Self-hosted installs (SELF_HOSTED=true, the default) now close /register
to the public. Workspace invites still work — the AcceptInvite page
links into /register with ?invite={id}, the middleware persists that
into the session, and POST /register passes through.
- EnsureRegistrationEnabled middleware gates GET/POST /register.
Accepts ?invite=… (URL) or pending_invite_id (session) as the pass.
- RegisteredUserController::store clears the marker after signup.
- AcceptInvite.vue passes invite.id in the register link's query string.
- Login.vue hides the "Sign up" link when self_hosted.
- UserSeeder bootstraps a single admin (admin@trypost.it / password).
Idempotent; not wired into DatabaseSeeder — operator runs
`php artisan db:seed --class=UserSeeder` per the install docs.
- Tests cover both flag values for every changed surface.
Docs PR: see trypost-docs self-hosting/installation.mdx step 3.
27 lines
648 B
PHP
27 lines
648 B
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Http\Middleware\App;
|
|
|
|
use Closure;
|
|
use Illuminate\Http\Request;
|
|
use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
|
|
|
|
class EnsureRegistrationEnabled
|
|
{
|
|
public function handle(Request $request, Closure $next): mixed
|
|
{
|
|
if (! config('trypost.self_hosted')) {
|
|
return $next($request);
|
|
}
|
|
|
|
if ($inviteId = $request->query('invite') ?? $request->session()->get('pending_invite_id')) {
|
|
$request->session()->put('pending_invite_id', $inviteId);
|
|
|
|
return $next($request);
|
|
}
|
|
|
|
throw new NotFoundHttpException;
|
|
}
|
|
}
|