mirror of
https://github.com/fosrl/pangolin.git
synced 2026-08-13 16:00:02 +02:00
Compare commits
32 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 84e1d51ccf | |||
| 9a18436d4f | |||
| bba34a15a7 | |||
| 797641a605 | |||
| cc49364c0d | |||
| 67b2e07e57 | |||
| cfd4595059 | |||
| acf0e29a87 | |||
| f9ced39be8 | |||
| 293d59f11c | |||
| 1759cf7890 | |||
| 0acabbb542 | |||
| 7abd68adc4 | |||
| a541daaca3 | |||
| 420a551de4 | |||
| ea965339b1 | |||
| 1b8d958b6a | |||
| 3a91147b86 | |||
| 2b20561461 | |||
| 9fc7e408c1 | |||
| 66748b28f1 | |||
| bd84119fd8 | |||
| 20c86108e6 | |||
| a4be9cc696 | |||
| 7909e792d0 | |||
| 8741885c85 | |||
| 4d839f1a1b | |||
| 842dd04556 | |||
| 897ed9c8d8 | |||
| a411df735f | |||
| c8217461b1 | |||
| 0a0ecd3b6f |
+2
-2
@@ -1,5 +1,5 @@
|
||||
# FROM node:24-slim AS base
|
||||
FROM public.ecr.aws/docker/library/node:26-slim AS base
|
||||
FROM public.ecr.aws/docker/library/node:24-slim AS base
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
@@ -33,7 +33,7 @@ FROM base AS builder
|
||||
RUN npm ci --omit=dev
|
||||
|
||||
# FROM node:24-slim AS runner
|
||||
FROM public.ecr.aws/docker/library/node:26-slim AS runner
|
||||
FROM public.ecr.aws/docker/library/node:24-slim AS runner
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
FROM node:26-alpine
|
||||
FROM node:24-alpine
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Моля, уверете се, че сте влезли като правилния потребител.",
|
||||
"inviteErrorNoUser": "Съжаляваме, но изглежда, че поканата, до която се опитвате да получите достъп, не е за съществуващ потребител.",
|
||||
"inviteCreateUser": "Моля, първо създайте акаунт.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Отиди вкъщи",
|
||||
"inviteLogInOtherUser": "Влезте като друг потребител",
|
||||
"createAnAccount": "Създайте профил",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Задайте ПИН код на ресурса",
|
||||
"actionSetResourceEmailWhitelist": "Задайте списък на одобрените имейл адреси за ресурса",
|
||||
"actionGetResourceEmailWhitelist": "Вземете списък на одобрените имейл адреси за ресурса",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Получете политика за ресурси",
|
||||
"actionUpdateResourcePolicy": "Актуализирайте политика за ресурси",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Задайте потребители на ресурсна политика",
|
||||
"actionSetResourcePolicyRoles": "Задайте роли на ресурсна политика",
|
||||
"actionSetResourcePolicyPassword": "Задайте парола на ресурсна политика",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Prosím ujistěte se, že jste přihlášeni jako správný uživatel.",
|
||||
"inviteErrorNoUser": "Je nám líto, ale vypadá to, že pozvánka, ke které se snažíte získat přístup, není pro existujícího uživatele.",
|
||||
"inviteCreateUser": "Nejprve si prosím vytvořte účet.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Přejít na hlavní stránku",
|
||||
"inviteLogInOtherUser": "Přihlásit se jako jiný uživatel",
|
||||
"createAnAccount": "Vytvořit účet",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Nastavit zdrojový kód",
|
||||
"actionSetResourceEmailWhitelist": "Nastavit seznam povolených dokumentů",
|
||||
"actionGetResourceEmailWhitelist": "Získat seznam povolených dokumentů",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Získat zásady zdroje",
|
||||
"actionUpdateResourcePolicy": "Aktualizovat zásady zdroje",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Nastavte uživatele pro zásady zdroje",
|
||||
"actionSetResourcePolicyRoles": "Nastavte role pro zásady zdroje",
|
||||
"actionSetResourcePolicyPassword": "Nastavte heslo pro zásady zdroje",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Venligst tjek at du er loget ind som korrekt bruger.",
|
||||
"inviteErrorNoUser": "Beklager, men det ser ud til, at invitationen du prøver at få adgang til, ikke er til en eksisterende bruger.",
|
||||
"inviteCreateUser": "Opret venligst en konto først.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Gå hjem",
|
||||
"inviteLogInOtherUser": "Log ind som en anden bruger",
|
||||
"createAnAccount": "Opret konto",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Angiv ressource-PIN-kode",
|
||||
"actionSetResourceEmailWhitelist": "Angiv e-mailwhitelist for ressource",
|
||||
"actionGetResourceEmailWhitelist": "Hent e-mailwhitelist for ressource",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Få ressourceretningslinjen",
|
||||
"actionUpdateResourcePolicy": "Opdater ressourceretningslinjen",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Angiv ressourceretningslinjens brugere",
|
||||
"actionSetResourcePolicyRoles": "Angiv ressourceretningslinjens roller",
|
||||
