로컬 가입을 비활성화하는 사이트 설정

could alternatively scope must_approve_users with a must_approve_local_users

but this would remove a possibility of disabling initial page that re-directs to /login as a side effect of solving this security vulnerability.