Skip to content

v0.1.34 — Dashboard authentication (username / password)

Choose a tag to compare

@invizen invizen released this 08 Oct 03:24

v0.1.34 — Dashboard authentication (username / password)

The dashboard now has real accounts. Create one and it's locked down; remove them all and it's open again.

Authentication

  • Username/password accounts replace the single shared token concept: each account gets its own login, stored as a bcrypt hash
  • Enable it from Settings → Authentication ("Create First Account") or from the host CLI:
    pulsemon auth-user add <user> <pass>
    
  • Manage accounts in Settings: add / remove, change your own password, log out
  • Disable it with the "Disable Authentication" action — removes every account and reopens the dashboard
  • Sessions last 30 days (sliding) via an HttpOnly cookie; a restart clears sessions (log in again)
  • The last remaining account can't be removed from the account list — only the explicit disable action opens the dashboard, so a typo can't silently do it
  • /api/healthz stays open even when auth is on, so external monitors keep working

CLI

pulsemon auth-user add <user> <pass>    # create an account (first one enables auth)
pulsemon auth-user remove <user>        # delete an account (last one refused)
pulsemon auth-user list                 # list accounts

Settings modal

Widened (max-w-lg → max-w-3xl) so the alert routing, TLS, and authentication panels have room to breathe — especially on 1080p and up.

UI

  • Login screen is now just the sign-in form (no install-specific CLI hints)
  • Login gate: username + password, 30-day session

Upgrading

Existing installs: no action needed — the dashboard boots open exactly as before. When you're ready to turn auth on, create the first account from Settings or the CLI.