vienalatina/apps/board/templates/member_new.html
Claude 3bd086ab0e
Say accounts cannot be created before the form is filled in
Running without GITEA_ADMIN_TOKEN is the safer configuration and is documented
as such, but the member form did not know: it offered "Crear también su cuenta"
ticked by default and reported "Falta GITEA_ADMIN_TOKEN" only on submit, after
three fields had been filled in.

That is the shape of failure this project has lost the most time to — something
that cannot happen, going unsaid until someone has relied on it. The form now
reads the config when it renders and says so, with a link to Gitea's create-user
page.

The checkbox is disabled rather than hidden, because "you cannot do this here"
is more use than an option that quietly is not there. The refusal itself stays
in the handler: a disabled input is a courtesy, and a hand-crafted POST still
meets the same error.

Verified: 104 checks. The form states the limit with no token and is unchanged
with one, and submitting create_account anyway still creates no member.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
2026-09-25 17:17:41 +00:00

57 lines
1.9 KiB
HTML

{% extends "base.html" %}
{% block title %}Dar de alta{% endblock %}
{% block main %}
<form class="card" method="post" action="{{ url_for('members.new') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token() }}">
<h1>Dar de alta a alguien</h1>
<label for="login">Usuario</label>
<input id="login" name="login" required pattern="[A-Za-z0-9][A-Za-z0-9._\-]*"
placeholder="maria.lopez">
<p class="muted small">Letras, números, punto, guion y guion bajo.</p>
<label for="display_name">Nombre</label>
<input id="display_name" name="display_name" placeholder="María López">
<label for="email">Correo</label>
<input id="email" name="email" type="email" placeholder="maria@ejemplo.com">
{% if can_create_accounts %}
<label class="check">
<input type="checkbox" name="create_account" checked>
Crear también su cuenta (desmarca si ya tiene una)
</label>
{% else %}
{# Disabled rather than hidden: "you cannot do this here" is more use than
an option that quietly is not there. The handler refuses it either way. #}
<label class="check">
<input type="checkbox" name="create_account" disabled>
Crear también su cuenta
</label>
<p class="muted small">
Este servidor no puede crear cuentas (no tiene un token de administración
de Gitea). Crea la cuenta primero en
<a href="{{ gitea_url }}/admin/users/new">Gitea</a> y luego da de alta
aquí ese mismo usuario.
</p>
{% endif %}
{% if can_make_admin %}
<label for="role">Rol</label>
<select id="role" name="role">
<option value="user">Usuario</option>
<option value="admin">Administrador</option>
</select>
{% else %}
<input type="hidden" name="role" value="user">
<p class="muted small">Los administradores sólo pueden dar de alta usuarios.</p>
{% endif %}
<div class="actions">
<button class="btn" type="submit">Dar de alta</button>
<a class="linkish" href="{{ url_for('members.index') }}">Cancelar</a>
</div>
</form>
{% endblock %}