feat(auth)!: go fully passwordless and fix cross-check review findings
Remove password authentication everywhere; the only session doors are passkey (WebAuthn), email OTP, in-game bind codes, QR scan-login, and op-login vouching. Remediates the 33-finding cross-check review across backend, CLI, panel, plugins, and docs. Backend/CLI: - Drop password routes and fields from account/user/onboard/auth handlers; align tests (new account subtests, naming reserves "console", op-login/onboard/qr-login test updates). - Add migrations 0016_op_login.sql and 0017_drop_password.sql. - Thread panel/admin hostnames from hostcfg through api.go, setup_panel.go, tui_root.go and tui_preflight.go instead of hardcoding; bootstrap.sh writes panel-hostname/admin-hostname into felis.toml. - Reword breakglass and TUI copy for passwordless flows. Panel: - Delete the ChangePassword page and all password UI; align login/auth/api/types with the passwordless contract; add the migration and op-login approval flows. - i18n: convert ImageBuildPage durations/status badges and ServerLuckPerms strings to translation keys; drop 72 orphan keys per locale; unify the title as "Felis - Console". Plugins (all six rebuilt): - Velocity waiting router returns 503 at_capacity during wake; MOTD/control-channel copy and config comments. - Paper zh menu title; Limbo bind-code TTL 600s with panel_url preference; unified /link lines in fabric/forge/neoforge; shared link-client javadoc contract fixes. Docs: openapi.yaml, sequence-diagrams.md, deploy/limbo/README.md and plugins/README.md aligned with the implementation. BREAKING CHANGE: migration 0017 irreversibly drops users.password_hash and users.must_change_password; password login cannot be restored after migrating.
This commit is contained in:
97 files changed
+1923
-1444
No files matched your search
@@ -1,12 +1,8 @@
|
||||
{
|
||||
"title": "管理",
|
||||
"subtitle": "服务器与内容管理",
|
||||
"signed_in_as": " · 当前登录:{{email}}",
|
||||
"servers": "服务器",
|
||||
"servers_desc": "通过结构化表单创建并管理平台服务器。",
|
||||
"images": "镜像",
|
||||
"images_desc": "平台镜像白名单——创建服务器时的可选镜像范围。",
|
||||
"server_admin_subtitle": "通过结构化表单创建并管理平台服务器。",
|
||||
"images_title": "镜像",
|
||||
"images_subtitle": "平台镜像白名单。仅已启用的镜像可用于创建服务器。您可以添加外部镜像,或将不需要的镜像从白名单中删除。",
|
||||
"add_image_title": "添加外部镜像",
|
||||
@@ -26,21 +22,14 @@
|
||||
"context_ref_placeholder": "例如: minio/contexts/my-modpack.tar.gz",
|
||||
"base_image_label": "基础镜像",
|
||||
"base_image_placeholder": "例如: library/postgres:15",
|
||||
"build_history_title": "构建历史",
|
||||
"view_logs_btn": "日志",
|
||||
"cancel_build_btn": "取消",
|
||||
"no_builds_title": "暂无构建任务",
|
||||
"no_builds_hint": "您可以使用右上角表单触发第一个镜像构建任务。",
|
||||
"build_log_title": "构建日志终端",
|
||||
"log_streaming": "实时输出中",
|
||||
"log_finished": "已结束",
|
||||
"no_images_title": "无白名单镜像",
|
||||
"no_images_hint": "白名单为空——平台管理员需通过 CLI 添加镜像。",
|
||||
"enabled": "已启用",
|
||||
"disabled": "已禁用",
|
||||
"footer_kubectl": "kubectl / CRD",
|
||||
"footer_pre": "集群扩缩、RBAC、Secrets 及控制面生命周期等属于 ",
|
||||
"footer_post": " 范畴,刻意不在面板中暴露——遵循四层职责分离原则(构建 / 运行时 / 运维 / 应用)。此处为平台观察视角,并非运维管理入口。",
|
||||
"table_ref": "镜像名称",
|
||||
"table_source": "来源",
|
||||
"table_status": "状态",
|
||||
@@ -49,6 +38,8 @@
|
||||
"table_requester": "发起人",
|
||||
"table_created_at": "创建时间",
|
||||
"table_duration": "耗时",
|
||||
"build_duration_seconds": "{{s}}秒",
|
||||
"build_duration_minutes": "{{m}}分{{s}}秒",
|
||||
"filter_all": "全部",
|
||||
"filter_enabled": "已启用",
|
||||
"filter_disabled": "已禁用",
|
||||
@@ -74,9 +65,7 @@
|
||||
"reject_reason": "驳回理由",
|
||||
"updates_title": "维护窗口",
|
||||
"updates_subtitle": "配置全局系统维护窗口。在此窗口内,Felis 可以自动应用系统更新;在窗口外,更新将降级为仅通知,不会自动执行。",
|
||||
