security: reject weak/default admin panel passwords at startup
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
0333f33b29
commit
84ffb8363d
2 changed files with 11 additions and 2 deletions
|
|
@ -7,8 +7,10 @@ BOT_USERNAME=YourBot_robot
|
|||
# Telegram user IDs allowed into the bot's admin menu and the web panel, comma-separated
|
||||
ADMIN_IDS=111111111,222222222
|
||||
|
||||
# Web panel login password (change it any time with: mbs pass)
|
||||
ADMIN_PANEL_PASSWORD=change-me
|
||||
# Web panel login password — must be a real random string, min 8 chars
|
||||
# (panel refuses to start on "change-me"/"admin"/etc). Generate one: openssl rand -base64 12
|
||||
# Change it any time with: mbs pass
|
||||
ADMIN_PANEL_PASSWORD=
|
||||
|
||||
# Domains — point all three A records at this server's IP (see README)
|
||||
PANEL_DOMAIN=panel.example.com
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue