Files
bookhoard/templates/settings.go
T
John O'Keefe b9f797789f
Release / build-and-push (push) Successful in 3m9s
feat: registration_enabled admin setting — hides signup surfaces, gates the API
One boolean (Security > Public Registration) switches the whole public
signup lifecycle: front page + login links, the logged-out sidebar's
Create-an-account (via a package-level templates hook so shared page
templates keep their signatures), GET /register -> 302 /login, and an
early 403 on POST /api/auth/register. First-user exception preserved:
zero admins keeps every route and link reachable for bootstrapping —
same 'users exist' reasoning as the setup gate. Admin user creation is
unaffected by design.

Live E2E verified: flag off hides all surfaces and blocks the POST
(403), flag on restores them (201); the admin UI renders the row
automatically.
2026-10-03 23:54:07 -04:00

28 lines
1.0 KiB
Go

package templates
// Package-level signup-visibility hook, wired once at startup the same way
// middleware.SetDefaultPasswordSettings wires the password policy: a shared
// component (SidebarSignIn's "Create an account" link) renders inside many
// page templates whose call sites have no per-page flag, so the templates
// package asks a closure backed by the live settings registry instead.
// The closure is re-evaluated on every render, so admin changes apply
// immediately without a restart.
// signupVisible reports whether public signup surfaces (front page, login
// page, logged-out sidebar) should render. Unwired → default true.
var signupVisible func() bool
// SetSignupVisibility wires the live visibility closure from main. Nil-safe:
// before wiring, all surfaces render (historical behavior).
func SetSignupVisibility(f func() bool) {
signupVisible = f
}
// SignupVisible consults the wired closure (defaults to visible).
func SignupVisible() bool {
if signupVisible == nil {
return true
}
return signupVisible()
}