Admin passwd in cleartext in configuration file #1662

Closed
opened 2026-04-05 19:39:05 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @M3rcur-x on 3/30/2025

Hi,

I just setup Pangolin on my VPS and the password of my admin user is available in cleartext in the configuration file of Pangolin (config/config.yml, users -> server_admin).

Why it isn't hashed ? While this account is also stored hashed in DB.

*Originally created by @M3rcur-x on 3/30/2025* Hi, I just setup Pangolin on my VPS and the password of my admin user is available in cleartext in the configuration file of Pangolin (config/config.yml, users -> server_admin). Why it isn't hashed ? While this account is also stored hashed in DB.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1662