Lost password or authenticator
| Lost | Who resets it | How |
|---|---|---|
| Authenticator | a superadmin | Reset authenticator on /admin/users |
| Authenticator | whoever runs the host | python scripts/reset_admin_password.py --reset-totp <username> |
| Password | whoever runs the host | python scripts/reset_admin_password.py --username <username> |
- Run the script inside the container:
docker exec -it openwhistle python scripts/reset_admin_password.py …. - Every reset ends every session of the account at once. After an authenticator reset, the old app stops working.
- A password reset by the script is in the audit log as
admin.password_reset. The next login must change it. - A reset in
/admin/usersmakes the account new again: new authenticator, and a new temporary password in place of the old one. - The temporary password is shown once, to the superadmin. It is in no log and no audit entry. Hand it over in person.
- With it, the next login goes to
/admin/mfa/setupto enrol a new app, as for a new account. Then the holder chooses a new password (Your account). - An LDAP or single sign-on account has no local password. It keeps its directory or provider login and enrols a new app.
- The script prints the new secret and its
otpauth://URI once. Hand them over in person. - A superadmin cannot reset their own authenticator in the browser: it would end their session and leave the account behind a password. Another superadmin or the script does it.
- The script works for any account, the last superadmin included.
- Every reset is in the audit log as
admin.totp_reset. WithDEMO_MODE, the demo accounts cannot be reset.