"updates_current_title": "当前设置",
|
||||
"updates_current_unset": "当前未设置维护窗口。自动更新将降级为仅通知,不会自动执行。",
|
||||
"updates_current_set": "Felis 可在以下时间段内自动执行更新:",
|
||||
"updates_start_label": "开始时间",
|
||||
"updates_end_label": "结束时间",
|
||||
"updates_set_title": "配置维护窗口",
|
||||
@@ -107,14 +96,10 @@
|
||||
"users_subtitle": "管理平台用户账号、配额和会话。",
|
||||
"users_create_btn": "创建用户",
|
||||
"users_create_title": "创建新用户",
|
||||
"users_create_desc": "创建一个新的平台账号。用户将收到初始密码,如果开启「首次登录修改密码」,用户将在首次登录时被要求修改密码。",
|
||||
"users_create_success_title": "用户创建成功",
|
||||
"users_create_success_desc": "请复制并妥善保管该用户的初始凭据。关闭此对话框后,此初始密码将无法再次查看!",
|
||||
"users_create_desc": "创建一个新的平台账号。账号无密码——用户通过游戏内 /link 绑定码登录,绑定后也可使用邮箱验证码 / Passkey 登录。",
|
||||
"users_create_username_placeholder": "例如: alice",
|
||||
"users_create_validation_username": "用户名为必填项。",
|
||||
"users_create_validation_username_taken": "该用户名已被使用。",
|
||||
"users_create_validation_password": "密码至少需要 8 个字符。",
|
||||
"users_create_must_change": "要求首次登录修改密码",
|
||||
"users_search_placeholder": "搜索用户名或邮箱...",
|
||||
"users_search_btn": "搜索",
|
||||
"users_filter_role_all": "全部角色",
|
||||
@@ -130,7 +115,6 @@
|
||||
"users_col_status": "状态",
|
||||
"users_col_created": "创建时间",
|
||||
"users_view_detail": "详情",
|
||||
"users_total_count": "共 {{count}} 个用户",
|
||||
"users_empty_title": "未找到用户",
|
||||
"users_empty_hint": "没有匹配当前筛选条件的用户。",
|
||||
"users_back_to_list": "返回用户列表",
|
||||
@@ -138,7 +122,6 @@
|
||||
"users_field_username": "用户名",
|
||||
"users_field_email": "邮箱",
|
||||
"users_field_role": "角色",
|
||||
"users_field_password": "初始密码",
|
||||
"users_save_btn": "保存更改",
|
||||
"users_save_ok": "更改保存成功。",
|
||||
"users_linked_accounts": "已关联的 Minecraft 账号",
|
||||
@@ -174,25 +157,21 @@
|
||||
"users_danger_enable": "启用用户",
|
||||
"users_danger_enable_desc": "允许此用户重新登录。",
|
||||
"users_danger_enable_btn": "启用",
|
||||
"users_danger_reset_pw": "重置密码",
|
||||
"users_danger_reset_pw_desc": "将生成随机密码,用户下次登录时将被强制修改密码。所有活跃会话将被立即撤销。",
|
||||
"users_danger_reset_pw_desc_email": "将生成随机密码并发送至 {{email}}。用户下次登录时将被强制修改密码。所有活跃会话将被立即撤销。",
|
||||
"users_danger_reset_pw_btn": "重置密码",
|
||||
"users_danger_reset_pw_confirm": "确认重置",
|
||||
"users_pw_reset_ok": "密码已重置,新密码已发送至 {{email}}。",
|
||||
"users_pw_reset_ok_no_email": "密码已重置。该用户未设置邮箱,新密码已记录在服务端日志中。",
|
||||
"users_danger_disable_dlg_title": "禁用用户",
|
||||
"users_danger_disable_dlg_desc": "此用户将无法登录。所有活跃会话将被立即撤销。",
|
||||
"users_danger_enable_dlg_title": "启用用户",
|
||||
"users_danger_enable_dlg_desc": "此用户将可以重新登录。",
|
||||
"users_danger_reset_pw_dlg_title": "重置密码",
|
||||
"users_danger_reset_pw_dlg_desc_email": "将生成随机密码并发送至 {{email}}。用户下次登录时将被强制修改密码。所有现有会话将被撤销。",
|
||||
"users_danger_reset_pw_dlg_desc_no_email": "将生成随机密码。由于此用户未设置邮箱地址,密码将记录在服务端日志中。用户下次登录时将被强制修改密码。所有现有会话将被撤销。",
|
||||
"users_danger_delete_dlg_title": "删除用户",
|
||||
"users_danger_delete_dlg_desc": "此操作不可逆。该用户拥有的所有服务器将被释放,所有会话将被撤销,账号将被永久禁用。此操作无法通过面板撤销。",
|
||||
"users_danger_delete": "删除用户",
|
||||
"users_danger_delete_desc": "软删除此用户。其拥有的服务器将被释放,所有会话将被撤销,账号将被永久禁用。此操作无法通过面板撤销。",
|
||||
"users_danger_delete_btn": "删除用户",
|
||||
"users_danger_delete_confirm": "此操作不可逆。该用户的服务器将被释放,会话将被撤销。确定要执行吗?",
|
||||
"users_danger_delete_yes": "是的,永久删除"
|
||||
"users_danger_delete_yes": "是的,永久删除",
|
||||
"add_image_desc": "将外部 Docker 镜像引用录入白名单,供后续创建服务器使用。",
|
||||
"images_search_placeholder": "搜索镜像名称或来源...",
|
||||
"search_no_results": "无匹配结果",
|
||||
"search_no_results_hint": "尝试更换搜索词或筛选条件。",
|
||||
"submissions_search_placeholder": "搜索模组包名称或提交人...",
|
||||
"trigger_build_desc": "输入镜像构建参数,在隔离命名空间中启动 Kaniko 流水线任务。",
|
||||
"builds_search_placeholder": "搜索构建 ID、镜像引用或状态..."
|
||||
}
|
||||
Reference in new issue
Block a user