Files
MediaManager/docs/configuration
Konstantin Chernyshev bdb886d076 feat: add auth.registration_enabled flag and admin ui user creation (#543)
Hey! @maxdorninger, could you please take a look on the other one ;) ?

Closes #145 ; seems like a must have thing

- Add `auth.registration_enabled` flag (default `false` — sounds safer
default in current setup)
- Password registration: `/auth/register` route will return 403 if
disabled
- OIDC registration: `UserManager.oauth_callback` is overridden to
reject user without match; so no auto-provision
- `/auth/metadata` exposes the flag to the frontend
- Frontend: signup link hidden on the login card; direct navigation to
`/login/signup` redirects to `/login` via a `+page.ts` load guard
  
  
<img width="463" height="461" alt="Screenshot 2026-05-16 at 20 52 11"
src="https://github.com/user-attachments/assets/1def5142-e930-4aa6-8771-cbff54250c1f"
/>
<img width="450" height="391" alt="Screenshot 2026-05-16 at 20 52 22"
src="https://github.com/user-attachments/assets/b4013964-cace-4aeb-a848-48ced86fcc5f"
/>

  
Also this means uses need to be created somehow -- so..
- Add POST `/users` - admin-protected endpoint to create a new users
(created user can be used with OIDC)
- Fronted: Add new user button and modal dialog  

<img width="800" height="379" alt="Screenshot 2026-05-17 at 11 32 06"
src="https://github.com/user-attachments/assets/048e6c43-a1c1-42ce-a19c-fd9d916a47d9"
/>
<img width="537" height="439" alt="Screenshot 2026-05-17 at 11 32 12"
src="https://github.com/user-attachments/assets/3f83c2c1-027b-4279-b6a1-bbc8da77efed"
/>

---

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Add config toggle to enable/disable user registration; when disabled
sign-up endpoints return 403 and OIDC won’t auto-create unknown users.
Added admin API to create users.

* **Frontend**
* Login UI hides signup link when registration is disabled; signup page
redirects to login. Admin users list gains “Add User” modal to create
users.

* **Documentation**
* Authentication docs and config examples updated to document the new
option.

<!-- review_stack_entry_start -->

[![Review Change
Stack](https://storage.googleapis.com/coderabbit_public_assets/review-stack-in-coderabbit-ui.svg)](https://app.coderabbit.ai/change-stack/maxdorninger/MediaManager/pull/543?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)

<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-05 19:41:04 +02:00
..
2026-02-08 19:16:38 +01:00
2026-02-08 19:16:38 +01:00
2026-02-08 19:16:38 +01:00
2026-01-05 19:12:55 +00:00
2026-02-08 19:16:38 +01:00

Configuration

MediaManager uses a TOML configuration file (config.toml) for all backend settings. This centralized configuration approach makes it easier to manage, backup, and share your MediaManager setup.

Frontend settings are configured through environment variables in your docker-compose.yaml file.

Configuration File Location

!!! warning Note that MediaManager may need to be restarted for changes in the config file to take effect.

Your config.toml file should be in the directory that's mounted to /app/config/config.toml inside the container:

volumes:
  - ./config:/app/config

You can change the configuration directory with the following environment variable:

  • CONFIG_DIR
    Directory that contains config.toml. Default is /app/config. Example: /etc/mediamanager/.

Configuration Sections

The configuration is organized into the following sections:

  • [misc] - General settings
  • [database] - Database settings
  • [auth] - Authentication settings
  • [notifications] - Notification settings (Email, Gotify, Ntfy, Pushover)
  • [torrents] - Download client settings (qBittorrent, Transmission, SABnzbd)
  • [indexers] - Indexer settings (Prowlarr and Jackett )
  • [metadata] - TMDB and TVDB settings

Configuring Secrets

For sensitive information like API keys, passwords, and secrets, you should use environment variables. You can actually set every configuration value through environment variables. For example, to set the token_secret value for authentication, with a .toml file you would use:

[auth]
token_secret = "your_super_secret_key_here"

But you can also set it through an environment variable:

MEDIAMANAGER_AUTH__TOKEN_SECRET = "your_super_secret_key_here"

or another example with the OIDC client secret:

[auth]
...
[auth.openid_connect]
client_secret = "your_client_secret_from_provider"

env variable:

MEDIAMANAGER_AUTH__OPENID_CONNECT__CLIENT_SECRET = "your_client_secret_from_provider"

So for every config "level", you basically have to take the name of the value and prepend it with the section names in uppercase with 2 underscores as delimiters and MEDIAMANAGER_ as the prefix.

!!! warning Note that not every env variable starts with MEDIAMANAGER_; this prefix only applies to env variables which replace/overwrite values in the config file. Variables like the CONFIG_DIR env variable must not be prefixed.