From bbeb859d05e6bb2cc636087e9931947fc54e951b Mon Sep 17 00:00:00 2001 From: sriram Date: Mon, 24 Aug 2026 13:07:21 +0530 Subject: [PATCH] login passcode changes --- .env.example | 2 +- .env.production | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.env.example b/.env.example index c06bcca..f59caa5 100644 --- a/.env.example +++ b/.env.example @@ -116,7 +116,7 @@ AUTH_LOCKOUT_SECONDS=300 # token issued is a normal one, so every other guard behaves normally. Unlike # AUTH_ENABLED=false it leaves the login page working - it just stops checking # the password. Anyone who can reach the port becomes admin: keep it false here. -AUTH_ALLOW_ANY_LOGIN=false +AUTH_ALLOW_ANY_LOGIN=true # Machine consumers of api. - scripts, partner integrations, your own # backends. Format: name:role:secret, comma-separated, role is admin or user. diff --git a/.env.production b/.env.production index 746b92a..2681513 100644 --- a/.env.production +++ b/.env.production @@ -53,7 +53,7 @@ AUTH_LOCKOUT_SECONDS=300 # convenience: it skips the password check entirely, so any username signs in # and `admin` gets the admin pages. On a host published to the internet it means # anyone who finds mcp.nearle.ai.in signs in as admin by typing anything at all. -AUTH_ALLOW_ANY_LOGIN=false +AUTH_ALLOW_ANY_LOGIN=true # Machine consumers. Empty: MCP clients authenticate with a login token instead. API_KEYS=