Repository navigation
v0.1.34 — Dashboard authentication (username / password)
v0.1.34 — Dashboard authentication (username / password)
The dashboard now has real accounts. Create one and it's locked down; remove them all and it's open again.
Authentication
- Username/password accounts replace the single shared token concept: each account gets its own login, stored as a bcrypt hash
- Enable it from Settings → Authentication ("Create First Account") or from the host CLI:
pulsemon auth-user add <user> <pass> - Manage accounts in Settings: add / remove, change your own password, log out
- Disable it with the "Disable Authentication" action — removes every account and reopens the dashboard
- Sessions last 30 days (sliding) via an HttpOnly cookie; a restart clears sessions (log in again)
- The last remaining account can't be removed from the account list — only the explicit disable action opens the dashboard, so a typo can't silently do it
/api/healthzstays open even when auth is on, so external monitors keep working
CLI
pulsemon auth-user add <user> <pass> # create an account (first one enables auth)
pulsemon auth-user remove <user> # delete an account (last one refused)
pulsemon auth-user list # list accounts
Settings modal
Widened (max-w-lg → max-w-3xl) so the alert routing, TLS, and authentication panels have room to breathe — especially on 1080p and up.
UI
- Login screen is now just the sign-in form (no install-specific CLI hints)
- Login gate: username + password, 30-day session
Upgrading
Existing installs: no action needed — the dashboard boots open exactly as before. When you're ready to turn auth on, create the first account from Settings or the CLI.