@echo off
rem ============================================================
rem  PixelPup - Set My Personal Access Password
rem
rem  Run this on YOUR WORK COMPUTER once.
rem  Generates a unique random password, sets it on this machine,
rem  and shows it on screen. Write it down or save it to a password
rem  manager - this is what you type when connecting from home.
rem
rem  PixelPup never stores or sees this password.
rem  If you lose it, run this script again to create a new one.
rem ============================================================
Title PixelPup - Set My Access Password
setlocal

rem ---- Self-elevate (needed to set the service password) ----
net session >nul 2>&1
if %errorlevel% NEQ 0 (
    echo Requesting administrator privileges...
    "%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -Command "Start-Process -FilePath '%~f0' -Verb RunAs"
    exit /b
)

color 0B
cls
echo.
echo    ==========================================================
echo.
echo        __      _
echo     o'')}____//     P I X E L P U P
echo      `_/      )     SET MY ACCESS PASSWORD
echo      (_(_/-(_/
echo.
echo    ==========================================================
echo      Sets a permanent password on THIS computer so you can
echo      connect to it from home without a technician present.
echo.
echo      PixelPup NEVER stores or sees this password.
echo    ----------------------------------------------------------
echo.

rem ---- Check RustDesk is installed ----
if not exist "C:\Program Files\RustDesk\RustDesk.exe" (
    echo [X] RustDesk is not installed at the expected location.
    echo     Run PixelPup_Install.bat on this computer first.
    echo.
    pause
    exit /b 1
)

rem ---- Check RustDesk service is running ----
sc query RustDesk | find "RUNNING" >nul 2>&1
if errorlevel 1 (
    echo Starting RustDesk service...
    net start RustDesk >nul 2>&1
    timeout /t 3 >nul
    sc query RustDesk | find "RUNNING" >nul 2>&1
    if errorlevel 1 (
        echo [X] Could not start RustDesk service. Please run PixelPup_Install.bat first.
        pause
        exit /b 1
    )
)

rem ---- Generate a random 12-char password ----
rem  Uses mixed case + digits. Omits easily-confused characters (O 0 I l 1).
rem  The characters come from Windows' cryptographic random number generator
rem  (not Get-Random, which is predictable), each one equally likely, and the
rem  password is handed straight back to this window - it is never written to
rem  a file. The command is encoded only so cmd cannot misread its symbols;
rem  decoded it reads:
rem    $ProgressPreference = 'SilentlyContinue'
rem    $abc = 'ABCDEFGHJKLMNPQRSTUVWXYZabcdefghjkmnpqrstuvwxyz23456789'
rem    $rng = [System.Security.Cryptography.RandomNumberGenerator]::Create()
rem    $buf = New-Object byte[] 1
rem    $limit = 256 - (256 %% $abc.Length)
rem    $pw = ''
rem    while ($pw.Length -lt 12) { $rng.GetBytes($buf); if ($buf[0] -lt $limit) { $pw += $abc[$buf[0] %% $abc.Length] } }
rem    $rng.Dispose()
rem    [Console]::Out.Write($pw)
echo [1/2] Generating your unique password...
set "NEWPW="
for /f "usebackq delims=" %%p in (`%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -EncodedCommand JABQAHIAbwBnAHIAZQBzAHMAUAByAGUAZgBlAHIAZQBuAGMAZQAgAD0AIAAnAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUAJwA7ACAAJABhAGIAYwAgAD0AIAAnAEEAQgBDAEQARQBGAEcASABKAEsATABNAE4AUABRAFIAUwBUAFUAVgBXAFgAWQBaAGEAYgBjAGQAZQBmAGcAaABqAGsAbQBuAHAAcQByAHMAdAB1AHYAdwB4AHkAegAyADMANAA1ADYANwA4ADkAJwA7ACAAJAByAG4AZwAgAD0AIABbAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBSAGEAbgBkAG8AbQBOAHUAbQBiAGUAcgBHAGUAbgBlAHIAYQB0AG8AcgBdADoAOgBDAHIAZQBhAHQAZQAoACkAOwAgACQAYgB1AGYAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAGIAeQB0AGUAWwBdACAAMQA7ACAAJABsAGkAbQBpAHQAIAA9ACAAMgA1ADYAIAAtACAAKAAyADUANgAgACUAIAAkAGEAYgBjAC4ATABlAG4AZwB0AGgAKQA7ACAAJABwAHcAIAA9ACAAJwAnADsAIAB3AGgAaQBsAGUAIAAoACQAcAB3AC4ATABlAG4AZwB0AGgAIAAtAGwAdAAgADEAMgApACAAewAgACQAcgBuAGcALgBHAGUAdABCAHkAdABlAHMAKAAkAGIAdQBmACkAOwAgAGkAZgAgACgAJABiAHUAZgBbADAAXQAgAC0AbAB0ACAAJABsAGkAbQBpAHQAKQAgAHsAIAAkAHAAdwAgACsAPQAgACQAYQBiAGMAWwAkAGIAdQBmAFsAMABdACAAJQAgACQAYQBiAGMALgBMAGUAbgBnAHQAaABdACAAfQAgAH0AOwAgACQAcgBuAGcALgBEAGkAcwBwAG8AcwBlACgAKQA7ACAAWwBDAG8AbgBzAG8AbABlAF0AOgA6AE8AdQB0AC4AVwByAGkAdABlACgAJABwAHcAKQAgACAA 2^>nul`) do set "NEWPW=%%p"

if "%NEWPW%"=="" (
    echo [X] Password generation failed. Check that PowerShell is available.
    pause
    exit /b 1
)
rem  Exactly 12 characters, or stop before RustDesk is touched.
set "PWOK="
if not "%NEWPW:~11,1%"=="" if "%NEWPW:~12,1%"=="" set "PWOK=1"
if not defined PWOK (
    echo [X] Password generation returned something unexpected. Nothing was changed.
    pause
    exit /b 1
)

rem ---- Set it via RustDesk CLI ----
echo [2/2] Setting your password on this machine...
set "PWSET="
"C:\Program Files\RustDesk\RustDesk.exe" --password "%NEWPW%" 2>&1 | find "Done" >nul && set "PWSET=1"
timeout /t 2 >nul

echo.
echo    ==========================================================
echo.
echo      YOUR ACCESS PASSWORD IS:
echo.
echo          %NEWPW%
echo.
if not defined PWSET (
    echo      [!] RustDesk did not confirm that this password was set.
    echo          Test it before you rely on it. If it does not work, run
    echo          this again or contact PixelPup.
    echo.
)
echo      SAVE THIS NOW - it will not be shown again.
echo.
echo      Write it down or store it in a password manager.
echo      Use it when connecting to this computer from home.
echo.
echo      PixelPup does not store this password. If you lose it,
echo      run this script again to generate a new one.
echo.
echo    ----------------------------------------------------------
echo.
echo      NEXT STEP: install PixelPup on your home computer.
echo      Download PixelPup_Home_Install.bat from pixelpup.net
echo      and run it there.
echo.
echo    ==========================================================
echo.
pause
