Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated. Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
24 lines
629 B
Go
24 lines
629 B
Go
package profile
|
|
|
|
import "testing"
|
|
|
|
func TestAllowAnonymous(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
url string
|
|
want bool
|
|
}{
|
|
{"empty is private", "", false},
|
|
{"whitespace only is private", " ", false},
|
|
{"configured url is public", "https://memos.example.com", true},
|
|
{"configured url with padding is public", " https://memos.example.com ", true},
|
|
}
|
|
for _, c := range cases {
|
|
t.Run(c.name, func(t *testing.T) {
|
|
p := &Profile{InstanceURL: c.url}
|
|
if got := p.AllowAnonymous(); got != c.want {
|
|
t.Fatalf("AllowAnonymous() with InstanceURL=%q = %v, want %v", c.url, got, c.want)
|
|
}
|
|
})
|
|
}
|
|
}
|