Requested: dev-token.sh/.ps1 tokens should last 3h by default, with an argument to override the duration. Server-verified finding: STALWART_RECOVERY_ADMIN (the break-glass account docker-compose.yml and the scripts used) always issues OAuth tokens with a fixed 1h expiry, regardless of the server's configured accessTokenExpiry — confirmed against the live container, including after changing the setting and restarting. Confirmed x:ApiKey objects, by contrast, support an arbitrary expiresAt set per request, and their secret works directly as a bearer token. Add scripts/dev-server-init.sh (+ .ps1): a one-time, idempotent setup step that completes the server's bootstrap wizard (default domain, no TLS certificate request), creates a real "devadmin" admin account, and sets the server's default OAuth token lifetime to 3h. Rework dev-token.sh/.ps1 to authenticate as devadmin and create an x:ApiKey with a caller-supplied expiry (`dev-token.sh 1800` for 30 minutes, defaults to 10800s/3h) instead of running the OAuth PKCE flow against the recovery account. Verified end-to-end against a fresh container, including a real browser session against the running WebUI. Also includes an incidental package-lock.json sync (was still pinned to v1.0.8 / stale dependency ranges from before the upstream merge).
48 lines
616 B
Plaintext
48 lines
616 B
Plaintext
# Logs
|
|
logs
|
|
*.log
|
|
npm-debug.log*
|
|
yarn-debug.log*
|
|
yarn-error.log*
|
|
pnpm-debug.log*
|
|
lerna-debug.log*
|
|
|
|
node_modules
|
|
dist
|
|
dist-ssr
|
|
*.local
|
|
|
|
# Editor directories and files
|
|
.vscode/*
|
|
!.vscode/extensions.json
|
|
.idea
|
|
.DS_Store
|
|
*.suo
|
|
*.ntvs*
|
|
*.njsproj
|
|
*.sln
|
|
*.sw?
|
|
.ignore
|
|
scripts/*
|
|
!scripts/dev-token.ps1
|
|
!scripts/dev-token.sh
|
|
!scripts/dev-server-init.ps1
|
|
!scripts/dev-server-init.sh
|
|
*.md
|
|
!README.md
|
|
!CHANGELOG.md
|
|
!AGENTS.md
|
|
!CLAUDE.md
|
|
!SCHEMA_DEVIATIONS.md
|
|
!DEVELOPMENT.md
|
|
!.agents/rules/*.md
|
|
/SPEC-*
|
|
# Tool-generated artifacts during agent sessions
|
|
.playwright-mcp/
|
|
outputs/
|
|
.vite_*.log
|
|
.tmp_*
|
|
*.py
|
|
webui.zip
|
|
release_body.md
|