feat: registration_enabled admin setting — hides signup surfaces, gates the API
Release / build-and-push (push) Successful in 3m9s

One boolean (Security > Public Registration) switches the whole public
signup lifecycle: front page + login links, the logged-out sidebar's
Create-an-account (via a package-level templates hook so shared page
templates keep their signatures), GET /register -> 302 /login, and an
early 403 on POST /api/auth/register. First-user exception preserved:
zero admins keeps every route and link reachable for bootstrapping —
same 'users exist' reasoning as the setup gate. Admin user creation is
unaffected by design.

Live E2E verified: flag off hides all surfaces and blocks the POST
(403), flag on restores them (201); the admin UI renders the row
automatically.
This commit is contained in:
John O'Keefe
2026-10-03 23:54:07 -04:00
parent 6aaefe210a
commit b9f797789f
43 changed files with 627 additions and 519 deletions
+9 -2
View File
@@ -62,7 +62,7 @@ func registerFrontendRoutes(cfg *Config) {
var buf bytes.Buffer
sessionExpired := c.QueryParam("session") == "expired"
deleted := c.QueryParam("deleted") == "true"
err := templates.Login(sessionExpired, deleted).Render(c.Request().Context(), &buf)
err := templates.Login(sessionExpired, deleted, templates.SignupVisible()).Render(c.Request().Context(), &buf)
if err != nil {
return err
}
@@ -70,6 +70,13 @@ func registerFrontendRoutes(cfg *Config) {
})
e.GET("/register", func(c *echo.Context) error {
// Registration can be disabled by admins. The first-user exception
// keeps the page reachable on an unconfigured server (zero admins) —
// see templates.SignupVisible for the shared reasoning. Redirect
// (not 404) so stale links and bookmarks land somewhere sensible.
if !templates.SignupVisible() {
return c.Redirect(http.StatusFound, "/login")
}
var buf bytes.Buffer
err := templates.Register().Render(c.Request().Context(), &buf)
if err != nil {
@@ -101,7 +108,7 @@ func registerFrontendRoutes(cfg *Config) {
loggedIn = err == nil && token.Valid
}
err = templates.Index(loggedIn).Render(c.Request().Context(), &buf)
err = templates.Index(loggedIn, templates.SignupVisible()).Render(c.Request().Context(), &buf)
if err != nil {
return err
}