Lost password or authenticator

Lost Who resets it How
Authenticator a superadmin Reset authenticator on /admin/users
Authenticator whoever runs the host python scripts/reset_admin_password.py --reset-totp <username>
Password whoever runs the host python scripts/reset_admin_password.py --username <username>
  • Run the script inside the container: docker exec -it openwhistle python scripts/reset_admin_password.py ….
  • Every reset ends every session of the account at once. After an authenticator reset, the old app stops working.
  • A password reset by the script is in the audit log as admin.password_reset. The next login must change it.
  • A reset in /admin/users makes the account new again: new authenticator, and a new temporary password in place of the old one.
  • The temporary password is shown once, to the superadmin. It is in no log and no audit entry. Hand it over in person.
  • With it, the next login goes to /admin/mfa/setup to enrol a new app, as for a new account. Then the holder chooses a new password (Your account).
  • An LDAP or single sign-on account has no local password. It keeps its directory or provider login and enrols a new app.
  • The script prints the new secret and its otpauth:// URI once. Hand them over in person.
  • A superadmin cannot reset their own authenticator in the browser: it would end their session and leave the account behind a password. Another superadmin or the script does it.
  • The script works for any account, the last superadmin included.
  • Every reset is in the audit log as admin.totp_reset. With DEMO_MODE, the demo accounts cannot be reset.

Edit this page on GitHub