Running without GITEA_ADMIN_TOKEN is the safer configuration and is documented as such, but the member form did not know: it offered "Crear también su cuenta" ticked by default and reported "Falta GITEA_ADMIN_TOKEN" only on submit, after three fields had been filled in. That is the shape of failure this project has lost the most time to — something that cannot happen, going unsaid until someone has relied on it. The form now reads the config when it renders and says so, with a link to Gitea's create-user page. The checkbox is disabled rather than hidden, because "you cannot do this here" is more use than an option that quietly is not there. The refusal itself stays in the handler: a disabled input is a courtesy, and a hand-crafted POST still meets the same error. Verified: 104 checks. The form states the limit with no token and is unchanged with one, and submitting create_account anyway still creates no member. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
57 lines
1.9 KiB
HTML
57 lines
1.9 KiB
HTML
{% extends "base.html" %}
|
|
{% block title %}Dar de alta{% endblock %}
|
|
|
|
{% block main %}
|
|
<form class="card" method="post" action="{{ url_for('members.new') }}">
|
|
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
|
|
<h1>Dar de alta a alguien</h1>
|
|
|
|
<label for="login">Usuario</label>
|
|
<input id="login" name="login" required pattern="[A-Za-z0-9][A-Za-z0-9._\-]*"
|
|
placeholder="maria.lopez">
|
|
<p class="muted small">Letras, números, punto, guion y guion bajo.</p>
|
|
|
|
<label for="display_name">Nombre</label>
|
|
<input id="display_name" name="display_name" placeholder="María López">
|
|
|
|
<label for="email">Correo</label>
|
|
<input id="email" name="email" type="email" placeholder="maria@ejemplo.com">
|
|
|
|
{% if can_create_accounts %}
|
|
<label class="check">
|
|
<input type="checkbox" name="create_account" checked>
|
|
Crear también su cuenta (desmarca si ya tiene una)
|
|
</label>
|
|
{% else %}
|
|
{# Disabled rather than hidden: "you cannot do this here" is more use than
|
|
an option that quietly is not there. The handler refuses it either way. #}
|
|
<label class="check">
|
|
<input type="checkbox" name="create_account" disabled>
|
|
Crear también su cuenta
|
|
</label>
|
|
<p class="muted small">
|
|
Este servidor no puede crear cuentas (no tiene un token de administración
|
|
de Gitea). Crea la cuenta primero en
|
|
<a href="{{ gitea_url }}/admin/users/new">Gitea</a> y luego da de alta
|
|
aquí ese mismo usuario.
|
|
</p>
|
|
{% endif %}
|
|
|
|
{% if can_make_admin %}
|
|
<label for="role">Rol</label>
|
|
<select id="role" name="role">
|
|
<option value="user">Usuario</option>
|
|
<option value="admin">Administrador</option>
|
|
</select>
|
|
{% else %}
|
|
<input type="hidden" name="role" value="user">
|
|
<p class="muted small">Los administradores sólo pueden dar de alta usuarios.</p>
|
|
{% endif %}
|
|
|
|
<div class="actions">
|
|
<button class="btn" type="submit">Dar de alta</button>
|
|
<a class="linkish" href="{{ url_for('members.index') }}">Cancelar</a>
|
|
</div>
|
|
</form>
|
|
{% endblock %}
|