release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
`minstrel admin reset-password` copied the new login password into subsonic_password, which is stored in plain text because Subsonic t/s sign-in needs it. Every account recovered through the CLI had its login password readable in the database, and changing the password later left the copy behind. - reset-password now changes only password_hash. - Migration 0064 clears every subsonic_password, removing the copies. - Settings gets a Subsonic password card: the server generates a random password, shows it once, and it can be regenerated or turned off (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather than user-chosen so it can never be a reused password. - docs/security.md describes the separate password instead of the known issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
11 lines
699 B
SQL
11 lines
699 B
SQL
-- `minstrel admin reset-password` used to copy the new login password into
|
|
-- subsonic_password, so every account recovered through the CLI had its login
|
|
-- password stored in plain text, and a later password change in Settings left
|
|
-- that copy behind (M462 #5026). The CLI no longer writes this column; a
|
|
-- Subsonic password is now generated separately in Settings and is never the
|
|
-- login password. Clearing every value here removes the copies already made.
|
|
--
|
|
-- Accounts whose Subsonic client signs in with t/s stop working until the user
|
|
-- generates a Subsonic password (or switches the client to an API key).
|
|
UPDATE users SET subsonic_password = NULL WHERE subsonic_password IS NOT NULL;
|