Add built-in TLS (self-signed autogen, CA pinning) and optional closed registration
coordinator / test (push) Canceled after 0s
python / test (push) Canceled after 0s
release / binaries (amd64, darwin) (push) Canceled after 0s
release / binaries (amd64, linux) (push) Canceled after 0s
release / binaries (amd64, windows) (push) Canceled after 0s
release / binaries (arm64, darwin) (push) Canceled after 0s
release / binaries (arm64, linux) (push) Canceled after 0s
release / binaries (arm64, windows) (push) Canceled after 0s
release / wheel (push) Canceled after 0s
release / image (push) Canceled after 0s
users / test (push) Canceled after 0s
release / release (push) Canceled after 0s

This commit is contained in:
Emil
2026-08-03 20:17:32 +03:00
parent 049113cec8
commit 63c8ef0b8a
15 changed files with 329 additions and 7 deletions
@@ -5,6 +5,7 @@ import (
"errors"
"log/slog"
"net/http"
"os"
"github.com/google/uuid"
@@ -38,6 +39,12 @@ func (h *Handlers) handleHealth(w http.ResponseWriter, _ *http.Request) {
// handleRegister creates an account. It returns 201 with the public user view,
// 409 if the email is taken, or 400 on a malformed body / weak password.
func (h *Handlers) handleRegister(w http.ResponseWriter, r *http.Request) {
// Standalone deployments can close self-service registration while keeping
// the bootstrap admin and existing accounts (USERSERVICE_DISABLE_REGISTRATION=1).
if os.Getenv("USERSERVICE_DISABLE_REGISTRATION") == "1" {
writeJSON(w, http.StatusForbidden, errorResponse{Error: "registration disabled", RequestID: requestIDFrom(r.Context())})
return
}
var req registerRequest
if !decodeJSON(w, r, &req) {
return
@@ -479,3 +479,12 @@ func TestAdminListsUsersAndKeys(t *testing.T) {
t.Errorf("admin revoke unknown key: got %d, want 404", rec.Code)
}
}
func TestRegistrationDisabledEnv(t *testing.T) {
t.Setenv("USERSERVICE_DISABLE_REGISTRATION", "1")
h := newTestServer()
rec := do(t, h, http.MethodPost, "/register", "", map[string]string{"email": "blocked@x.io", "password": "pw"})
if rec.Code != http.StatusForbidden {
t.Errorf("register when disabled: got %d, want 403", rec.Code)
}
}