Files
project-manager/docker-compose.yml
T
aneurinandClaude Sonnet 5 7da881bb78 Add a config toggle to turn off new user registration
APP_ALLOW_REGISTRATION (default true) gates the only "sign up" this app has --
the account-creation side effect of POST /api/auth/magic-link. When false, an
unknown address is silently ignored (find-only, no findOrCreateByEmail) while
an existing address still gets its sign-in link as normal; the response is
identical either way (202, same message), so there's still no enumeration
signal.

- Config::allowRegistration, read from APP_ALLOW_REGISTRATION.
- AuthController::requestLoginLink takes the flag; only looks up (doesn't
  create) when it's off.
- docker-compose.yml / .env.example / README document the new var.
- ApiTestCase::reconfigure() rebuilds the app against changed env (same
  database) for tests that need a non-default Config; two new AuthTest
  cases cover both halves (blocks a new address, doesn't block an existing
  one). 59 tests pass.

Verified against the rebuilt container: with the flag on (default), a new
address gets a link and an account; switched off via the same env var, a
brand-new address gets the same 202 but no email and no user row, while an
address that already had an account still receives its link.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-04 18:19:48 +01:00

50 lines
1.8 KiB
YAML

name: php-project-manager
services:
app:
build: .
image: php-project-manager
ports:
- "8080:80"
environment:
APP_DEBUG: "${APP_DEBUG:-false}"
# Generated files (SQLite DB + JWT signing key) go here, on the `storage`
# volume below.
STORAGE_PATH: /var/www/storage
# Leave blank to auto-generate a secret into the storage volume on first run.
JWT_SECRET: "${JWT_SECRET:-}"
JWT_TTL: "${JWT_TTL:-86400}"
# Set to false to stop new accounts being created (existing users can
# still sign in).
APP_ALLOW_REGISTRATION: "${APP_ALLOW_REGISTRATION:-true}"
# The SPA and the API are both served from this container.
APP_URL: "${APP_URL:-http://localhost:8080}"
# Deliver to the Mailpit catcher below; read mail at http://localhost:8025.
MAIL_TRANSPORT: "${MAIL_TRANSPORT:-smtp}"
MAIL_FROM: "${MAIL_FROM:-no-reply@todo.test}"
MAIL_SMTP_HOST: "${MAIL_SMTP_HOST:-mailpit}"
MAIL_SMTP_PORT: "${MAIL_SMTP_PORT:-1025}"
MAIL_SMTP_USERNAME: "${MAIL_SMTP_USERNAME:-}"
MAIL_SMTP_PASSWORD: "${MAIL_SMTP_PASSWORD:-}"
MAIL_SMTP_ENCRYPTION: "${MAIL_SMTP_ENCRYPTION:-none}"
volumes:
# Only generated state is mounted. The app itself — PHP source and the
# built frontend — is baked into the image; rebuild to pick up changes:
# docker compose up -d --build
- storage:/var/www/storage
depends_on:
- mailpit
restart: unless-stopped
# Development mail catcher (Mailpit — the maintained MailHog successor). ~15 MB,
# single Go binary, messages held in memory. Web UI: http://localhost:8025
mailpit:
image: axllent/mailpit:v1.31
ports:
- "8025:8025" # web UI + REST API
- "1025:1025" # SMTP (also reachable in-network as mailpit:1025)
restart: unless-stopped
volumes:
storage: