vienalatina/apps/board/templates
Claude e11016a8e9
Refuse before the form, not after the password
A member followed his invitation link, chose a password, typed it twice,
pressed save, and was shown the name of an environment variable. The
server knew from the first byte of that request that it could not save
anything: without GITEA_ADMIN_TOKEN it cannot set a password in Gitea.
It asked him to do the work anyway.

Three places had the same shape, all now checked up front through a new
gitea.admin_configured(), mirroring mail.configured():

- the invitation page answers 503 with an explanation and no password
  field, identically for a real and an invented token so it cannot be
  used to probe for live ones
- /recuperar refuses instead of mailing a link to a page that could only
  apologise — and its deliberately identical answer would have hidden
  that from the admin as well as the member
- the sign-in page stops offering recovery it cannot complete

Also: a 404 from admin_set_password now names the real cause. A member
added without "crear también su cuenta" has no Gitea account, so the
password change is aimed at nothing, and "Gitea rechazó el cambio de
contraseña (404)" blames Gitea for an account that was never made.

deploy-board.sh warns about settings that are present but empty. The
previous check looked for missing names, and GITEA_ADMIN_TOKEN= has a
name — which is why the deploy that led to this said nothing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NizVpJ2dwzCbjCrTLCjeHn
2026-09-25 19:20:44 +00:00
..
base.html Write the site from the members area instead of Decap 2026-09-25 15:07:31 +00:00
comment_form.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
content_form.html Write the site from the members area instead of Decap 2026-09-25 15:07:31 +00:00
content_list.html Write the site from the members area instead of Decap 2026-09-25 15:07:31 +00:00
error.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
logged_out.html Brand Gitea's auth screens, and stop Salir overstating itself 2026-09-25 16:28:10 +00:00
login.html Refuse before the form, not after the password 2026-09-25 19:20:44 +00:00
member_created.html Hand the mail settings to the container, and rebuild on deploy 2026-09-25 18:42:39 +00:00
member_new.html Hand the mail settings to the container, and rebuild on deploy 2026-09-25 18:42:39 +00:00
members.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
recover.html Refuse before the form, not after the password 2026-09-25 19:20:44 +00:00
set_password.html Refuse before the form, not after the password 2026-09-25 19:20:44 +00:00
thread_form.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
thread.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00
threads.html Add a members area: roles and an internal board 2026-09-22 10:57:18 +00:00