Users
An instance has one user, created from the command line: there is no default account, and the password never goes through an argument, a variable or the logs.
sh
docker compose run --rm api user create <name> # asks for the password twice, without echo
docker compose run --rm api user password <name> # a new password; signs out every session
printf '%s\n' "$password" | docker compose run --rm -T api user create <name> # from a script- Passwords have at least 15 characters: a passphrase, or one from a password manager. They are stored hashed with argon2id.
- Signing in opens a session for 30 days, ended sooner by 7 days without use or by signing out.
- After 10 failed attempts within 15 minutes, for a username or from an address, attempts are refused until the 15 minutes are over. Restarting
apiclears this. - A forgotten password is replaced with
user password.