A member followed his invitation link, chose a password, typed it twice, pressed save, and was shown the name of an environment variable. The server knew from the first byte of that request that it could not save anything: without GITEA_ADMIN_TOKEN it cannot set a password in Gitea. It asked him to do the work anyway. Three places had the same shape, all now checked up front through a new gitea.admin_configured(), mirroring mail.configured(): - the invitation page answers 503 with an explanation and no password field, identically for a real and an invented token so it cannot be used to probe for live ones - /recuperar refuses instead of mailing a link to a page that could only apologise — and its deliberately identical answer would have hidden that from the admin as well as the member - the sign-in page stops offering recovery it cannot complete Also: a 404 from admin_set_password now names the real cause. A member added without "crear también su cuenta" has no Gitea account, so the password change is aimed at nothing, and "Gitea rechazó el cambio de contraseña (404)" blames Gitea for an account that was never made. deploy-board.sh warns about settings that are present but empty. The previous check looked for missing names, and GITEA_ADMIN_TOKEN= has a name — which is why the deploy that led to this said nothing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
25 lines
829 B
HTML
25 lines
829 B
HTML
{% extends "base.html" %}
|
|
{% block title %}Entrar{% endblock %}
|
|
|
|
{% block main %}
|
|
<article class="card card--center">
|
|
<h1>Área de la comunidad</h1>
|
|
<p class="muted">
|
|
Este espacio es sólo para miembros de Viena Latina. Se entra con la misma
|
|
cuenta que se usa para publicar en el sitio.
|
|
</p>
|
|
<a class="btn" href="{{ url_for('auth.start', next=next) }}">Entrar con Gitea</a>
|
|
{# Offered only when the server can actually complete it: without a Gitea
|
|
admin token the recovery page can do nothing but apologise. #}
|
|
{% if can_recover %}
|
|
<p class="muted small">
|
|
<a href="{{ url_for('auth.recover') }}">¿Olvidaste tu contraseña?</a>
|
|
</p>
|
|
{% endif %}
|
|
<p class="muted small">
|
|
¿No tienes cuenta? Pídesela a un administrador: las cuentas se crean a mano,
|
|
no hay registro abierto.
|
|
</p>
|
|
</article>
|
|
{% endblock %}
|