Skip to content

System Settings ​

Site-wide configuration: server address, login & registration switches, GitHub / Lark / WeChat OAuth, Turnstile, SMTP, appearance, announcements. UI: web/default-pro/src/views/setting/SystemSetting.vue.

Endpoints ​

EndpointMethodAuthDescription
/api/option/GETRootList all options (*Token / *Secret keys are filtered out)
/api/option/PUTRootSingle-key persistence

Implementation: controller/option.go. Backed by the options table + config.OptionMap.

Sections ​

SectionFields
Server AddressServerAddress (external API base)
Login / RegisterPasswordLoginEnabled / PasswordRegisterEnabled / RegisterEnabled / EmailVerificationEnabled / GitHubOAuthEnabled / LarkOAuthEnabled / WeChatAuthEnabled / TurnstileCheckEnabled
GitHub OAuthGitHubClientId / GitHubClientSecret
Lark OAuthLarkClientId / LarkClientSecret
WeChat loginWeChatServerAddress / WeChatServerToken / WeChatAccountQRCodeImageURL
TurnstileTurnstileSiteKey / TurnstileSecretKey
SMTPSMTPServer / SMTPPort / SMTPAccount / SMTPFrom / SMTPToken
AppearanceSystemName / Logo / Theme
ContentNotice / HomePageContent

Field Semantics ​

FieldNotes
ServerAddressExternal API base URL shown on the Token page (/v1)
PasswordLoginEnabledWhen off, login is only via OAuth / WeChat / Lark
PasswordRegisterEnabledWhen off, signup must go through invitations or OAuth
RegisterEnabledMaster signup switch; false rejects POST /api/user/register outright
EmailVerificationEnabledRequire email + verification code on signup
EmailDomainRestrictionEnabled + EmailDomainWhitelistEmail-domain whitelist (configured under /setting/operation)
GitHubOAuthEnabled / LarkOAuthEnabled / WeChatAuthEnabledEnable the OAuth login entries; Client ID / Secret must be filled first
TurnstileCheckEnabledForce Cloudflare Turnstile on critical flows (signup, password reset)
NoticeTop banner (exposed via GET /api/notice)
HomePageContentLanding-page hero copy (exposed via GET /api/home_page_content)
SystemName / Logo / ThemeSite name / logo / frontend theme (must be in config.ValidThemes)

Toggle Preconditions ​

controller/option.go::UpdateOption validates prerequisites before enabling certain keys — see operation-setting.

OAuth Setup ​

  1. Create an OAuth app on the provider (GitHub / Lark / WeChat). Capture the Client ID and Secret.
  2. Set the redirect URL to {ServerAddress}/api/oauth/{github|lark|wechat}.
  3. Fill the Client ID / Secret on this page.
  4. Toggle the matching *Enabled switch and save.

SMTP ​

Provide server, port (587 by default), account, From address and token (an app-specific password is recommended). Once saved:

  • Email-verification codes on signup;
  • Password-reset emails;
  • Invitation notifications;

are dispatched via this SMTP relay.

Turnstile ​

  1. Create a Turnstile widget in the Cloudflare dashboard; obtain a Site Key (frontend) + Secret Key (backend).
  2. Enter both on this page and toggle TurnstileCheckEnabled.
  3. Signup / password reset / redemption pages automatically embed the Turnstile challenge.

Frontend Guide ​

  • Top: single-input Server Address + Save button.
  • Login / Register has eight switches; each saves on @change.
  • Each OAuth / Turnstile / SMTP block has its own Save button.
  • Appearance saves the three fields together.
  • Content saves both textareas together.

Implementation Pointers ​

ConcernLocation
Handler + validationcontroller/option.go
Boot-time init / syncmodel/option.go::InitOptionMap / SyncOptions
Public notice / home contentcontroller/misc.go (GetNotice / GetHomePageContent)
GitHub OAuthcontroller/auth/github.go
Lark OAuthcontroller/auth/lark.go
WeChat OAuthcontroller/auth/wechat.go
Routesrouter/api.go