Files
project-manager/.env.example
T
aneurinandClaude Sonnet 5 7da881bb78 Add a config toggle to turn off new user registration
APP_ALLOW_REGISTRATION (default true) gates the only "sign up" this app has --
the account-creation side effect of POST /api/auth/magic-link. When false, an
unknown address is silently ignored (find-only, no findOrCreateByEmail) while
an existing address still gets its sign-in link as normal; the response is
identical either way (202, same message), so there's still no enumeration
signal.

- Config::allowRegistration, read from APP_ALLOW_REGISTRATION.
- AuthController::requestLoginLink takes the flag; only looks up (doesn't
  create) when it's off.
- docker-compose.yml / .env.example / README document the new var.
- ApiTestCase::reconfigure() rebuilds the app against changed env (same
  database) for tests that need a non-default Config; two new AuthTest
  cases cover both halves (blocks a new address, doesn't block an existing
  one). 59 tests pass.

Verified against the rebuilt container: with the flag on (default), a new
address gets a link and an account; switched off via the same env var, a
brand-new address gets the same 202 but no email and no user row, while an
address that already had an account still receives its link.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 18:19:48 +01:00

47 lines
1.7 KiB
Bash

# Copy to .env and adjust as needed. All values are optional and have sane
# development defaults (see src/Support/Config.php).
# Show full exception details in API error responses. Never enable in production.
APP_DEBUG=false
# Directory for generated files: the SQLite database and the JWT signing key.
# Defaults to <project>/storage. The Docker setup points this at a volume
# outside the bind-mounted source.
STORAGE_PATH=storage
# Path to the SQLite database file (absolute, or relative to the project root).
# Defaults to <STORAGE_PATH>/database.sqlite.
DATABASE_PATH=storage/database.sqlite
# Secret used to sign JWTs. Leave blank to auto-generate one into storage/secret.key.
JWT_SECRET=
# How long an issued token stays valid, in seconds (default: 86400 = 24h).
JWT_TTL=86400
# When false, POST /api/auth/magic-link only signs existing users in -- an
# unknown address is silently ignored (same response either way) rather than
# creating a new account. Closes sign-ups without touching existing users.
APP_ALLOW_REGISTRATION=true
# Base URL the app is reached at. Verification magic links point here, e.g.
# <APP_URL>/verify-email?token=... The Docker image serves the SPA and the API
# together on http://localhost:8080; a host `npm run dev` serves it on :5173.
APP_URL=http://localhost:8080
# Email delivery.
# mail — PHP's built-in mail() function (default)
# smtp — the SMTP server configured below
# log — append messages to MAIL_LOG_PATH instead of sending (dev/test)
MAIL_TRANSPORT=mail
MAIL_FROM=no-reply@todo.test
MAIL_FROM_NAME=Projects
MAIL_LOG_PATH=storage/mail.log
# Only used when MAIL_TRANSPORT=smtp.
MAIL_SMTP_HOST=
MAIL_SMTP_PORT=587
MAIL_SMTP_USERNAME=
MAIL_SMTP_PASSWORD=
MAIL_SMTP_ENCRYPTION=tls # tls | ssl | none