feat: registration_enabled admin setting — hides signup surfaces, gates the API
Release / build-and-push (push) Successful in 3m9s

One boolean (Security > Public Registration) switches the whole public
signup lifecycle: front page + login links, the logged-out sidebar's
Create-an-account (via a package-level templates hook so shared page
templates keep their signatures), GET /register -> 302 /login, and an
early 403 on POST /api/auth/register. First-user exception preserved:
zero admins keeps every route and link reachable for bootstrapping —
same 'users exist' reasoning as the setup gate. Admin user creation is
unaffected by design.

Live E2E verified: flag off hides all surfaces and blocks the POST
(403), flag on restores them (201); the admin UI renders the row
automatically.
This commit is contained in:
John O'Keefe
2026-10-03 23:54:07 -04:00
parent 6aaefe210a
commit b9f797789f
43 changed files with 627 additions and 519 deletions
+7 -5
View File
@@ -1,6 +1,6 @@
package templates
templ Index(loggedIn bool) {
templ Index(loggedIn bool, registrationEnabled bool) {
<!DOCTYPE html>
<html lang="en">
<head>
@@ -97,10 +97,12 @@ templ Index(loggedIn bool) {
</div>
<button type="submit" class="btn btn-primary w-full py-2.5">Sign In</button>
</form>
<p class="text-center text-sm mt-4" style="color: var(--text-secondary)">
No account?
<a href="/register" class="font-medium hover:underline" style="color: var(--accent)">Register</a>
</p>
if registrationEnabled {
<p class="text-center text-sm mt-4" style="color: var(--text-secondary)">
No account?
<a href="/register" class="font-medium hover:underline" style="color: var(--accent)">Register</a>
</p>
}
</div>
<div id="auth-result" class="mt-4 text-center text-sm"></div>
</div>