From f0111e40d52dce14f623cd55ca43c48d7573db2e Mon Sep 17 00:00:00 2001 From: Andrey Date: Sun, 28 Jun 2026 00:32:07 +0300 Subject: [PATCH] fix(identity): disable TOTP for users; fix local credentials Stop forcing OWNER totp_required on bootstrap (TOTP off for users), and set the canonical local operator password. Document the fixed local OWNER/OPERATOR credentials in the README. These local credentials are fixed and must not be changed without explicit consent. Co-Authored-By: Claude Opus 4.8 --- README.md | 9 +++++++-- apps/backend/hub_platform/identity/bootstrap.py | 4 ++-- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index a3fa602..3cfc8e8 100644 --- a/README.md +++ b/README.md @@ -27,10 +27,15 @@ Default local URLs: - Web Chat: `http://localhost:5175` - Backend API: `http://localhost:8010/api/v1` -Create or refresh the local OWNER account: +Local accounts (TOTP disabled). These credentials are fixed — do not change them: + +- OWNER — `owner@edevs.tech` / `Owner-Local-2026` +- OPERATOR — `a.kotova@edevs.tech` / `Operator-Local-2026` + +Bootstrap the organization and both accounts: ```powershell -docker compose run --rm backend python manage.py bootstrap_owner --email owner@edevs.tech --password local-owner-password --name "Иван Петров" +docker compose run --rm backend python manage.py bootstrap_owner --email owner@edevs.tech --password Owner-Local-2026 --name "Иван Петров" ``` ## Tests diff --git a/apps/backend/hub_platform/identity/bootstrap.py b/apps/backend/hub_platform/identity/bootstrap.py index cebe31a..65189a2 100644 --- a/apps/backend/hub_platform/identity/bootstrap.py +++ b/apps/backend/hub_platform/identity/bootstrap.py @@ -64,7 +64,7 @@ def bootstrap_edevs_owner(*, email: str, password: str, full_name: str = "") -> "organization": organization, "role": EmployeeRole.OWNER, "department": sales_department, - "totp_required": True, + "totp_required": False, }, ) @@ -77,7 +77,7 @@ def bootstrap_edevs_owner(*, email: str, password: str, full_name: str = "") -> }, ) if created_operator: - operator.set_password("local-operator-password") + operator.set_password("Operator-Local-2026") operator.save(update_fields=["password"]) operator_profile, _ = EmployeeProfile.objects.get_or_create(