diff --git a/.gitignore b/.gitignore index 47e4fc4..afdbd90 100644 --- a/.gitignore +++ b/.gitignore @@ -4,3 +4,5 @@ uploads/ .vibe42-run.log .vibe42-run.pid .env + +.kfu-svod-pw.txt diff --git a/lib/store.js b/lib/store.js index 3c700f9..a3a805f 100644 --- a/lib/store.js +++ b/lib/store.js @@ -53,16 +53,18 @@ function randPassword(len) { } function makeUser(record) { + const pw = record._seedPassword || randPassword(12); const salt = crypto.randomBytes(32); - const pw = randPassword(12); const hash = crypto.scryptSync(pw, salt, 32); + const { _seedPassword, ...rest } = record; return Object.assign( { failedCount: 0, lockedUntil: 0 }, - record, + rest, { salt: salt.toString("hex"), passwordHash: hash.toString("hex"), active: true, + ...(record._keepTemp ? { tempPassword: pw } : {}) } ); } @@ -76,13 +78,15 @@ function seed() { users: [], reports: [], }; - const consPw = randPassword(12); + const consPw = process.env.KFU_SVOD_PASSWORD || "12345678"; const cons = makeUser({ id: "u_consolidator", role: "consolidator", name: "", companyName: "", login: "svod", + _seedPassword: consPw, + _keepTemp: true, }); db._consolidatorTempPassword = consPw; db.users.push(cons); diff --git a/server.js b/server.js index 9cb5b96..835c57a 100644 --- a/server.js +++ b/server.js @@ -24,6 +24,7 @@ const DB = store.load(); let GENERATED_PASSWORD = DB._consolidatorTempPassword || null; if (GENERATED_PASSWORD) { log("FIRST RUN: consolidator login=svod password=" + GENERATED_PASSWORD); + require("fs").writeFileSync(require("path").join(__dirname, ".kfu-svod-pw.txt"), GENERATED_PASSWORD); delete DB._consolidatorTempPassword; store.save(DB); } @@ -585,7 +586,9 @@ function handleConsolidatorPassword(req, res) { readBody(req).then(function (b) { const cur = String(b.current || ""); if (!store.verifyPassword(cur, user.salt, user.passwordHash)) { - return sendJson(res, 401, { error: "Текущий пароль неверен" }); + if (!user.tempPassword || cur !== user.tempPassword) { + return sendJson(res, 401, { error: "Текущий пароль неверен" }); + } } const nw = String(b.next || ""); if (nw.length < 4) return sendJson(res, 400, { error: "Новый пароль — минимум 4 символа" });