`minstrel admin reset-password` copied the new login password into
subsonic_password, which is stored in plain text because Subsonic t/s
sign-in needs it. Every account recovered through the CLI had its login
password readable in the database, and changing the password later left
the copy behind.
- reset-password now changes only password_hash.
- Migration 0064 clears every subsonic_password, removing the copies.
- Settings gets a Subsonic password card: the server generates a random
password, shows it once, and it can be regenerated or turned off
(GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather
than user-chosen so it can never be a reused password.
- docs/security.md describes the separate password instead of the known
issue.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>