{"record":{"id":"46f6eef4165ce56b","repo":"laurent22/joplin","slug":"signup-is-not-enabled","errorCode":null,"errorMessage":"Signup is not enabled","messagePattern":"Signup is not enabled","errorType":"http","errorClass":"ErrorForbidden","httpStatus":403,"severity":"error","filePath":"packages/server/src/routes/index/signup.ts","lineNumber":41,"sourceCode":"}\n\nexport interface FormUser {\n\tfull_name: string;\n\temail: string;\n\tpassword: string;\n\tpassword2: string;\n}\n\nconst router: Router = new Router(RouteType.Web);\n\nrouter.public = true;\n\nrouter.get('signup', async (_path: SubPath, _ctx: AppContext) => {\n\treturn makeView();\n});\n\nrouter.post('signup', async (_path: SubPath, ctx: AppContext) => {\n\tif (!config().signupEnabled) throw new ErrorForbidden('Signup is not enabled');\n\n\tawait limiterSignupBruteForce(userIp(ctx));\n\n\ttry {\n\t\tconst formUser = await bodyFields<FormUser>(ctx.req);\n\t\tconst password = checkRepeatPassword(formUser, true);\n\n\t\tconst user = await ctx.joplin.models.user().save({\n\t\t\taccount_type: AccountType.Basic,\n\t\t\temail: formUser.email,\n\t\t\tfull_name: formUser.full_name,\n\t\t\tpassword,\n\t\t});\n\n\t\tconst session = await ctx.joplin.models.session().createUserSession(user.id);\n\t\tcookieSet(ctx, 'sessionId', session.id);\n\n\t\treturn redirect(ctx, `${config().baseUrl}/home`);","sourceCodeStart":23,"sourceCodeEnd":59,"githubUrl":"https://github.com/laurent22/joplin/blob/981a03c5c9e88130bccff4db47c411d35ec7ae2c/packages/server/src/routes/index/signup.ts#L23-L59","documentation":"The POST signup route throws ErrorForbidden('Signup is not enabled') when config().signupEnabled is false. The Joplin Server administrator must explicitly enable self-service account creation; otherwise all signup attempts are rejected with 403.","triggerScenarios":"POSTing registration form data (email/password/repeat password) to the signup endpoint on a server where signupEnabled is not set to true in the config.","commonSituations":"Self-hosted Joplin Server default configuration where signup is disabled; users sharing a server URL expecting open registration; after a config migration that dropped the signupEnabled flag.","solutions":["Enable signup in the server config (set SIGNUP_ENABLED or the equivalent config value to true) and restart the server.","Ask the server administrator to create the account via the admin user-management route instead.","Check that you are posting to the correct server whose config you updated."],"exampleFix":"// before (docker-compose / env)\n# signup not configured\n// after\nenvironment:\n  - Signup_Enabled=true","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { await api.post('/signup', form); } catch (e) { if (e.httpStatus === 403) showMessage('Signup is disabled on this server'); }","preventionTips":["Query server config/capabilities before showing the signup form.","Admins: set Signup_Enabled explicitly when self-registration is desired."],"tags":["server","forbidden","configuration"],"backgroundTag":"feature-not-enabled","analyzedSha":"981a03c5c9e88130bccff4db47c411d35ec7ae2c","analyzedAt":"2026-09-17T14:49:40.960Z","contentChangedAt":"2026-09-17T14:49:40.960Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}