Some checks failed
CD / Build and push images (push) Successful in 3m12s
CI / Lint, typecheck, test (push) Failing after 2m29s
CI / Auth e2e pack (push) Successful in 3m32s
CI / Build container images (push) Has been skipped
CD / Deploy to Test (push) Successful in 8s
CD / Smoke tests against Test (push) Successful in 1m11s
CD / Promote to Int (push) Successful in 11s
Instance operators get basic user administration for support, abuse handling, and GDPR groundwork (security.md §Privacy). - api `admin/`: Site-Admin-gated `/admin/users` — a searchable, paginated list (username, e-mail, status, role, pond count, last login) plus lifecycle actions: disable/enable (a disabled user is logged out everywhere and login is refused with the distinct `account_disabled`), resend verification, delete, and grant/revoke Site Admin. Guards: you cannot act on your own account (`cannot_modify_self`) and the last Site Admin cannot be dropped (`last_site_admin`). Every action is audit-logged with the actor. - `PseudonymizationService`: account deletion scrubs the PII, removes all login identities + sessions, and trashes the personal pond — the kept row is what authorship references, so shared content the user authored shows as "Deleted user" (no orphaned/cascaded content). - web: the Admin area gains a 'Users' surface — search, pagination, and the actions (destructive ones behind an inline two-step confirm; self-actions hidden). New `users` i18n namespace (de+en). - tests: `user-admin.e2e.db.test.ts` (disable → logout + login blocked; delete → pseudonymized authorship + personal pond trashed + credentials gone; last Site Admin and self protected; Site-Admin gating); a non-destructive browser `admin-users` pack proving disable-in-UI blocks login and enable restores it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
71 lines
3.8 KiB
JSON
71 lines
3.8 KiB
JSON
{
|
|
"bad_request": "The request is invalid.",
|
|
"unauthorized": "Please sign in to continue.",
|
|
"forbidden": "You do not have permission for this action.",
|
|
"not_found": "The requested resource does not exist.",
|
|
"conflict": "The request conflicts with the current state.",
|
|
"gone": "This resource is no longer available.",
|
|
"payload_too_large": "The submitted data is too large.",
|
|
"rate_limited": "Too many requests — please try again later.",
|
|
"internal_error": "Internal server error.",
|
|
"registration_closed": "Registration is currently closed on this instance.",
|
|
"token_invalid": "This link is invalid or has expired.",
|
|
"login_failed": "Username/e-mail or password is incorrect.",
|
|
"login_backoff": "Too many failed attempts — please wait a few minutes.",
|
|
"email_unverified": "Please confirm your e-mail address first.",
|
|
"account_disabled": "This account has been disabled.",
|
|
"password_incorrect": "The current password is incorrect.",
|
|
"csrf_origin_mismatch": "The request came from an unexpected origin.",
|
|
"cannot_revoke_current_session": "Use sign-out to end your current session.",
|
|
"personal_pond_undeletable": "The personal pond cannot be deleted.",
|
|
"quota_exceeded": "The quota has been reached (limit: {{limit}}).",
|
|
"slug_taken": "This slug is already taken in this pond.",
|
|
"page_document_too_large": "The page is too large (limit: {{limitBytes}} bytes).",
|
|
"invalid_page_state": "The submitted page content is invalid.",
|
|
"page_trashed": "This page has been moved to the trash.",
|
|
"label_name_taken": "A label with this name already exists at this level.",
|
|
"label_cycle": "A label cannot be moved into its own subtree.",
|
|
"label_depth_exceeded": "Labels can be nested at most {{max}} levels deep.",
|
|
"label_has_pages": "This label still has pages assigned; confirm to detach them.",
|
|
"label_wrong_pond": "This label belongs to a different pond.",
|
|
"unsupported_file_type": "This file type is not supported.",
|
|
"file_too_large": "The file is too large (limit: {{limitBytes}} bytes).",
|
|
"network": "The server could not be reached.",
|
|
"grant_exists": "This grant already exists.",
|
|
"grant_pond_admin_scope": "A Pond Admin grant must apply to the whole pond and a specific user.",
|
|
"grant_pond_admin_personal_pond": "A personal pond's only administrator is its owner.",
|
|
"grant_subject_id_mismatch": "The grant's subject is inconsistent.",
|
|
"grant_scope_id_mismatch": "The grant's scope is inconsistent.",
|
|
"grant_scope_not_found": "The label or page this grant points to does not exist in this pond.",
|
|
"grant_subject_not_found": "This user does not exist.",
|
|
"grant_last_admin": "The last Pond Admin cannot be removed.",
|
|
"member_not_found": "No user with that username or e-mail exists.",
|
|
"member_exists": "This user is already a member of this pond.",
|
|
"member_not_a_member": "This user is not a member of this pond.",
|
|
"member_is_owner": "The pond owner's membership cannot be changed here.",
|
|
"cannot_modify_self": "You cannot perform this action on your own account.",
|
|
"last_site_admin": "The last Site Admin cannot be removed.",
|
|
"validation": {
|
|
"required": "This field is required.",
|
|
"taken": "This value is already taken.",
|
|
"username": {
|
|
"tooShort": "The username needs at least 3 characters.",
|
|
"tooLong": "The username can have at most 32 characters.",
|
|
"charset": "Only letters, digits, and hyphens are allowed."
|
|
},
|
|
"password": {
|
|
"tooShort": "The password needs at least 10 characters.",
|
|
"tooLong": "The password can have at most 128 characters.",
|
|
"tooCommon": "This password is too common."
|
|
},
|
|
"email": {
|
|
"invalid": "Please enter a valid e-mail address."
|
|
},
|
|
"displayName": {
|
|
"required": "Please enter a display name."
|
|
},
|
|
"labelColor": "Please enter a colour like #a1b2c3.",
|
|
"tooLong": "The input is too long."
|
|
}
|
|
}
|