Edit history

Earlier versions of Allow self hosted instances to restrict registrations to requiring an invite code or just disabling it completely, newest first.

Current version | Edited by Rex
Changes
Also worth noting that achieving this is not entirely impossible right now, however it requires some manual remapping of routes in the reverse proxy. For example right now you could force a 404 on the /register endpoint and have a route rule to map /register/<some_secret_code> to the /register endpoint of the API. You can just skip the second part to disable registrations entirely.Removed: ### ChecksRemoved: Removed: - ☑ I searched for existing discussions and didn't find a duplicate.Removed:
Show

Allow self hosted instances to restrict registrations to requiring an invite code or just disabling it completely

Problem

As a self hosted user I want to host a small instance for a relatively small private friend group. However currently there is no way to disable public registration to the instance. This means that any random publics can register on a self hosted instance and use the resources.

Proposed solution

Add an option similar to how matrix resolves this namely there can be 3 states:
  1. Open public registration to an instance
  2. Registrations are allowed but a valid invite code must be submitted with the registration request to be accepted
  3. Registrations are disabled entirely and new accounts can only be manually created in the backend (or maybe admin panel) by the admin

Notes (optional)

If federation or OIDC will be considered in the future there could also need to be considerations made perhaps allowing the federation for all, only allowing from specific hosts or disabling it entirely. Also worth noting that achieving this is not entirely impossible right now, however it requires some manual remapping of routes in the reverse proxy. For example right now you could force a 404 on the /register endpoint and have a route rule to map /register/<some_secret_code> to the /register endpoint of the API. You can just skip the second part to disable registrations entirely.
Original by Rex
Show

Allow self hosted instances to restrict registrations to requiring an invite code or just disabling it completely

Problem

As a self hosted user I want to host a small instance for a relatively small private friend group. However currently there is no way to disable public registration to the instance. This means that any random publics can register on a self hosted instance and use the resources.

Proposed solution

Add an option similar to how matrix resolves this namely there can be 3 states:
  1. Open public registration to an instance
  2. Registrations are allowed but a valid invite code must be submitted with the registration request to be accepted
  3. Registrations are disabled entirely and new accounts can only be manually created in the backend (or maybe admin panel) by the admin

Notes (optional)

If federation or OIDC will be considered in the future there could also need to be considerations made perhaps allowing the federation for all, only allowing from specific hosts or disabling it entirely. Also worth noting that achieving this is not entirely impossible right now, however it requires some manual remapping of routes in the reverse proxy. For example right now you could force a 404 on the /register endpoint and have a route rule to map /register/<some_secret_code> to the /register endpoint of the API. You can just skip the second part to disable registrations entirely.

Checks

  • ☑ I searched for existing discussions and didn't find a duplicate.