Skip to content

First sign-in

A new installation has one administrator account, local@localhost, with no password yet. Nobody can sign in with it until a password is set. You set it with the normal Forgot password flow. Without an email service, the reset link is printed in the server console, so only whoever runs the server can claim the administrator account.

  1. On the sign-in page, choose Forgot password?

    Forgot password

  2. Enter local@localhost and choose Send reset link. The page confirms: “On this installation the link is printed in the server console.”

  3. Look at the terminal running npm start. You will see a box like this:

    ┌─ password reset ───────────────────────────────────────────
    │ for Local User <local@localhost>
    │ link http://127.0.0.1:4100/#/reset?token=…
    │ valid for 30 minutes, once
    └────────────────────────────────────────────────────────────

    On a Linux server installed with the deployment scripts, the console is the system journal: sudo journalctl -u autotestx -n 50.

  4. Open the link, then enter and confirm a new password (at least 10 characters). Choose Set password and sign in.

    Choose a new password

You are now signed in as Local User: organization administrator of Northstar Ops and Admin of its Default Project.

After first sign-in

Tip: change the name and email of this account under Accounts → Edit, so reports show a real person.

There are three ways for people to get an account.

Invite them into the organization (recommended). Go to Org members → Invite. Enter their email and name, choose an organization role (Member or Administrator), and optionally a project and a project role. This creates the account and gives access in one step. They then go to the sign-in page, choose Forgot password?, and set their own password through the reset link. Without a mail service, you (the person running the server) forward the link from the console.

Add a sign-in account only. Accounts → + Add member creates an account with a platform role. That role only controls who may manage sign-in accounts. It gives no access to any project. Use this when you will assign project roles separately.

They register themselves. The sign-in page has Create an account. A self-registered person is always a normal member, never an administrator. An email that already belongs to a member cannot be registered again; that person uses Forgot password instead.

Note for administrators: self-registration is currently open to anyone who can reach the server. The policy lives in selfRegistration() in packages/server/src/auth-routes.ts. Change it there to allow only invited people or one email domain before you expose the server to the internet.

New people do not see any project until someone gives them a role in one. See People, roles and permissions.

Rule Value
Minimum password length 10 characters
Failed attempts before lock-out 5 within 15 minutes
Lock-out duration 15 minutes (or reset the password)
Session lifetime 7 days, or 12 hours without activity
Reset link validity 30 minutes, single use
Changing your password signs you out everywhere else

→ Your first test in 10 minutes