounted.
  • chat-session-lifetime.md, chat-ui-walkthrough.md — reference officer-agent, renamed.

Historical — a record of a moment, and should stay one

Do not rewrite these to match today's code. They document how a decision was reached, and editing them destroys the reasoning. If they mislead, add a dated header pointing forward.

  • sidecar-audit-2026-07.md (1,377 lines)
  • claude-sidecar-isolation.md — records the officer-claudeofficer-agent rename that preceded tonight's officer-agentofficer-claude-code
  • open-threads-after-per-user-claude.md
  • two-agent-field-report-2026-08-12.md
  • api-method-changes-2026-08-06.md

The opencode cluster — nine documents for one migration

opencode-fork-decision · -parity · -api-2-assessment · -phase0-review · -phase1-report · -phase1-review · -serve-migration-plan · -serve-path · -testing-checklist

The migration landedopencode serve is in the sidecar, verified. So opencode-serve-migration-plan.md saying "Nothing here is implemented" is false.

This is the clearest consolidation candidate in the whole directory: one document recording what was decided and what shipped, replacing nine that describe stages of getting there. I did not do it because it needs reading all nine, and deleting documents unread is not a thing to do at 4am.

The mobile-dav thread — three documents, one conversation

mobile-dav-provisioning · -feedback · -reply. A correspondence. Almost certainly one document.

Unclassified — I have not looked

design-language-interface · file-sync · jobs-unification · mobile-photo-sync-api · nextcloud-replacement · agent-git-identity


The plugin split, which affects most of the above

A core install is six processes. Everything else is a plugin, switched off tonight but present on disk. Most documents here were written when the estate was twenty processes and every one of them was simply "there", so they describe availability that no longer holds.

The useful rewrite is usually one line, not a rewrite: say whether the thing described is core or a plugin, and if a plugin, that it is not mounted on a fresh install.

S
Description
No description provided
Readme
42 MiB
Languages
TypeScript 91.1%
Shell 4.5%
JavaScript 4.1%
CSS 0.2%
HTML 0.1%