{"record":{"id":"95dcf65d41d3ae56","repo":"toeverything/AFFiNE","slug":"sign-up-forbidden","errorCode":"sign_up_forbidden","errorMessage":"You are not allowed to sign up.","messagePattern":"You are not allowed to sign up\\.","errorType":"exception","errorClass":"SignUpForbidden","httpStatus":403,"severity":"error","filePath":"packages/backend/server/src/core/auth/magic-link.ts","lineNumber":135,"sourceCode":"      TokenType.SignIn,\n      consumed.token,\n      {\n        credential: email,\n      }\n    );\n\n    if (!tokenRecord) {\n      throw new InvalidEmailToken();\n    }\n\n    const user = await this.models.user.fulfill(email);\n\n    return { userId: user.id, method: 'magic_link' };\n  }\n\n  private async assertSignupAllowed(email: string) {\n    if (!this.config.auth.allowSignup) {\n      throw new SignUpForbidden();\n    }\n\n    if (!this.config.auth.requireEmailDomainVerification) {\n      return;\n    }\n\n    if (!(await verifyEmailDomainRecords(email))) {\n      throw new InvalidEmail({ email });\n    }\n  }\n}\n","sourceCodeStart":117,"sourceCodeEnd":147,"githubUrl":"https://github.com/toeverything/AFFiNE/blob/b4c8548c09da21b2898443559a5b846f0ccf5dd8/packages/backend/server/src/core/auth/magic-link.ts#L117-L147","documentation":"MagicLinkService.assertSignupAllowed runs when the email has no existing user. If config.auth.allowSignup is false (self-hosted instances after the first user, or signup disabled by policy), it throws SignUpForbidden (sign_up_forbidden) - passwordless sign-in cannot silently create accounts when signup is closed.","triggerScenarios":"A brand-new email requests a magic link on an instance where signup is disabled; the workspace is at its licensed user cap with signup turned off; admins closed signup after onboarding and a new contractor tries the flow.","commonSituations":"Self-hosted AFFiNE where the first account already exists and allowSignup defaults off; enterprise deployments with invite-only policy; users mistyping their email so they look 'new' to the system.","solutions":["An administrator enables signup in auth config, or invites the user from workspace member management","Sign in with an existing account instead","Double-check the email address - a typo makes an existing user look like a new signup","Self-hosters: verify the allowSignup setting and licensing/user-limit state"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":"function isSignUpForbidden(e: unknown): boolean {\n  return typeof e === 'object' && e !== null && (e as { code?: string }).code === 'sign_up_forbidden';\n}","tryCatchPattern":"try {\n  await sendMagicLink(email);\n} catch (e) {\n  if (isSignUpForbidden(e)) {\n    show('Sign-up is disabled on this instance. Ask an admin to invite you.');\n  } else throw e;\n}","preventionTips":["Surface instance signup policy in the UI before users attempt sign-up","Prefer admin-invite flows on closed-signup instances"],"tags":["auth","signup","configuration","self-hosted"],"backgroundTag":"signup-disabled","analyzedSha":"b4c8548c09da21b2898443559a5b846f0ccf5dd8","analyzedAt":"2026-08-18T21:16:52.546Z","contentChangedAt":"2026-08-18T21:16:52.546Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}