memos/server/router/api/v1/test
boojack d1cef7a9ab feat(auth): add private instance mode derived from instance_url
Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated.

Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
2026-07-05 22:48:00 +08:00
..
ai_service_test.go refactor: split STT and Audio-LLM into separate interfaces (#5928) 2026-05-03 00:21:58 +08:00
attachment_service_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
auth_service_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
auth_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
authz_test.go feat(auth): add private instance mode derived from instance_url 2026-07-05 22:48:00 +08:00
idp_service_test.go fix(api): make credentials write-only and restrict sensitive settings to admins 2026-03-29 07:34:00 +08:00
instance_admin_cache_test.go feat: update instance profile to use admin user instead of initialized flag 2026-01-28 23:27:53 +08:00
instance_service_test.go fix(instance): add needs_setup so admin-less instances aren't treated as fresh 2026-06-21 22:14:15 +08:00
instance_stats_test.go feat(stats): admin instance resource statistics 2026-05-01 23:15:56 +08:00
memo_attachment_service_test.go fix(security): enforce attachment ownership on memo updates 2026-05-01 18:23:53 +08:00
memo_relation_service_test.go fix(security): implement security review recommendations (#5228) 2025-11-06 23:32:27 +08:00
memo_service_benchmark_test.go fix: reduce list memo query overhead (#5880) 2026-04-22 09:31:48 +08:00
memo_service_test.go fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
memo_share_service_test.go fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
reaction_service_test.go fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
shortcut_service_test.go fix: fix legacy username auth flows (#5885) 2026-04-23 22:35:38 +08:00
sse_handler_test.go fix(sse): stream initial response and refresh tokens 2026-05-09 09:15:50 +08:00
test_helper.go chore(settings): show build commit in version info 2026-04-27 08:51:11 +08:00
user_email_visibility_test.go fix(api): restrict user email exposure to self and admins (#5784) 2026-03-25 22:02:08 +08:00
user_notification_test.go fix: delete user cleanup (#5981) 2026-05-25 22:10:29 +08:00
user_resource_name_test.go fix: fix legacy username auth flows (#5885) 2026-04-23 22:35:38 +08:00
user_search_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
user_service_delete_test.go feat: redesign account and SSO management (#5886) 2026-04-24 09:08:58 +08:00
user_service_email_username_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
user_service_registration_test.go fix(auth): harden authorization and username validation (#5890) 2026-04-25 21:24:16 +08:00
user_service_stats_test.go feat(stats): support filtered all-user stats 2026-05-09 09:11:04 +08:00
user_setting_test.go feat(settings): move tag metadata to user settings (#6017) 2026-06-07 23:58:00 +08:00