mirror of
https://forgejo.ellis.link/continuwuation/continuwuity/
synced 2026-10-05 16:08:07 +00:00
* Tokens + recaptcha combinations have been removed since they don't work. Docstring in config tomlto be removed later * Method 3 expanded to include both static and admin issued tokens * Methods 1-3 are the "trusted token flow" and 4-6 are the "untrusted captcha flow"
47 lines
3.5 KiB
Plaintext
47 lines
3.5 KiB
Plaintext
# Internal authentication
|
|
|
|
Continuwuity comes with an internal database for user authentication, which it uses by default. This allows for self-servicing of account registration, linking emails, and password resets.
|
|
|
|
## Registration
|
|
|
|
Registration is disabled by default. To enable it, set `allow_registration = true` in your config file and use at least one of the registration methods below.
|
|
|
|
| Method | Description | Additional configuration needed |
|
|
| ------ | --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
|
|
| 1 | Admin-issued tokens (recommended) | None. Use the [`!admin token issue`](../reference/admin/token#admin-token-issue) command |
|
|
| 2 | Static registration token | `registration_token` or `registration_token_file` |
|
|
| 3 | Token + email | Method 1 or 2 + `require_email_for_token_registration = true` in `[global.smtp]`. See [Email configuration](#email-configuration) |
|
|
| 4 | Email-only registration | `require_email_for_registration = true` in `[global.smtp]` section. See [Email configuration](#email-configuration) |
|
|
| 5 | reCAPTCHA-only registration | `recaptcha_site_key` and `recaptcha_private_site_key` |
|
|
| 6 | Email + reCAPTCHA registration | Methods 4 + 5 |
|
|
|
|
Admin-issued tokens are the recommended registration method. These tokens are well suited for private or invite-only servers, and they can be scoped with an expiry duration or given a usage limit. See the [`!admin token`](../reference/admin/token) commands for more details.
|
|
|
|
Other registration methods are meant for **untrusted, public registration**. Care must be taken when allowing these modes of operation.
|
|
|
|
## Email configuration
|
|
|
|
Continuwuity can be configured to send emails via an SMTP relay of your choice. These are used for verifying user email addresses and sending password reset links to them.
|
|
|
|
A user is associated with only **one** email address at a time.
|
|
|
|
All email options are in the `[global.smtp]` block of the [configuration file](../reference/config.mdx), and are toggled on when the block is uncommented. For example:
|
|
|
|
```toml
|
|
[global.smtp]
|
|
# Example URI for the user john@example.com on the `mail.example.net` mail server
|
|
connection_uri = "smtps://john%40example.com:password@mail.example.net:465"
|
|
sender = "John's Continuwuity server <john@example.com>"
|
|
```
|
|
|
|
A user's email address can also be modified by the [`!admin users change-email`](../reference/admin/users#admin-users-change-email) command. To view current user-email associations, use the `!admin users get-email` and `!admin users get-user-by-email` command.
|
|
|
|
Use [`!admin debug send-test-email`](../reference/admin/debug#admin-debug-send-test-email) to test that your email setup is working.
|
|
|
|
## Password resets
|
|
|
|
Password resets in Continuwuity can be made via:
|
|
|
|
- Self-service password resets. This requires a user's email to have been set up and verified.
|
|
- Using the [`!admin users reset-password`](../reference/admin/users#admin-users-reset-password) command.
|