feat(login): add LOGIN_SHOW_TOTP and LOGIN_SHOW_VERSION config flags
Two opt-out branding/login flags, both default true (no behaviour change for existing deployments): - LOGIN_SHOW_TOTP=false hides the manual "I have a 2FA code" toggle on the login form. Deployments that delegate auth to an external directory (LDAP/OIDC) where 2FA lives in the IdP have no server-side TOTP, so the toggle only ever leads to a failed login. Server-required TOTP (totp_required, which auto-shows the field) is unaffected. - LOGIN_SHOW_VERSION=false hides the build version in the login footer, so the exact version isn't disclosed to unauthenticated visitors. Wired through the existing config registry (CONFIG_ENV_MAP) → /api/config → useConfig, matching the surrounding LOGIN_* options. Refs #519. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
2704d5dc23
commit
65cb6be8a9
@@ -74,6 +74,8 @@ export async function GET(request: NextRequest) {
|
||||
loginImprintUrl: branded<string>('loginImprintUrl', ''),
|
||||
loginPrivacyPolicyUrl: branded<string>('loginPrivacyPolicyUrl', ''),
|
||||
loginWebsiteUrl: branded<string>('loginWebsiteUrl', ''),
|
||||
loginShowTotp: configManager.get<boolean>('loginShowTotp', true),
|
||||
loginShowVersion: configManager.get<boolean>('loginShowVersion', true),
|
||||
demoMode: configManager.get<boolean>('demoMode', false),
|
||||
allowCustomJmapEndpoint: configManager.get<boolean>('allowCustomJmapEndpoint', false),
|
||||
jmapServers: redactJmapServers(parseJmapServers(configManager.get<unknown>('jmapServers', []))),
|
||||
|
||||
Reference in New Issue
Block a user