diff --git a/src/content/docs/docs/security.md b/src/content/docs/docs/security.md index 2a85dd8..ae189a3 100644 --- a/src/content/docs/docs/security.md +++ b/src/content/docs/docs/security.md @@ -24,6 +24,7 @@ Run it on a trusted network, or behind a reverse proxy that terminates TLS and a - Sessions expire after an idle lifetime, 12 hours by default. A session in use is reissued past the halfway mark. - Login is rate-limited to 5 attempts per IP per 15 minutes. Counters are in memory, so a restart clears them and they are not shared across replicas. Run a single instance behind any proxy. - Changing the password rotates the session secret, signing out every other device. Sign out all devices does the same without changing the password. +- Changing the password, or turning protection off, needs the current password as well as a session. Wrong attempts count toward the login limit of 5 per IP per 15 minutes. Authentication is only in force once a password is stored. Until then, the endpoint that sets one accepts the first caller. See [First setup](/docs/first-setup/). diff --git a/src/content/docs/docs/settings-reference.md b/src/content/docs/docs/settings-reference.md index b0b6620..a5fd980 100644 --- a/src/content/docs/docs/settings-reference.md +++ b/src/content/docs/docs/settings-reference.md @@ -38,7 +38,7 @@ If every app suddenly shows as unhealthy, the socket proxy address is the usual | Setting | What it does | | --- | --- | -| Password Protection | Sets or changes the dashboard password. Between 8 and 1024 characters. Leave blank to keep the existing one. | +| Password Protection | Sets or changes the dashboard password. Between 8 and 1024 characters. Leave blank to keep the existing one. Changing the password, or turning protection off, asks for the current password. | | Sign out all devices | Ends every session everywhere, including the one you are using. Use it if you think a session may be compromised. | Locked out? See [password recovery](/docs/troubleshooting/#i-forgot-the-password-and-i-am-locked-out). diff --git a/src/content/docs/docs/troubleshooting.md b/src/content/docs/docs/troubleshooting.md index e180819..414135c 100644 --- a/src/content/docs/docs/troubleshooting.md +++ b/src/content/docs/docs/troubleshooting.md @@ -228,6 +228,9 @@ Messages shown in the admin, and what each one means. | Message | Meaning | | --- | --- | | `Could not connect to dashboard API` | The UI loaded but the API did not answer. See [above](#could-not-connect-to-dashboard-api). | +| `The current password is incorrect.` | The current password typed to change or remove the password did not match. Nothing was saved. | +| `The password was changed elsewhere. Reload the page and try again.` | The password changed on another device while this save ran. Nothing was saved. | +| `Too many attempts. Try again later.` | 5 wrong passwords from this IP in 15 minutes. Wait, then try again. See [above](#one-persons-failed-logins-lock-everyone-out). | | `Enter the credential again for: ...` | The request a secret belonged to changed, so the secret was cleared. Re-enter and save. | | `Nothing at that address answered.` | The socket proxy address is unreachable from inside the container. Usually a proxy published on the host's loopback. | | `That name is resolved by Docker, which answers only for containers on a shared network.` | The socket proxy service name is not on a network Stackyard shares. |