Add design spec for env-var-controlled sign-up
This commit is contained in:
@@ -0,0 +1,62 @@
|
|||||||
|
# Allow Sign-Up Via Environment Variable
|
||||||
|
|
||||||
|
Date: 2026-08-19
|
||||||
|
Status: Draft
|
||||||
|
|
||||||
|
## Summary
|
||||||
|
|
||||||
|
Replace the current "count of users" check that gates sign-up with a
|
||||||
|
single environment variable. This lets an operator explicitly control
|
||||||
|
whether public sign-up is available, instead of Podstalk inferring it
|
||||||
|
from how many users already exist.
|
||||||
|
|
||||||
|
## Motivation
|
||||||
|
|
||||||
|
Today `ServeSignup` disables sign-up once a user already exists
|
||||||
|
(`store.UserCount() > 0`). That is implicit and easy to get wrong: the
|
||||||
|
first user must register before anyone can log in, and once that happens
|
||||||
|
no one can ever register again. Controlling this with an explicit
|
||||||
|
environment variable is predictable and self-documenting.
|
||||||
|
|
||||||
|
## Behavior
|
||||||
|
|
||||||
|
New environment variable: `PODSTALK_ALLOW_SIGNUP`.
|
||||||
|
|
||||||
|
- Unset or any falsy value (`false`, `0`, `no`, `off`): sign-up **disabled**.
|
||||||
|
- Truthy value (`true`, `1`, `yes`, `on`): sign-up **enabled**.
|
||||||
|
|
||||||
|
Default (unset) is **disabled**.
|
||||||
|
|
||||||
|
## Changes
|
||||||
|
|
||||||
|
### `main.go`
|
||||||
|
|
||||||
|
Read `PODSTALK_ALLOW_SIGNUP` from the environment and resolve it with a
|
||||||
|
truthy-value parser. Set the resulting boolean on the `AuthHandler`.
|
||||||
|
|
||||||
|
### `handler/auth.go`
|
||||||
|
|
||||||
|
- Add an `AllowSignup bool` field to `AuthHandler`.
|
||||||
|
- `ServeSignup`: redirect to `/signin` when `!AllowSignup` (replaces the
|
||||||
|
`UserCount() > 0` check).
|
||||||
|
- Replace the `hasUsers()` helper (driven by user count) with a check on
|
||||||
|
`AllowSignup`, so the Sign In page shows/ hides the "Sign Up" nav link
|
||||||
|
based on whether sign-up is enabled.
|
||||||
|
|
||||||
|
### Unchanged
|
||||||
|
|
||||||
|
`store.UserCount()` remains in the store package. It is no longer used by
|
||||||
|
authentication but is left in place as a general utility.
|
||||||
|
|
||||||
|
## Out of Scope
|
||||||
|
|
||||||
|
- No admin/user-management UI to invite specific users.
|
||||||
|
- No change to the existing `adduser` CLI command (operator provisioning
|
||||||
|
still works regardless of the sign-up toggle).
|
||||||
|
- No change to sign-in/sign-out behavior.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
- `scripts/build` passes (gofmt, go vet, go build, docker build).
|
||||||
|
- Manual verification is limited by the sandbox; behavior relies on the
|
||||||
|
straightforward boolean branch and the truthy parser.
|
||||||
Reference in New Issue
Block a user