Allow self hosted instances to restrict registrations to requiring an invite code or just disabling it completely

(#1035) Feature Shipped self-hosting

Problem

As a self hosted user I want to host a small instance for a relatively small private friend group. However currently there is no way to disable public registration to the instance. This means that any random publics can register on a self hosted instance and use the resources.

Proposed solution

Add an option similar to how matrix resolves this namely there can be 3 states:
  1. Open public registration to an instance
  2. Registrations are allowed but a valid invite code must be submitted with the registration request to be accepted
  3. Registrations are disabled entirely and new accounts can only be manually created in the backend (or maybe admin panel) by the admin

Notes (optional)

If federation or OIDC will be considered in the future there could also need to be considerations made perhaps allowing the federation for all, only allowing from specific hosts or disabling it entirely. Also worth noting that achieving this is not entirely impossible right now, however it requires some manual remapping of routes in the reverse proxy. For example right now you could force a 404 on the /register endpoint and have a route rule to map /register/<some_secret_code> to the /register endpoint of the API. You can just skip the second part to disable registrations entirely.

1 comment

Sign in with Fluxer to comment and vote.
Comment by @SolunaCG
RexSystem 1 vote originally by @SolunaCG on GitHub
This would be especially useful if invite-based registrations could be configured with:
  • maximum number of uses
  • expiration dates
  • optional role assignment
  • optional email requirement
Example: A self-hosted operator wants to invite 5 friends to try Fluxer. Instead of opening registrations globally, they create an invite that is valid for 5 registrations and expires after 24 hours. This keeps registrations controlled while making onboarding much easier for small communities.