Server settings for administrators, from the account menu, in Postulo's own interface #24
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Reference
Postulo/postulo#24
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
What exists today
manage.py createsuperuserat install time (README, Installing Postulo, Getting started).StaffRequiredMixin(core/mixins.py, line 28) gates exactly one thing: issuing invitations. No page lists accounts, promotes, demotes or deactivates anyone.POSTULO_ADMIN_URL(defaultadmin/) and is not linked from anywhere in the interface. It is an escape hatch, not a settings page.POSTULO_REGISTRATION_OPEN(base.py, line 137),POSTULO_TIME_ZONE(155),POSTULO_PDF_BACKEND(184),POSTULO_CAPTURE_IGNORE_ROBOTS(192),POSTULO_DEFAULT_FROM_EMAIL(220), the SMTP host settings (prod.py, lines 54–59). Changing whether registration is open means editing.envand restarting the container.Shape
1. A Server settings area, in Postulo's own shell, reached from the account menu (#10) — an entry that appears only for administrators, below the person's own Settings (#22). Same sidebar layout, different sections:
accounts:invite_list,invite_create,invite_revoke) move here from the main navigation, decided 2026-09-05 — inviting people is user management; deactivate; make or unmake administrator — never the last onedocs/PLAN.mdpromised in section 7 — and whether each loaded cleanlyrobots.txtpolicy, fetch limits2. Which settings move, and which do not. The line is infrastructure versus policy:
SiteSettingsrow edited from the page — registration, defaults, capture policy, instance name.POSTULO_REGISTRATION_OPENis in the environment, the page shows the value read-only with "set by the environment", and the database value is ignored. Every existing deployment — the ragnar instance's.envincluded — keeps behaving exactly as it does today, which is what makes this non-breaking. The Compose documentation then recommends leaving policy out of.env.3. The role, made explicit. "Administrator" is the word in the interface; underneath it stays
is_staff, so nothing else changes. Two additions: the People section can grant and revoke it, and the first account created on an empty instance becomes an administrator automatically, which retires thecreatesuperuserstep from the installation guide.createsuperuserkeeps working for the person who wants it. The Django admin stays mounted and unlinked, mentioned once under Overview as the escape hatch.4. Wiki. Accounts and invitations and Configuration are rewritten around this: what is a setting, what is an environment variable, and which wins.
Classification
Enhancement. Not breaking on one condition: environment variables keep precedence over the database, so no existing
.envchanges meaning. The first-account rule only affects an empty instance.Open questions
Where do invitations live afterwards?Decided 2026-09-05: only here, under People. The staff-only main-navigation item (base.html, line 49) is removed, and they do not appear in the account menu either (#10).