Describe the bug
When DISABLE_USER_REGISTRATION=true and ALLOW_REGISTRATION_EMAIL is set to a whitelist (e.g. ALLOW_REGISTRATION_EMAIL="alice@example.com"), the registration whitelist never works: every registration attempt is rejected with The user registration has been disabled by the administrator. Please contact the administrator!, even for whitelisted emails.
Root cause
In backend/bizpkg/config/base/base.go, getBasicConfigurationFromOldConfig() populates AllowRegistrationEmail from the wrong environment variable:
AllowRegistrationEmail: os.Getenv(consts.DisableUserRegistration),
It should read ALLOW_REGISTRATION_EMAIL (consts.AllowRegistrationEmail). Because DISABLE_USER_REGISTRATION is set to "true" in this scenario, the whitelist becomes the single-element list ["true"], which never contains a real email, so allowRegisterChecker always returns false.
To Reproduce
- Set in
.env: DISABLE_USER_REGISTRATION=true and ALLOW_REGISTRATION_EMAIL="neuroai@neurotrace.net"
- Restart the server
- Try to register an account with
neuroai@neurotrace.net
Expected behavior
Only the email(s) listed in ALLOW_REGISTRATION_EMAIL can register; other emails are rejected.
Actual behavior
All registration attempts (including whitelisted emails) are rejected with "The user registration has been disabled by the administrator."
Version
Current main (the bug has existed since the persisted base config was introduced, ~PR #2303, Oct 2025).
Environment
Any (env-based deployment; independent of the database, since getBasicConfigurationFromOldConfig() is the fallback used when no base config is persisted yet).
Additional context
Describe the bug
When
DISABLE_USER_REGISTRATION=trueandALLOW_REGISTRATION_EMAILis set to a whitelist (e.g.ALLOW_REGISTRATION_EMAIL="alice@example.com"), the registration whitelist never works: every registration attempt is rejected withThe user registration has been disabled by the administrator. Please contact the administrator!, even for whitelisted emails.Root cause
In
backend/bizpkg/config/base/base.go,getBasicConfigurationFromOldConfig()populatesAllowRegistrationEmailfrom the wrong environment variable:It should read
ALLOW_REGISTRATION_EMAIL(consts.AllowRegistrationEmail). BecauseDISABLE_USER_REGISTRATIONis set to"true"in this scenario, the whitelist becomes the single-element list["true"], which never contains a real email, soallowRegisterCheckeralways returns false.To Reproduce
.env:DISABLE_USER_REGISTRATION=trueandALLOW_REGISTRATION_EMAIL="neuroai@neurotrace.net"neuroai@neurotrace.netExpected behavior
Only the email(s) listed in
ALLOW_REGISTRATION_EMAILcan register; other emails are rejected.Actual behavior
All registration attempts (including whitelisted emails) are rejected with "The user registration has been disabled by the administrator."
Version
Current
main(the bug has existed since the persisted base config was introduced, ~PR #2303, Oct 2025).Environment
Any (env-based deployment; independent of the database, since
getBasicConfigurationFromOldConfig()is the fallback used when no base config is persisted yet).Additional context
BasicConfiguration.AdminAuthMWalready usesconsts.AllowRegistrationEmailcorrectly for the admin email fallback; only the registration whitelist path is broken.