dograh/ui/src/lib/auth/config.ts
prabhatlepton e7494e9c21
feat(auth): gate OSS signup behind ENABLE_SIGNUP flag (#514)
* feat(auth): gate OSS signup behind ENABLE_SIGNUP flag

## Problem

The `POST /api/v1/auth/signup` endpoint is unconditionally exposed on
every OSS install. Operators running an invite-only deployment (private
customer instances, staging environments, internal-only tenants) have
no way to disable public account creation without patching the codebase.
The UI also shows the "Sign up" link on `/auth/login` regardless of
whether signup is available, so a locked-down deployment leaves broken
navigation on the login page.

## Fix

Introduce a single `ENABLE_SIGNUP` env var (default `true` — no behavior
change for existing installs) that controls signup end-to-end:

- **Backend** — `api/constants.ENABLE_SIGNUP` is read at module load.
  The signup handler returns 403 when it's false. Also exposed on
  `GET /api/v1/health` as `signup_enabled: bool` so the UI can mirror
  the operator's choice at runtime instead of at bundle-build time.

- **UI** — `getSignupEnabled()` in `lib/auth/config.ts` proxies the
  health field, `/api/config/auth` surfaces it to the browser, the
  login page conditionally renders the "Sign up" link via a one-shot
  `fetch("/api/config/auth")` in `useEffect`, and the middleware
  redirects `/auth/signup` → `/auth/login` when disabled (fires before
  Next.js can serve the statically-prerendered signup page).

- **Helm** — `config.enableSignup` (default `true`) is rendered into
  the ConfigMap as `ENABLE_SIGNUP` so operators can flip it via
  `--set config.enableSignup=false` at install/upgrade time.

Fallbacks default to `signupEnabled: true` in every layer so a fresh
install "just works" and matches the backend default.

* address review: rollout on ConfigMap change, cache TTL, no signup-link flash

Four review points on #514:

**P1 — ConfigMap Change Skips Rollout** (`configmap.yaml`). `helm upgrade
--set config.enableSignup=false` updated the ConfigMap but did NOT roll
the api pods, so running processes kept the ENABLE_SIGNUP env from
startup and continued serving the old signup behavior — including
divergence between replicas mid-upgrade.

Fix: add the standard `checksum/config` pod-template annotation on the
four backend Deployments that `envFrom` the ConfigMap (`web`,
`arq-worker`, `ari-manager`, `campaign-orchestrator`). Verified with
`helm template`: all four Deployments share the same checksum on any
given render, and flipping `config.enableSignup` changes the checksum
uniformly so kubectl sees a pod-template diff and rolls all four.

**P1 — Signup Flag Stays Cached (server)** (`ui/src/lib/auth/config.ts`).
Module-scoped cache had no TTL. `revalidate: 300` was passed on the
underlying `fetch()` but the in-memory short-circuit above ran first, so
the value never refreshed until the UI pod restarted.

Fix: add `AUTH_CONFIG_TTL_MS = 5 * 60 * 1000` (matching the fetch
revalidate hint) so the module cache and the Next fetch cache stay in
sync. Backend flag flips propagate within 5 minutes without a pod
restart.

**P1 — Middleware Redirect Uses Stale State** (`ui/src/middleware.ts`).
Same shape as above — a separate module cache with no expiry could keep
redirecting `/auth/signup → /auth/login` after signup was re-enabled, or
keep serving the statically-prerendered signup page after lockdown.

Fix: same `SERVER_CONFIG_TTL_MS = 5 * 60 * 1000` TTL on the middleware
cache.

**P2 — Signup link flash on login page** (`ui/src/app/auth/login/page.tsx`).
Initial `signupEnabled` state was `null`, so `{signupEnabled && ...}`
hid the link on first paint and it popped in after the fetch resolved
— a CLS on every login-page load on stock installs where signup is
enabled.

Fix: initialise the state to `true` (matches the backend default). The
fetch still overrides to `false` when the operator has actually
disabled signup, so the lockdown UI behavior is unchanged; only the
happy-path flash is gone.

* simplify signup flag: drop TTL caches and middleware redirect

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* resolve signup flag server-side to avoid signup link flicker

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: prabhat pankaj <prabhatiitbhu@gmail.com>
Co-authored-by: Abhishek Kumar <abhishek@a6k.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-13 14:08:25 +05:30

87 lines
3 KiB
TypeScript

import "server-only";
import { getServerBackendUrl } from "@/lib/apiClient";
export interface StackConfig {
projectId: string;
publishableClientKey: string;
}
interface ResolvedAuthConfig {
authProvider: string;
stackConfig: StackConfig | null;
signupEnabled: boolean;
}
let cachedConfig: ResolvedAuthConfig | null = null;
/**
* Fetches the auth configuration from the backend health endpoint and caches it.
*
* The backend reports the active auth provider and — when it is `stack` — the
* public Stack client config (project id + publishable client key). The UI uses
* these at runtime to initialize Stack Auth, so they no longer need to be baked
* into the browser bundle at build time. Falls back to local auth on error.
*/
async function resolveAuthConfig(): Promise<ResolvedAuthConfig> {
if (cachedConfig) {
return cachedConfig;
}
try {
const backendUrl = getServerBackendUrl();
const res = await fetch(`${backendUrl}/api/v1/health`, {
next: { revalidate: 300 },
});
if (res.ok) {
const data = await res.json();
const authProvider = (data.auth_provider as string) || "local";
const stackConfig =
authProvider === "stack" &&
data.stack_project_id &&
data.stack_publishable_client_key
? {
projectId: data.stack_project_id as string,
publishableClientKey:
data.stack_publishable_client_key as string,
}
: null;
// Default to signup-enabled when the backend omits the field (older api
// versions before the flag existed) — matches the backend's own default.
const signupEnabled = data.signup_enabled !== false;
cachedConfig = { authProvider, stackConfig, signupEnabled };
return cachedConfig;
}
} catch {
// Backend not reachable — fall through without caching so we retry next request.
}
// Unknown (backend unreachable). Return the local fallback for THIS request but
// do NOT cache it: caching here would pin the entire UI to local auth until a
// container restart if the first resolution loses the startup race with the api
// service. Leaving it uncached means the next request retries and self-heals.
return { authProvider: "local", stackConfig: null, signupEnabled: true };
}
/**
* Returns the active auth provider ('local' or 'stack'). Falls back to 'local'.
*/
export async function getAuthProvider(): Promise<string> {
return (await resolveAuthConfig()).authProvider;
}
/**
* Returns the public Stack client config when the active provider is `stack`,
* otherwise null. Server-only — the browser receives these via /api/config/auth.
*/
export async function getStackConfig(): Promise<StackConfig | null> {
return (await resolveAuthConfig()).stackConfig;
}
/**
* Returns true when the backend allows signup (`ENABLE_SIGNUP`, default true).
* The login page uses this to hide the signup link on locked-down installs.
*/
export async function getSignupEnabled(): Promise<boolean> {
return (await resolveAuthConfig()).signupEnabled;
}