feat: allow admin password overwrite during setup recovery

This commit is contained in:
Linus Rath
2026-05-16 18:21:48 +02:00
parent 307e6d5d34
commit 997bedc91b
2 changed files with 21 additions and 8 deletions
+8 -5
View File
@@ -58,13 +58,16 @@ export async function POST(request: NextRequest) {
}
try {
// 1. Provision the admin account. Aborts cleanly if one already exists
// (defence in depth - should be impossible in bootstrap state).
const created = await setInitialAdminPassword(adminPassword);
// 1. Provision the admin account. An admin.json file may already exist
// from a previous ADMIN_PASSWORD env var or an aborted earlier wizard
// run while setupComplete is still false — accept the wizard's
// password as authoritative in that case. The finish route is gated
// by the bootstrap state + one-time setup token, so this is safe.
const created = await setInitialAdminPassword(adminPassword, { allowOverwrite: true });
if (!created) {
return NextResponse.json(
{ error: 'Admin account already exists; cannot finish setup again' },
{ status: 409 },
{ error: 'Failed to write admin credentials' },
{ status: 500 },
);
}