feat(identity): offer account creation to visitors who have none #344
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!344
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/forgejo-create-account-link"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #336.
A visitor who clicks "Sign In" on the git host is redirected into the identity provider's username
prompt. Local registration is off — the portal is the only sign-up path — so someone without an
account reaches a form they cannot complete and is offered nothing else.
The fix goes in the git host's navbar, not the identity provider. Kanidm has no configuration
for this: its documented customisation surface is site display name, site image, per-application
display names and images, and a custom stylesheet — and CSS
content:cannot produce a clickableanchor. Rewriting the response body at the proxy to inject one is technically viable and explicitly
rejected: it would put a pre-1.0 third-party module on the TLS-terminating edge for a cosmetic gain.
Three parts:
custom/extra_links.tmplhook rendering into the navbar's left menu,gated on the visitor being signed out. Label and path both follow
ctx.Locale.Lang, so an Englishreader gets "Create account" →
/en/signupand a Swedish one "Skapa konto" →/signup. Theapplication's own
registerkey is deliberately unused: it labels the disabled local sign-uproute, so it would name the wrong destination.
existing stylesheet override. The comment states that this is text and not a link, and that
generated content is not user-selectable in Chromium or WebKit, so the URL is kept short enough to
retype.
when selectors moved; a rule that silently no-ops after an upgrade is worse than no rule.
The selector is scoped, and that was verified mechanically
form#loginalone is not precise — it is reused on the password, TOTP, backup-code,mechanism-choose and device-login templates. Running a real
:has()engine over every 1.10.4 logintemplate plus the live page:
Verification
The navbar hook was rendered by a real instance and curled: the link appears between Explore and
Help when signed out and is absent when signed in. The sign-in note was screenshotted in headless
Chromium in both dark and light schemes, and confirmed absent when the same page is rebuilt with the
password-step form.
ansible-playbook site.yml --syntax-checkclean,ansible-lint0 failures, Prettier andmarkdownlint clean. The health gate stays a pure variable comparison — no network, no session — so it
behaves identically under
--checkrather than fabricating a pass.Note the sign-in page no longer offers account recovery, which was disabled in production earlier
today; the rule assumes nothing about that link.
1427742f20160c0cf958160c0cf9589d69ce7e1d9d69ce7e1dca2b8a11a7ca2b8a11a74d04ceb0024d04ceb002993a653414993a653414324fd0b6b1324fd0b6b141c0551aa8