feat: registration_enabled admin setting — hides signup surfaces, gates the API
Release / build-and-push (push) Successful in 3m9s
Release / build-and-push (push) Successful in 3m9s
One boolean (Security > Public Registration) switches the whole public signup lifecycle: front page + login links, the logged-out sidebar's Create-an-account (via a package-level templates hook so shared page templates keep their signatures), GET /register -> 302 /login, and an early 403 on POST /api/auth/register. First-user exception preserved: zero admins keeps every route and link reachable for bootstrapping — same 'users exist' reasoning as the setup gate. Admin user creation is unaffected by design. Live E2E verified: flag off hides all surfaces and blocks the POST (403), flag on restores them (201); the admin UI renders the row automatically.
This commit is contained in:
@@ -65,6 +65,7 @@ var SettingDefaults = []SettingDefault{
|
||||
{Key: "password_require_lower", Value: "true", Type: SettingTypeBool, Category: "security", Group: "Password Quality", Description: "Require at least one lowercase letter (a-z)"},
|
||||
{Key: "password_require_number", Value: "true", Type: SettingTypeBool, Category: "security", Group: "Password Quality", Description: "Require at least one number (0-9)"},
|
||||
{Key: "password_require_special", Value: "true", Type: SettingTypeBool, Category: "security", Group: "Password Quality", Description: "Require at least one special character"},
|
||||
{Key: "registration_enabled", Value: "true", Type: SettingTypeBool, Category: "security", Group: "Public Registration", Description: "Allow users to create their own accounts (admins can always create accounts)"},
|
||||
{Key: "opds_default_page_size", Value: "50", Type: SettingTypeInt, Min: "1", Max: "500", Category: "api", Group: "OPDS Catalog", Description: "Default OPDS page size"},
|
||||
{Key: "opds_max_page_size", Value: "200", Type: SettingTypeInt, Min: "1", Max: "1000", Category: "api", Group: "OPDS Catalog", Description: "Maximum OPDS page size"},
|
||||
{Key: "device_rate_sync_per_min", Value: "60", Type: SettingTypeInt, Min: "1", Max: "10000", Category: "api", Group: "Device Rate Limits", Description: "Device sync requests per minute"},
|
||||
@@ -188,6 +189,12 @@ func (r *SettingsRegistry) ScanPollInterval() time.Duration {
|
||||
// AutoScanEnabled reports whether auto-scanning is on.
|
||||
func (r *SettingsRegistry) AutoScanEnabled() bool { return r.getBool("auto_scan_enabled") }
|
||||
|
||||
// RegistrationEnabled reports whether public signup is allowed. Admin user
|
||||
// creation is never affected — only self-service registration rides this
|
||||
// flag; handlers additionally grant the first-user exception (see
|
||||
// handlers/auth.go Register).
|
||||
func (r *SettingsRegistry) RegistrationEnabled() bool { return r.getBool("registration_enabled") }
|
||||
|
||||
// DefaultTimezone returns the configured default timezone name.
|
||||
func (r *SettingsRegistry) DefaultTimezone() string { return r.raw("default_timezone") }
|
||||
|
||||
|
||||
@@ -174,6 +174,21 @@ func (h *AuthHandler) Register(c *echo.Context) error {
|
||||
req.Role = strings.ToLower(req.Role)
|
||||
}
|
||||
|
||||
// Public registration can be disabled by admins. The giveaway exception
|
||||
// is an unconfigured server: with zero admins the first-user-becomes-
|
||||
// admin bootstrap path must stay reachable (mirrors setupRedirect-
|
||||
// Middleware's "users exist" reasoning). Admin account creation via the
|
||||
// admin API never rides this route, so it is unaffected regardless.
|
||||
if h.settings != nil && !h.settings.RegistrationEnabled() {
|
||||
count, countErr := h.db.CountAdmins(c.Request().Context())
|
||||
if countErr != nil || count > 0 {
|
||||
if c.Request().Header.Get("HX-Request") == "true" {
|
||||
return c.HTML(http.StatusForbidden, `<div class="text-red-500">Registration is disabled on this server</div>`)
|
||||
}
|
||||
return c.JSON(http.StatusForbidden, map[string]string{"error": "registration is disabled on this server"})
|
||||
}
|
||||
}
|
||||
|
||||
if _, err := h.db.GetUserByEmail(c.Request().Context(), req.Email); err == nil {
|
||||
if c.Request().Header.Get("HX-Request") == "true" {
|
||||
return c.HTML(http.StatusConflict, `<div class="text-red-500">Email already exists</div>`)
|
||||
|
||||
@@ -62,7 +62,7 @@ func registerFrontendRoutes(cfg *Config) {
|
||||
var buf bytes.Buffer
|
||||
sessionExpired := c.QueryParam("session") == "expired"
|
||||
deleted := c.QueryParam("deleted") == "true"
|
||||
err := templates.Login(sessionExpired, deleted).Render(c.Request().Context(), &buf)
|
||||
err := templates.Login(sessionExpired, deleted, templates.SignupVisible()).Render(c.Request().Context(), &buf)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -70,6 +70,13 @@ func registerFrontendRoutes(cfg *Config) {
|
||||
})
|
||||
|
||||
e.GET("/register", func(c *echo.Context) error {
|
||||
// Registration can be disabled by admins. The first-user exception
|
||||
// keeps the page reachable on an unconfigured server (zero admins) —
|
||||
// see templates.SignupVisible for the shared reasoning. Redirect
|
||||
// (not 404) so stale links and bookmarks land somewhere sensible.
|
||||
if !templates.SignupVisible() {
|
||||
return c.Redirect(http.StatusFound, "/login")
|
||||
}
|
||||
var buf bytes.Buffer
|
||||
err := templates.Register().Render(c.Request().Context(), &buf)
|
||||
if err != nil {
|
||||
@@ -101,7 +108,7 @@ func registerFrontendRoutes(cfg *Config) {
|
||||
loggedIn = err == nil && token.Valid
|
||||
}
|
||||
|
||||
err = templates.Index(loggedIn).Render(c.Request().Context(), &buf)
|
||||
err = templates.Index(loggedIn, templates.SignupVisible()).Render(c.Request().Context(), &buf)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user