Files
felhom.eu/documentation/audits/signup-lock-2026-09-29/A/aftersetuppatch.py
T

20 lines
1.4 KiB
Python

# after_setup env per app (decision 47, controller >= 0.282.0) — appended after the signup_block line.
import os, sys
R = sys.argv[1]
VAL = {"adventurelog": ("SIGNUP_CLOSED", "true"), "calcom": ("SIGNUP_CLOSED", "true"), "gitea": ("SIGNUP_CLOSED", "true"),
"gramps-web": ("SIGNUP_CLOSED", "true"), "homebox": ("SIGNUP_OPEN", "false"), "papra": ("SIGNUP_OPEN", "false"),
"sparkyfitness": ("SIGNUP_CLOSED", "true"), "termix": ("SIGNUP_OPEN", "false"), "vikunja": ("SIGNUP_OPEN", "false")}
WHY = {"calcom": "safe from install too (the first admin is /auth/setup)", "gitea": "safe from install too (the installer makes the admin)",
"gramps-web": "safe from install too (create_owner)"}
for app, (k, v) in VAL.items():
p = os.path.join(R, "templates", app, ".felhom.yml")
s = open(p).read()
assert "after_setup:" not in s and "\nsignup_block:" in s, app
i = s.index("\nsignup_block:"); j = s.index("\n", i + 1) + 1
note = WHY.get(app, "it also refuses the household's own first account, so it goes on AFTER the setup")
s = s[:j] + (f"# The app's OWN sign-up switch, set once the gate opens (measured on 9202 2026-09-29: with it on a stranger's\n"
f"# sign-up is refused even straight at the app; {note}). The compose default stays open, so an installed app is\n"
f"# unchanged by the catalog.\nafter_setup:\n env:\n {k}: \"{v}\"\n") + s[j:]
open(p, "w").write(s)
print("after_setup on", list(VAL))