Any authenticated user can invite an e-mail address; the mailed single-use token lets exactly one signup through even while registration is closed. Open (pending, unexpired) invitations count against the new instance setting invitations.maxOpenPerUser (default 5, 0 disables inviting) — plus a 20/day per-user rate limit so a revoke-and-recreate loop cannot become a mail cannon. Only the SHA-256 token hash is stored (auth-tokens pattern); a failed signup (taken username) un-redeems the token so the invitee can retry. Surfaces: invitations section in the user settings (list, invite, revoke, quota line; wide table in a focusable .table-scroll region), signup page reads ?invitation=<token> (preview banner, e-mail prefill, closed-mode gate opens only for a previewed-valid token), admin general card gets the quota field (flat RHF name per #322; VS-NfD marked and hideable). Governance: audit actions invitation.created/revoked/accepted (catalogue 1.10), VS-NfD profile entry (compliant: 0) + hardening-guide row, i18n de+en including the invitation mail template. Tests: api e2e-db (mail link, closed-mode single-use signup with un-redeem on failure, quota + revoke frees slot, quota 0 = 403, auth matrix), new web e2e pack invitations.spec.ts (full UI loop through Mailpit, wired into ci.yml with its own rate-limit reset), a11y scan waits for the new section. Full api suite (107 files / 607 tests), auth/admin-settings/a11y packs green against a fresh local stack. Closes #332
35 lines
1.0 KiB
JSON
35 lines
1.0 KiB
JSON
{
|
|
"section": {
|
|
"title": "Einladungen",
|
|
"intro": "Lade Personen per E-Mail ein. Der Link erlaubt genau eine Registrierung — auch wenn die Selbst-Registrierung geschlossen ist — und ist 14 Tage gültig.",
|
|
"quota": "{{open}} von {{max}} offenen Einladungen belegt.",
|
|
"disabled": "Einladungen sind auf dieser Instanz deaktiviert.",
|
|
"empty": "Noch keine Einladungen."
|
|
},
|
|
"form": {
|
|
"email": "E-Mail-Adresse",
|
|
"submit": "Einladen",
|
|
"sent": "Einladung verschickt."
|
|
},
|
|
"columns": {
|
|
"email": "E-Mail",
|
|
"status": "Status",
|
|
"created": "Eingeladen am",
|
|
"expires": "Gültig bis",
|
|
"actions": "Aktionen"
|
|
},
|
|
"status": {
|
|
"pending": "Offen",
|
|
"accepted": "Angenommen",
|
|
"revoked": "Widerrufen",
|
|
"expired": "Abgelaufen"
|
|
},
|
|
"actions": {
|
|
"revoke": "Widerrufen"
|
|
},
|
|
"signup": {
|
|
"banner": "{{inviterName}} lädt dich ein ({{email}}). Mit dieser Einladung kannst du dir jetzt ein Konto anlegen.",
|
|
"invalid": "Dieser Einladungslink ist ungültig, abgelaufen oder wurde bereits verwendet."
|
|
}
|
|
}
|