feat: Implement first admin setup guard to lock registration after initial account creation

- Updated the registration flow to check if the first admin account has been created, preventing further public registrations.
- Introduced `is_first_admin_setup_available` function to determine registration availability.
- Modified the `/register` and `/login` pages to redirect based on the setup state.
- Enhanced the user creation process to handle internal admin accounts correctly.
- Added migration script to enforce the new registration rules in the database.
- Refactored chat API to improve message handling and context building.
- Updated dashboard and settings components for better state management.
- Improved error handling and user feedback across various components.
This commit is contained in:
Poyraz Avsever
2026-06-08 16:22:26 +03:00
parent cf8492db9e
commit 950522d467
15 changed files with 570 additions and 445 deletions
+16 -1
View File
@@ -3,6 +3,7 @@
import { revalidatePath } from 'next/cache'
import { redirect } from 'next/navigation'
import { createClient } from '@/lib/supabase/server'
import { getFirstAdminSetupState } from '@/lib/auth/first-admin-setup'
export async function login(formData: FormData) {
const supabase = await createClient()
@@ -23,6 +24,20 @@ export async function login(formData: FormData) {
}
export async function signup(formData: FormData) {
const setupState = await getFirstAdminSetupState()
if (setupState.errorMessage) {
redirect(`/register?error=true&message=${encodeURIComponent(setupState.errorMessage)}`)
}
if (!setupState.available) {
redirect(
`/login?error=true&message=${encodeURIComponent(
'Kayıt kapalı. Bu self-host kurulumunda ilk admin hesabı zaten oluşturulmuş.',
)}`,
)
}
const supabase = await createClient()
const data = {
@@ -33,7 +48,7 @@ export async function signup(formData: FormData) {
const { error } = await supabase.auth.signUp(data)
if (error) {
redirect(`/login?error=true&message=${encodeURIComponent(error.message)}`)
redirect(`/register?error=true&message=${encodeURIComponent(error.message)}`)
}
revalidatePath('/', 'layout')