Commit graph

7 commits

Author SHA1 Message Date
boojack
d1cef7a9ab feat(auth): add private instance mode derived from instance_url
Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated.

Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
2026-07-05 22:48:00 +08:00
boojack
94ce1e5347 chore(settings): show build commit in version info 2026-04-27 08:51:11 +08:00
Steven
9cc970a3ea chore: fix data directory handling 2026-01-21 08:02:25 +08:00
Steven
4180613fc0 fix: update demo mode handling 2026-01-21 07:36:30 +08:00
Johnny
324f795965 fix: improve default data directory handling 2026-01-20 23:55:46 +08:00
Johnny
47ebb04dc3 refactor: remove mode flag and introduce explicit demo flag 2026-01-20 22:58:33 +08:00
Steven
f1b365f928 refactor: clean packages 2025-05-29 21:44:43 +08:00