chore: rotate Beszel admin password
This commit is contained in:
parent
5de89f22d4
commit
be31212508
1 changed files with 20 additions and 17 deletions
37
compose.yaml
37
compose.yaml
|
|
@ -20,33 +20,36 @@ services:
|
|||
start_period: 15s
|
||||
retries: 3
|
||||
|
||||
beszel-verifier:
|
||||
beszel-password-changer:
|
||||
image: python:3.11-alpine
|
||||
container_name: beszel-verifier
|
||||
container_name: beszel-password-changer
|
||||
restart: "no"
|
||||
depends_on:
|
||||
beszel:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
BESZEL_EMAIL: ${BESZEL_ADMIN_EMAIL}
|
||||
BESZEL_PASSWORD: ${BESZEL_ADMIN_PASSWORD}
|
||||
BESZEL_OLD_PASSWORD: ${BESZEL_OLD_PASSWORD}
|
||||
BESZEL_NEW_PASSWORD: ${BESZEL_NEW_PASSWORD}
|
||||
command:
|
||||
- python
|
||||
- -c
|
||||
- |
|
||||
import json, os, time, urllib.request
|
||||
import json, os, urllib.request
|
||||
base = "http://beszel:8090"
|
||||
body = json.dumps({"identity": os.environ["BESZEL_EMAIL"], "password": os.environ["BESZEL_PASSWORD"]}).encode()
|
||||
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
|
||||
with urllib.request.urlopen(req, timeout=10) as response:
|
||||
token = json.load(response)["token"]
|
||||
result = []
|
||||
for _ in range(12):
|
||||
req = urllib.request.Request(base + "/api/collections/systems/records?perPage=50", headers={"Authorization": token})
|
||||
email = os.environ["BESZEL_EMAIL"]
|
||||
old = os.environ["BESZEL_OLD_PASSWORD"]
|
||||
new = os.environ["BESZEL_NEW_PASSWORD"]
|
||||
def auth(password):
|
||||
body = json.dumps({"identity": email, "password": password}).encode()
|
||||
req = urllib.request.Request(base + "/api/collections/users/auth-with-password", data=body, headers={"Content-Type": "application/json"})
|
||||
with urllib.request.urlopen(req, timeout=10) as response:
|
||||
items = json.load(response)["items"]
|
||||
result = [{"name": item["name"], "status": item["status"]} for item in items]
|
||||
if result and all(item["status"] == "up" for item in result):
|
||||
break
|
||||
time.sleep(5)
|
||||
print(json.dumps({"verified_systems": result}, sort_keys=True), flush=True)
|
||||
return json.load(response)
|
||||
session = auth(old)
|
||||
record_id = session["record"]["id"]
|
||||
body = json.dumps({"password": new, "passwordConfirm": new}).encode()
|
||||
req = urllib.request.Request(base + "/api/collections/users/records/" + record_id, data=body, method="PATCH", headers={"Authorization": session["token"], "Content-Type": "application/json"})
|
||||
with urllib.request.urlopen(req, timeout=10) as response:
|
||||
updated = json.load(response)
|
||||
verified = auth(new)
|
||||
print(json.dumps({"password_changed": updated.get("id") == record_id, "new_login_ok": bool(verified.get("token"))}), flush=True)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue