Skip to content

Require Admin Credentials Outside Development/Test Environments - #277

Open
jarednorman wants to merge 3 commits into
solidusio:mainfrom
SuperGoodSoft:jared/require-admin-credentials
Open

jarednorman wants to merge 3 commits into
solidusio:mainfrom
SuperGoodSoft:jared/require-admin-credentials

Conversation

@jarednorman

Copy link
Copy Markdown
Member

Summary

No one should be using the defaults outside of dev/test, so I've made it bail out if you try to. Included a couple other little minor fixes.

Checklist

Check out our PR guidelines for more details.

The following are mandatory for all PRs:

The following are not always needed:

  • 📖 I have updated the README to account for my changes.
  • 📑 I have documented new code with YARD.
  • 🛣️ I have opened a PR to update the guides.
  • ✅ I have added automated tests to cover my changes.
  • 📸 I have attached screenshots to demo visual changes.

🤖 Generated with Claude Code

The seed used to fall back to the documented admin@example.com / test123
credentials in every environment, so a database seeded in production or
staging without ADMIN_EMAIL and ADMIN_PASSWORD set got a fully privileged
admin account with publicly known credentials.

Keep the defaults for development and test, where the sandbox, the docs and
extension test suites rely on them, and abort with instructions everywhere
else.
The --admin-email, --admin-password and --interactive options passed the
credentials to railties:install:migrations, which never creates a user, so
they had no effect. Run spree_auth:admin:create after migrating when either
option is given. Callers that pass neither are unchanged.
@jarednorman
jarednorman requested a review from a team October 4, 2026 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants