mirror of
https://github.com/mikecarper/MeshCore.git
synced 2026-09-02 06:54:18 +00:00
Adds an admin-password field to the setup wizard and the LAN editor, so a node's password can be set during onboarding and rotated later without a serial console. The key maps to the top-level `password` CLI command rather than a `set` handler, so it is classified separately from WC_ALLOWED_SET_KEYS. It is the only key granted that treatment, which keeps the allowlist the sole route to `set` and leaves no general path from a batch to arbitrary CLI commands. Accepted in both modes: MODE_OFF is refused earlier in handleConfigPost, LAN required a login to get that far, and the setup AP implies physical proximity. Restricting rotation to the AP would have forced a bridge outage (`set bridge off` + `start webconfig ap`) just to change a password. First onboarding is gated server-side: while the setup AP is up and no WiFi is configured, a batch that reboots or sets wifi.ssid must also carry a password, so neither the Advanced editor nor a crafted request can save WiFi and strand the node on the factory password. The flag is latched at AP start, so a save that fails partway cannot drop the requirement on retry. The CLI's `password` command echoes the new secret back in its reply, and replies are served to the client over the open setup AP, so the reply is overwritten with "OK" before it can be serialized. UI: the field lives with the other NodePrefs settings (wizard step 2, and the Node card on the Radio tab) rather than beside the WiFi password, which is a different credential. Confirm fields mirror their password twin and are cleared whenever it is, so a stale confirm value cannot fail a later save as a spurious mismatch. Validation runs ahead of the WiFi-changed split so a password-only save is still checked, and reveals the Radio tab before reporting, since the save bar spans every tab.