Internal authentication

Continuwuity comes with an internal database for user authentication, which it uses by default. This allows for self-servicing of account registration, linking emails, and password resets.

Registration

Registration is disabled by default. To enable it, set allow_registration = true in your config file and use at least one of the registration methods below.

MethodDescriptionAdditional configuration needed
1Admin-issued tokens (recommended)None. Use the !admin token issue command
2Static registration tokenregistration_token or registration_token_file
3Token + emailMethod 1 or 2 + require_email_for_token_registration = true in [global.smtp]. See Email configuration
4Email-only registrationrequire_email_for_registration = true in [global.smtp] section. See Email configuration
5reCAPTCHA-only registrationrecaptcha_site_key and recaptcha_private_site_key
6Email + reCAPTCHA registrationMethods 4 + 5

Admin-issued tokens are the recommended registration method. These tokens are well suited for private or invite-only servers, and they can be scoped with an expiry duration or given a usage limit. See the !admin token commands for more details.

Other registration methods are meant for untrusted, public registration. Care must be taken when allowing these modes of operation.

Email configuration

Continuwuity can be configured to send emails via an SMTP relay of your choice. These are used for verifying user email addresses and sending password reset links to them.

A user is associated with only one email address at a time.

All email options are in the [global.smtp] block of the configuration file, and are toggled on when the block is uncommented. For example:

[global.smtp]
# Example URI for the user [email protected] on the `mail.example.net` mail server
connection_uri = "smtps://john%40example.com:[email protected]:465"
sender = "John's Continuwuity server <[email protected]>"

A user's email address can also be modified by the !admin users change-email command. To view current user-email associations, use the !admin users get-email and !admin users get-user-by-email command.

Use !admin debug send-test-email to test that your email setup is working.

Password resets

Password resets in Continuwuity can be made via:

  • Self-service password resets. This requires a user's email to have been set up and verified.
  • Using the !admin users reset-password command.