feat(server): add flag to disable new sign ups (#6752)
This commit is contained in:
@@ -53,6 +53,9 @@ AFFiNE.port = 3010;
|
|||||||
// AFFiNE.metrics.enabled = true;
|
// AFFiNE.metrics.enabled = true;
|
||||||
//
|
//
|
||||||
// /* Authentication Settings */
|
// /* Authentication Settings */
|
||||||
|
// /* Whether allow anyone signup */
|
||||||
|
// AFFiNE.auth.allowSignup = true;
|
||||||
|
//
|
||||||
// /* User Signup password limitation */
|
// /* User Signup password limitation */
|
||||||
// AFFiNE.auth.password = {
|
// AFFiNE.auth.password = {
|
||||||
// minLength: 8,
|
// minLength: 8,
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import {
|
|||||||
import type { Request, Response } from 'express';
|
import type { Request, Response } from 'express';
|
||||||
|
|
||||||
import {
|
import {
|
||||||
|
Config,
|
||||||
PaymentRequiredException,
|
PaymentRequiredException,
|
||||||
Throttle,
|
Throttle,
|
||||||
URLHelper,
|
URLHelper,
|
||||||
@@ -43,7 +44,8 @@ export class AuthController {
|
|||||||
private readonly url: URLHelper,
|
private readonly url: URLHelper,
|
||||||
private readonly auth: AuthService,
|
private readonly auth: AuthService,
|
||||||
private readonly user: UserService,
|
private readonly user: UserService,
|
||||||
private readonly token: TokenService
|
private readonly token: TokenService,
|
||||||
|
private readonly config: Config
|
||||||
) {}
|
) {}
|
||||||
|
|
||||||
@Public()
|
@Public()
|
||||||
@@ -74,6 +76,10 @@ export class AuthController {
|
|||||||
} else {
|
} else {
|
||||||
// send email magic link
|
// send email magic link
|
||||||
const user = await this.user.findUserByEmail(credential.email);
|
const user = await this.user.findUserByEmail(credential.email);
|
||||||
|
if (!user && !this.config.auth.allowSignup) {
|
||||||
|
throw new BadRequestException('You are not allows to sign up.');
|
||||||
|
}
|
||||||
|
|
||||||
const result = await this.sendSignInEmail(
|
const result = await this.sendSignInEmail(
|
||||||
{ email: credential.email, signUp: !user },
|
{ email: credential.email, signUp: !user },
|
||||||
redirectUri
|
redirectUri
|
||||||
|
|||||||
@@ -87,6 +87,10 @@ export class AuthResolver {
|
|||||||
@Args('email') email: string,
|
@Args('email') email: string,
|
||||||
@Args('password') password: string
|
@Args('password') password: string
|
||||||
) {
|
) {
|
||||||
|
if (!this.config.auth.allowSignup) {
|
||||||
|
throw new ForbiddenException('You are not allowed to sign up.');
|
||||||
|
}
|
||||||
|
|
||||||
validators.assertValidCredential({ email, password });
|
validators.assertValidCredential({ email, password });
|
||||||
const user = await this.auth.signUp(name, email, password);
|
const user = await this.auth.signUp(name, email, password);
|
||||||
await this.auth.setCookie(ctx.req, ctx.res, user);
|
await this.auth.setCookie(ctx.req, ctx.res, user);
|
||||||
|
|||||||
@@ -214,6 +214,8 @@ export interface AFFiNEConfig {
|
|||||||
* authentication config
|
* authentication config
|
||||||
*/
|
*/
|
||||||
auth: {
|
auth: {
|
||||||
|
allowSignup: boolean;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* The minimum and maximum length of the password when registering new users
|
* The minimum and maximum length of the password when registering new users
|
||||||
*
|
*
|
||||||
|
|||||||
@@ -147,6 +147,7 @@ export const getDefaultAFFiNEConfig: () => AFFiNEConfig = () => {
|
|||||||
playground: true,
|
playground: true,
|
||||||
},
|
},
|
||||||
auth: {
|
auth: {
|
||||||
|
allowSignup: true,
|
||||||
password: {
|
password: {
|
||||||
minLength: node.prod ? 8 : 1,
|
minLength: node.prod ? 8 : 1,
|
||||||
maxLength: 32,
|
maxLength: 32,
|
||||||
|
|||||||
Reference in New Issue
Block a user