(c *gin.Context)
| 486 | |
| 487 | // Generate the root password. The plaintext is returned in this |
| 488 | // response only — it is never stored, only the bcrypt hash is |
| 489 | // persisted via the transactional Provision below. |
| 490 | plainPassword, err := configstore.GeneratePassword() |
| 491 | if err != nil { |
| 492 | c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to generate password"}) |
| 493 | return |
| 494 | } |
| 495 | hash, err := configstore.HashPassword(plainPassword) |
| 496 | if err != nil { |
| 497 | c.JSON(http.StatusInternalServerError, gin.H{"error": "failed to hash password"}) |
| 498 | return |
| 499 | } |
| 500 | |
| 501 | // orgID was already validated as a DNS-1123 label at the top of the |
| 502 | // handler (validateDucklingOrgID) — that's all the Trino catalog/group |
| 503 | // naming needs, since TrinoCatalogName sanitizes it injectively |
| 504 | // (org_<sanitize(Name)>). It also makes the org id a legal Kubernetes |
| 505 | // Secret data key, which the tenant-password projection requires. No |
nothing calls this directly
no test coverage detected