diff --git a/routstr/core/admin.py b/routstr/core/admin.py index 0b1245e1..c6cc8ee0 100644 --- a/routstr/core/admin.py +++ b/routstr/core/admin.py @@ -164,6 +164,28 @@ async def update_settings(request: Request, update: SettingsUpdate) -> dict: return data +class SetupRequest(BaseModel): + password: str + + +@admin_router.post("/api/setup") +async def initial_setup(request: Request, payload: SetupRequest) -> dict[str, object]: + try: + current = SettingsService.get() + except Exception: + current = settings + if getattr(current, "admin_password", ""): + raise HTTPException(status_code=409, detail="Admin password already set") + pw = (payload.password or "").strip() + if len(pw) < 8: + raise HTTPException( + status_code=400, detail="Password must be at least 8 characters" + ) + async with create_session() as session: + await SettingsService.update({"admin_password": pw}, session) + return {"ok": True} + + class WithdrawRequest(BaseModel): amount: int mint_url: str | None = None @@ -206,6 +228,67 @@ def login_form() -> str: """ +def setup_form() -> str: + return """ + + + + + + +
+

🔧 Initial Admin Setup

+

Create a secure password for your admin dashboard.

+
+ + + +
+
+
+ + + """ + + def info(content: str) -> str: return f""" @@ -233,7 +316,7 @@ def admin_auth() -> str: except Exception: admin_pw = os.getenv("ADMIN_PASSWORD", "") if admin_pw == "": - return info("Please set a secure ADMIN_PASSWORD= in your ENV variables.") + return setup_form() else: return login_form()