feat: registration_enabled admin setting — hides signup surfaces, gates the API
Release / build-and-push (push) Successful in 3m9s
Release / build-and-push (push) Successful in 3m9s
One boolean (Security > Public Registration) switches the whole public signup lifecycle: front page + login links, the logged-out sidebar's Create-an-account (via a package-level templates hook so shared page templates keep their signatures), GET /register -> 302 /login, and an early 403 on POST /api/auth/register. First-user exception preserved: zero admins keeps every route and link reachable for bootstrapping — same 'users exist' reasoning as the setup gate. Admin user creation is unaffected by design. Live E2E verified: flag off hides all surfaces and blocks the POST (403), flag on restores them (201); the admin UI renders the row automatically.
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
package templates
|
||||
|
||||
templ Login(sessionExpired bool, deleted bool) {
|
||||
templ Login(sessionExpired bool, deleted bool, registrationEnabled bool) {
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
@@ -53,10 +53,12 @@ templ Login(sessionExpired bool, deleted bool) {
|
||||
<button type="submit" class="btn btn-primary w-full py-2.5">Sign In</button>
|
||||
</form>
|
||||
<div id="result" class="mt-4 text-center text-sm"></div>
|
||||
<p class="text-center mt-6 text-sm" style="color: var(--text-secondary)">
|
||||
Don't have an account?
|
||||
<a href="/register" class="font-medium hover:underline" style="color: var(--accent)">Sign up</a>
|
||||
</p>
|
||||
if registrationEnabled {
|
||||
<p class="text-center mt-6 text-sm" style="color: var(--text-secondary)">
|
||||
Don't have an account?
|
||||
<a href="/register" class="font-medium hover:underline" style="color: var(--accent)">Sign up</a>
|
||||
</p>
|
||||
}
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
|
||||
Reference in New Issue
Block a user