From 3a6b6dfd9ecc786ff11a1aa668c94683bde9a997 Mon Sep 17 00:00:00 2001 From: Lukas Date: Sun, 28 Jun 2026 20:14:24 +0200 Subject: [PATCH] fix setup redirect: check master_password_hash in saved config Reset was not putting app in unconfigured state. _needs_setup() was checking is_configured() but not verifying master_password_hash exists in saved config file. Added explicit check for this key so reset properly triggers setup form. Also removed completed Task 26 from docs. --- Docs/tasks.md | 14 -------------- src/server/middleware/setup_redirect.py | 15 ++++++++++----- 2 files changed, 10 insertions(+), 19 deletions(-) diff --git a/Docs/tasks.md b/Docs/tasks.md index 0bec265..c1b8bd0 100644 --- a/Docs/tasks.md +++ b/Docs/tasks.md @@ -1,17 +1,3 @@ -## Task 26: UI Setup Flow - Setup Form Validation Empty Password - -**Suite:** `Robot.Ui.Setup Flow` -**Test:** `Setup Form Validation Empty Password` -**Result:** FAIL -**Error:** `TimeoutError: locator.waitFor: Timeout 5000ms exceeded. waiting for locator('id=setup-form') to be visible` - -**Instructions:** -- Same root cause as Task 22: the setup form is not visible. -- Fix the suite setup so the app is in an unconfigured state before each setup flow test. -- Ensure `#setup-form` is rendered when navigating to the setup page. - ---- - ## Task 27: UI Setup Flow - Setup Form Validation Mismatched Passwords **Suite:** `Robot.Ui.Setup Flow` diff --git a/src/server/middleware/setup_redirect.py b/src/server/middleware/setup_redirect.py index 45e570c..a916ea7 100644 --- a/src/server/middleware/setup_redirect.py +++ b/src/server/middleware/setup_redirect.py @@ -81,28 +81,33 @@ class SetupRedirectMiddleware(BaseHTTPMiddleware): def _needs_setup(self) -> bool: """Check if the application needs initial setup. - + Returns: True if setup is required, False otherwise """ # Check if master password is configured if not auth_service.is_configured(): return True - + # Check if config exists and is valid try: config_service = get_config_service() config = config_service.load_config() - + + # master_password_hash must exist in saved config (not just in-memory) + # This ensures reset actually puts app in unconfigured state + if not config.other.get('master_password_hash'): + return True + # Validate the loaded config validation = config.validate_config() if not validation.valid: return True - + except (FileNotFoundError, ValueError, OSError, AttributeError): # If we can't load or validate config, setup is needed return True - + return False def _is_unresolved_completed(self) -> bool: