fix(09): WR-11 reject ambiguous admin logins and cross-field login or email collisions

This commit is contained in:
Jakub Zych
2026-10-01 21:17:50 +02:00
parent eb8c727790
commit 331351a73c
5 changed files with 70 additions and 8 deletions

View File

@@ -77,7 +77,7 @@ The application binary has two commands for operators:
./bin/acme admin:reset-password admin@example.com --password '<secret>'
```
`admin:create` creates an activated administrator; `--login` defaults to the lower-cased email and `--role <code>` assigns a role. `admin:reset-password` takes a login or an email, sets the password and revokes every token issued before the reset. Passwords are hashed with bcrypt at `admin.password.bcrypt_cost`, so hashes copied from a WinterCMS database keep working.
`admin:create` creates an activated administrator; `--login` defaults to the lower-cased email and `--role <code>` assigns a role. It refuses a login or email that matches another administrator's login or email in either field, because a sign-in identifier that matches two administrators is answered like a wrong password. `admin:reset-password` takes a login or an email, sets the password and revokes every token issued before the reset. Passwords are hashed with bcrypt at `admin.password.bcrypt_cost`, so hashes copied from a WinterCMS database keep working.
> [!TIP]
> Pass the password through an environment variable or a prompt of your shell rather than typing it on the command line, where it stays in the shell history.