memos/server
boojack d1cef7a9ab feat(auth): add private instance mode derived from instance_url
Run the instance in private mode when instance_url is not configured: the API rejects anonymous requests except the auth-bootstrap set (sign-in, token refresh, instance profile/settings, SSO providers, share-link access) plus first-run user creation, and the web UI redirects anonymous visitors to /auth instead of /explore. Setting instance_url keeps the current public behavior. Access tokens and personal access tokens are never gated.

Enforcement lives in a shared Authorizer used by both the Connect interceptor and the gRPC-gateway middleware; the file server applies the same rule to public-memo attachments and avatars. Also merges the duplicated Authenticate/AuthenticateToUser token dispatch behind resolveBearer, dedups the AuthContext unauthenticated state, extracts the redirect decision into a pure shouldGatePrivateInstance helper, and prints the access mode at startup.
2026-07-05 22:48:00 +08:00
..
auth feat(auth): add private instance mode derived from instance_url 2026-07-05 22:48:00 +08:00
notification feat(notification): add smtp email settings 2026-05-01 18:48:21 +08:00
router feat(auth): add private instance mode derived from instance_url 2026-07-05 22:48:00 +08:00
runner fix(s3presign): preserve motion media payload 2026-05-09 22:51:56 +08:00
cors.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
cors_test.go fix(cors): open API to any origin for token auth, keep cookies same-origin 2026-06-14 23:20:34 +08:00
server.go feat: add OpenAPI-driven MCP support (#6026) 2026-06-09 09:16:50 +08:00