CreateWebSession has exactly one caller, internal/httpd/accounts.go:89, the
/login?token= handler. The token that reaches it can only be minted by
web login over SSH. Web signup requires pasting a public key
(internal/httpd/accounts.go:211).
So anyone without an SSH key cannot use the web UI at all. admin user create
already makes --key optional, which means an admin can create an account today
that has no way to authenticate anywhere.
web.password_auth exists in the config and is rejected at startup
(internal/config/config.go:325) as not implemented.
Fix: let an unauthenticated visitor request a login link by username or verified email address, delivered by the SMTP that already sends verification mail.
This does not widen what a browser session can do. The web dispatches with
ViaAPI: true, so a session cannot run any SSHOnly command — secrets, token
minting, admin, audit, and mirror credentials stay on SSH regardless of how the
session was obtained.
Design: docs/specs/2026-09-04-email-login-design.md.
referenced in commit c7a2a1a6ab by cmc: e2e: a link minted before suspension opens nothing
2026-09-05 04:20 UTC