Skip to content

feat: read INITIAL_PASSWORD env var during setup - #8439

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.49from
linhdmn:fix/read-INITIAL_PASSWORD-env
Jul 26, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.49from
linhdmn:fix/read-INITIAL_PASSWORD-env

Conversation

@linhdmn

@linhdmn linhdmn commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Summary

Allow users to set the admin password via the INITIAL_PASSWORD environment variable during omniroute setup.

Problem

The resolvePassword() function in bin/cli/commands/setup.mjs only reads the password from the --password CLI flag or interactive prompt. The INITIAL_PASSWORD env var (loaded via loadEnvFile() in omniroute.mjs) is completely ignored.

Fix

Add a one-line check for process.env.INITIAL_PASSWORD in resolvePassword(). The new resolution priority is:

  1. --password CLI flag (highest)
  2. INITIAL_PASSWORD env var
  3. Interactive prompt
  4. Skip / no password

Change

bin/cli/commands/setup.mjs — +1 line

Allow users to set the admin password via the INITIAL_PASSWORD
environment variable instead of requiring the --password CLI flag
or interactive prompt. Falls between --password flag and interactive
prompt in resolution priority.
@linhdmn
linhdmn requested a review from diegosouzapw as a code owner July 24, 2026 15:19
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks for this — nice catch, and a clean minimal fix. I confirmed with a local test that omniroute setup --non-interactive currently leaves the dashboard login disabled (requireLogin: false, no password stored) even when INITIAL_PASSWORD is set, until the actual server boots once (there's a separate runtime bootstrap in src/lib/auth/managementPassword.ts that self-heals this on server startup, but your fix closes the gap for CLI-only/scripted setups where the server hasn't started yet). Your one-line change correctly routes through the existing setupPassword()/hashManagementPassword() flow, so the 8-character minimum and hashing still apply — good.

The one thing we need before this can merge is test coverage: the existing tests/unit/cli-setup-command.test.ts doesn't exercise the INITIAL_PASSWORD path yet, and our contribution guidelines require a regression test for any production code change. Could you add:

  1. A test that --non-interactive (and the interactive "no --password" case) picks up INITIAL_PASSWORD and results in requireLogin: true with a correctly-hashed password.
  2. A test that an explicit --password flag still wins over INITIAL_PASSWORD (the priority order you described in the PR body).

Happy to help if you'd like guidance on the test setup (see the withTempEnv helper already in that test file). Once tests are in, this should be good to merge.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw
diegosouzapw merged commit a095ebc into diegosouzapw:release/v3.8.49 Jul 26, 2026
3 checks passed
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @linhdmn — merged into release/v3.8.49 via the local merge-train (validated as one combined tree: full test:unit + test:vitest 274/274 on the 32-core box, tip d4b9ce6016). Your commit keeps its authorship. 🚀

@diegosouzapw diegosouzapw mentioned this pull request Jul 28, 2026
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
* feat: read INITIAL_PASSWORD env var during setup

Allow users to set the admin password via the INITIAL_PASSWORD
environment variable instead of requiring the --password CLI flag
or interactive prompt. Falls between --password flag and interactive
prompt in resolution priority.

* test(cli): cover INITIAL_PASSWORD env var in setup resolvePassword

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: linh.doan <linh.doan@be.com.vn>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* feat: read INITIAL_PASSWORD env var during setup

Allow users to set the admin password via the INITIAL_PASSWORD
environment variable instead of requiring the --password CLI flag
or interactive prompt. Falls between --password flag and interactive
prompt in resolution priority.

* test(cli): cover INITIAL_PASSWORD env var in setup resolvePassword

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: linh.doan <linh.doan@be.com.vn>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants