Public read-only demo
DEMO_MODE is off by default. When enabled, Libris lets visitors read the showcase library without publishing account credentials. A visitor without an existing session can enter through POST /api/auth/demo; a signed-in visitor keeps their current account. After signing out, the sign-in page offers an Enter the demo button.
Prepare the demo account
- Sign in as an administrator and create a dedicated local account. It must not be an administrator, must have two-factor authentication disabled, and must not be an external account.
- Set a random password for this account and never publish or share it. Visitors use automatic demo sign-in; no username or password is published.
- Import the showcase project archives into this account before enabling demo mode. Every import and archive restoration counts toward the licence quota. Check the remaining quota first.
Enable and protect the instance
Set DEMO_MODE=true and DEMO_USERNAME=<account> in the installation .env, then apply the settings with cd /opt/libris && docker compose up -d api worker. Set FORWARDED_ALLOW_IPS to the trusted reverse proxy address; this is required so client IP based protections use the real visitor address. See demo settings.
Configure rate limits at the reverse proxy for POST /api/auth/demo, /api/auth/login, /api/exports/* and /api/projects/*/export/*. Keep private data and personal accounts off the public instance.
What visitors can do
GET, HEAD and OPTIONS requests are allowed. The only allowed write requests are sign-in, sign-out, sign-in two-factor endpoints, automatic demo sign-in, and grouped EPUB/text exports. Other write requests return 403 demo_read_only. /mcp, SSO and LDAP are closed; the worker only sends licence heartbeats. GET /health reports demo: true and, when the automatic sign-in account is configured, demo_login: true.
Reset the showcase
Set DEMO_MODE=false, then apply it with cd /opt/libris && docker compose up -d api worker. Sign in as an administrator, remove the old showcase books, and restore the saved project archives to the dedicated demo account. Imports and restorations count toward the licence quota. Re-enable DEMO_MODE=true, then apply it with cd /opt/libris && docker compose up -d api worker.