Repository navigation
feat(admins): configurable password generator - #48
Merged
Merged
Conversation
Every password field that sets a credential (Add admin, Edit admin, Your account, server RCON) gets a "Generate password" button that opens one shared dialog. The admin can tweak length and character sets, copy the value, and fill the field + its confirmation. - Sbpp\Security\PasswordGenerator: random_int based, guarantees one character per enabled set, shuffles, clamps length to [max(8, config.password.minlength), 128], optional look-alike exclusion. Symbols skip quotes/backslash/;/space/backtick so values are safe in server.cfg and SourceMod configs. - Owner defaults in Settings > Main (config.password.generator.*), seeded by data.sql and backfilled by updater migration 813. - admins.generate_password accepts per-request options, falls back to the defaults, and echoes the effective options + bounds. - web/scripts/password-generator.js replaces the page-local Add admin handler; loaded once from core/footer.tpl. - REST POST /admins fallback password uses the same generator; the now-unused Crypto::genPassword() is removed. - REST PATCH /settings types the new keys as bool/int. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
maxijabase
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a configurable password generator to every panel form that sets a credential:
admins.generate_passwordgate)Each generate button opens one shared dialog. It shows a random password and lets the admin:
0 O 1 l I) on or offOwners set the starting options under Settings > Main > Password generator defaults.
Implementation
Sbpp\Security\PasswordGenerator(new): the only place passwords get generated.random_int, puts at least one character from every enabled set, then runs a Fisher-Yates shuffle.[max(8, config.password.minlength), 128], so a generated password always passes the panel's own minimum.;, space, and backtick, so values are safe inserver.cfgand SourceMod configs.config.password.generator.*rows. They are seeded indata.sqland backfilled for upgraded installs by updater migration 813 (INSERT IGNORE, idempotent). RESTPATCH /settingstypes the new keys as bool / int.admins.generate_password: now accepts optionallength/lowercase/uppercase/digits/symbols/exclude_ambiguous. Missing options fall back to the defaults. The response echoes the effective options plusmin_length/max_length. If every character set is off, it returns avalidationerror on fieldcharset. The permission gate is unchanged.api-contract.jsis regenerated.web/scripts/password-generator.js(new,// @ts-check): one document-level delegate for[data-password-generator][data-password-targets="id,id2"], loaded fromcore/footer.tpl. It replaces the page-local generator handler on Add admin.POST /adminsnow builds its fallback password with the same generator.Crypto::genPassword()had no callers left and is removed.docs/.../setup/admins-and-groups.md, a namespacing row and a "Where to find what" row in AGENTS.md, and a directory-layout line in ARCHITECTURE.md.Test plan
PasswordGeneratorTest: length clamping, per-set guarantee, look-alike exclusion, console-safe symbols, empty-set rejection, plus a check that the keys and defaults match betweendata.sqland813.phpAdminsTest::testGeneratePassword*: request options, length clamp, empty charset, configured defaultsgenerate_password_success,youraccount_ownerAdminsTestare the local CRLF snapshot baseline and also fail onmainworkers: 1):password-generator.spec.ts: options shape the output, empty charset blocks "Use password", configured defaults seed the dialog, Settings save round-trip, Edit admin, Your account, axe checkadmins-add-form.spec.tsmailpitcontainer that wasn't running locally🤖 Generated with Claude Code