"actionSetResourcePolicyPassword": "Angiv ressourceretningslinjen for adgangskode",
|
||||
|
||||
+8
-3
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Bitte stelle sicher, dass du als korrekter Benutzer angemeldet bist.",
|
||||
"inviteErrorNoUser": "Es tut uns leid, aber es sieht so aus, als sei die Einladung, auf die du zugreifen möchtest, nicht für einen existierenden Benutzer bestimmt.",
|
||||
"inviteCreateUser": "Bitte erstelle zuerst ein Konto.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Zur Startseite",
|
||||
"inviteLogInOtherUser": "Als anderer Benutzer anmelden",
|
||||
"createAnAccount": "Konto erstellen",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Ressourcen-PIN festlegen",
|
||||
"actionSetResourceEmailWhitelist": "Ressourcen-E-Mail-Whitelist festlegen",
|
||||
"actionGetResourceEmailWhitelist": "Ressourcen-E-Mail-Whitelist abrufen",
|
||||
"actionListResourcePolicies": "Ressourcen-Richtlinien auflisten",
|
||||
"actionCreateResourcePolicy": "Ressourcen-Richtlinie erstellen",
|
||||
"actionGetResourcePolicy": "Ressourcenrichtlinie abrufen",
|
||||
"actionUpdateResourcePolicy": "Ressourcenrichtlinie aktualisieren",
|
||||
"actionDeleteResourcePolicy": "Ressourcen-Richtlinie löschen",
|
||||
"actionSetResourcePolicyUsers": "Ressourcenrichtlinienbenutzer festlegen",
|
||||
"actionSetResourcePolicyRoles": "Rollen der Ressourcenrichtlinie festlegen",
|
||||
"actionSetResourcePolicyPassword": "Passwort der Ressourcenrichtlinie festlegen",
|
||||
@@ -2012,7 +2017,7 @@
|
||||
"billingSites": "Standorte",
|
||||
"billingUsers": "Benutzergeräte",
|
||||
"billingDomains": "Domänen",
|
||||
"billingOrganizations": "Orden",
|
||||
"billingOrganizations": "Organisationen",
|
||||
"billingRemoteExitNodes": "Entfernte Knoten",
|
||||
"billingPublicResources": "Öffentliche Ressourcen",
|
||||
"billingPrivateResources": "Private Ressourcen",
|
||||
@@ -2172,7 +2177,7 @@
|
||||
"billingResolvePaymentIssue": "Bitte beheben Sie Ihr Zahlungsproblem vor dem Upgrade oder Herabstufen",
|
||||
"signUpTerms": {
|
||||
"IAgreeToThe": "Ich stimme den",
|
||||
"termsOfService": "Nutzungsbedingungen zu",
|
||||
"termsOfService": "Nutzungsbedingungen",
|
||||
"and": "und",
|
||||
"privacyPolicy": "datenschutzrichtlinie."
|
||||
},
|
||||
@@ -3390,7 +3395,7 @@
|
||||
"enterMfaCode": "Geben Sie den Code aus Ihrer Authentifizierungs-App ein",
|
||||
"securityKeyRequired": "Bitte verwenden Sie Ihren Sicherheitsschlüssel zum Anmelden.",
|
||||
"needToUseAnotherAccount": "Benötigen Sie ein anderes Konto?",
|
||||
"loginLegalDisclaimer": "Indem Sie auf die Buttons unten klicken, bestätigen Sie, dass Sie gelesen haben, verstehen, und stimmen den <termsOfService>Nutzungsbedingungen</termsOfService> und <privacyPolicy>Datenschutzrichtlinien</privacyPolicy> zu.",
|
||||
"loginLegalDisclaimer": "Indem Sie auf die Buttons unten klicken, bestätigen Sie, dass Sie die <termsOfService>Nutzungsbedingungen</termsOfService> und <privacyPolicy>Datenschutzrichtlinien</privacyPolicy> gelesen haben, verstehen und ihnen zustimmen.",
|
||||
"termsOfService": "Nutzungsbedingungen",
|
||||
"privacyPolicy": "Datenschutzerklärung",
|
||||
"userNotFoundWithUsername": "Kein Benutzer mit diesem Benutzernamen gefunden.",
|
||||
|
||||
@@ -43,8 +43,6 @@
|
||||
"inviteLoginUser": "Please make sure you're logged in as the correct user.",
|
||||
"inviteErrorNoUser": "We're sorry, but it looks like the invite you're trying to access is not for a user that exists.",
|
||||
"inviteCreateUser": "Please create an account first.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Go Home",
|
||||
"inviteLogInOtherUser": "Log In as a Different User",
|
||||
"createAnAccount": "Create an Account",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Por favor, asegúrese de que ha iniciado sesión como el usuario correcto.",
|
||||
"inviteErrorNoUser": "Lo sentimos, pero parece que la invitación a la que intentas acceder no es para un usuario que existe.",
|
||||
"inviteCreateUser": "Por favor, cree una cuenta primero.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Ir a casa",
|
||||
"inviteLogInOtherUser": "Iniciar sesión como un usuario diferente",
|
||||
"createAnAccount": "Crear una cuenta",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Establecer Pincode del recurso",
|
||||
"actionSetResourceEmailWhitelist": "Establecer lista blanca de correo de recursos",
|
||||
"actionGetResourceEmailWhitelist": "Obtener correo electrónico de recursos",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Obtener política de recursos",
|
||||
"actionUpdateResourcePolicy": "Actualizar política de recursos",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Definir política de recursos para usuarios",
