Extract serverSetupRequest type and resolveSetupSigningKeys(): when no keys are provided the server generates a fresh Ed25519 pair (existing behaviour); when a private key is provided it is validated and the public key derived from it (public key may be omitted or supplied for cross-check). Mismatched pairs are rejected 400. Remove configure-secrets route from welcome-mode router (was only usable with Docker socket mounted, unreachable in that mode). Add inferPublicURL() helper to fill publicURL from X-Forwarded-* headers when the operator omits it. pq.QuoteLiteral() used for password in ALTER USER. Tests: generate-when-missing, use-provided-pair, reject-mismatched-pair.
129 KiB
1057x719px
129 KiB
1057x719px