Hey! @maxdorninger, could you please take a look on the other one ;) ? Closes #145 ; seems like a must have thing - Add `auth.registration_enabled` flag (default `false` — sounds safer default in current setup) - Password registration: `/auth/register` route will return 403 if disabled - OIDC registration: `UserManager.oauth_callback` is overridden to reject user without match; so no auto-provision - `/auth/metadata` exposes the flag to the frontend - Frontend: signup link hidden on the login card; direct navigation to `/login/signup` redirects to `/login` via a `+page.ts` load guard <img width="463" height="461" alt="Screenshot 2026-05-16 at 20 52 11" src="https://github.com/user-attachments/assets/1def5142-e930-4aa6-8771-cbff54250c1f" /> <img width="450" height="391" alt="Screenshot 2026-05-16 at 20 52 22" src="https://github.com/user-attachments/assets/b4013964-cace-4aeb-a848-48ced86fcc5f" /> Also this means uses need to be created somehow -- so.. - Add POST `/users` - admin-protected endpoint to create a new users (created user can be used with OIDC) - Fronted: Add new user button and modal dialog <img width="800" height="379" alt="Screenshot 2026-05-17 at 11 32 06" src="https://github.com/user-attachments/assets/048e6c43-a1c1-42ce-a19c-fd9d916a47d9" /> <img width="537" height="439" alt="Screenshot 2026-05-17 at 11 32 12" src="https://github.com/user-attachments/assets/3f83c2c1-027b-4279-b6a1-bbc8da77efed" /> --- <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Add config toggle to enable/disable user registration; when disabled sign-up endpoints return 403 and OIDC won’t auto-create unknown users. Added admin API to create users. * **Frontend** * Login UI hides signup link when registration is disabled; signup page redirects to login. Admin users list gains “Add User” modal to create users. * **Documentation** * Authentication docs and config examples updated to document the new option. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maxdorninger/MediaManager/pull/543?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Configuration
MediaManager uses a TOML configuration file (config.toml) for all backend settings. This centralized configuration approach makes it easier to manage, backup, and share your MediaManager setup.
Frontend settings are configured through environment variables in your docker-compose.yaml file.
Configuration File Location
!!! warning Note that MediaManager may need to be restarted for changes in the config file to take effect.
Your config.toml file should be in the directory that's mounted to /app/config/config.toml inside the container:
volumes:
- ./config:/app/config
You can change the configuration directory with the following environment variable:
CONFIG_DIR
Directory that containsconfig.toml. Default is/app/config. Example:/etc/mediamanager/.
Configuration Sections
The configuration is organized into the following sections:
[misc]- General settings[database]- Database settings[auth]- Authentication settings[notifications]- Notification settings (Email, Gotify, Ntfy, Pushover)[torrents]- Download client settings (qBittorrent, Transmission, SABnzbd)[indexers]- Indexer settings (Prowlarr and Jackett )[metadata]- TMDB and TVDB settings
Configuring Secrets
For sensitive information like API keys, passwords, and secrets, you should use environment variables. You can actually set every configuration value through environment variables. For example, to set the token_secret value for authentication, with a .toml file you would use:
[auth]
token_secret = "your_super_secret_key_here"
But you can also set it through an environment variable:
MEDIAMANAGER_AUTH__TOKEN_SECRET = "your_super_secret_key_here"
or another example with the OIDC client secret:
[auth]
...
[auth.openid_connect]
client_secret = "your_client_secret_from_provider"
env variable:
MEDIAMANAGER_AUTH__OPENID_CONNECT__CLIENT_SECRET = "your_client_secret_from_provider"
So for every config "level", you basically have to take the name of the value and prepend it with the section names in uppercase with 2 underscores as delimiters and MEDIAMANAGER_ as the prefix.
!!! warning
Note that not every env variable starts with MEDIAMANAGER_; this prefix only applies to env variables which replace/overwrite values in the config file. Variables like the CONFIG_DIR env variable must not be prefixed.