|
||||
"actionSetResourcePolicyRoles": "Definir roles de política de recursos",
|
||||
"actionSetResourcePolicyPassword": "Definir contraseña de política de recursos",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Veuillez vous assurer que vous êtes connecté avec le bon compte.",
|
||||
"inviteErrorNoUser": "Nous sommes désolés, mais il semble que l'invitation à laquelle vous essayez d'accéder ne concerne pas un utilisateur existant.",
|
||||
"inviteCreateUser": "Veuillez d'abord créer un compte.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Retour à l'accueil",
|
||||
"inviteLogInOtherUser": "Se connecter en tant qu'utilisateur différent",
|
||||
"createAnAccount": "Créer un compte",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Définir le code PIN de la ressource",
|
||||
"actionSetResourceEmailWhitelist": "Définir la liste blanche des emails de la ressource",
|
||||
"actionGetResourceEmailWhitelist": "Obtenir la liste blanche des emails de la ressource",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Obtenir une politique de ressources",
|
||||
"actionUpdateResourcePolicy": "Mettre à jour la politique de ressources",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Définir les utilisateurs de la politique de ressources",
|
||||
"actionSetResourcePolicyRoles": "Définir les rôles de la politique de ressources",
|
||||
"actionSetResourcePolicyPassword": "Définir le mot de passe de la politique de ressources",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Assicurati di aver effettuato l'accesso come utente corretto.",
|
||||
"inviteErrorNoUser": "Siamo spiacenti, ma sembra che l'invito che stai cercando di accedere non sia per un utente che esiste.",
|
||||
"inviteCreateUser": "Si prega di creare un account prima.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Vai alla Home",
|
||||
"inviteLogInOtherUser": "Accedi come utente diverso",
|
||||
"createAnAccount": "Crea un account",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Imposta Codice PIN Risorsa",
|
||||
"actionSetResourceEmailWhitelist": "Imposta Lista Autorizzazioni Email Risorsa",
|
||||
"actionGetResourceEmailWhitelist": "Ottieni Lista Autorizzazioni Email Risorsa",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Ottieni la Politica della Risorsa",
|
||||
"actionUpdateResourcePolicy": "Aggiorna la Politica della Risorsa",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Imposta Utenti della Politica Risorsa",
|
||||
"actionSetResourcePolicyRoles": "Imposta Ruoli della Politica Risorsa",
|
||||
"actionSetResourcePolicyPassword": "Imposta Password della Politica Risorsa",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "올바른 사용자로 로그인했는지 확인하십시오.",
|
||||
"inviteErrorNoUser": "죄송하지만, 접근하려는 초대가 존재하지 않는 사용자에 대한 것인 것 같습니다.",
|
||||
"inviteCreateUser": "먼저 계정을 생성해 주세요.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "홈으로 가기",
|
||||
"inviteLogInOtherUser": "다른 사용자로 로그인",
|
||||
"createAnAccount": "계정 만들기",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "리소스 핀코드 설정",
|
||||
"actionSetResourceEmailWhitelist": "리소스 이메일 화이트리스트 설정",
|
||||
"actionGetResourceEmailWhitelist": "리소스 이메일 화이트리스트 가져오기",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "리소스 정책 가져오기",
|
||||
"actionUpdateResourcePolicy": "리소스 정책 업데이트",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "리소스 정책 사용자 설정",
|
||||
"actionSetResourcePolicyRoles": "리소스 정책 역할 설정",
|
||||
"actionSetResourcePolicyPassword": "리소스 정책 비밀번호 설정",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Vennligst sjekk at du er logget inn som riktig bruker.",
|
||||
"inviteErrorNoUser": "Vi beklager, men det ser ut som invitasjonen du prøver å få tilgang til ikke er for en bruker som eksisterer.",
|
||||
"inviteCreateUser": "Vennligst opprett en konto først.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Gå hjem",
|
||||
"inviteLogInOtherUser": "Logg inn som en annen bruker",
|
||||
"createAnAccount": "Lag konto",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Angi ressurspinkode",
|
||||
"actionSetResourceEmailWhitelist": "Angi e-post-hviteliste for ressurs",
|
||||
"actionGetResourceEmailWhitelist": "Hent e-post-hviteliste for ressurs",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Hent ressursregel",
|
||||
"actionUpdateResourcePolicy": "Oppdater ressursregel",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Sett ressursregel for brukere",
|
||||
"actionSetResourcePolicyRoles": "Sett ressursregel for roller",
|
||||
"actionSetResourcePolicyPassword": "Sett ressursregel for passord",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Controleer of je bent aangemeld als de juiste gebruiker.",
|
||||
"inviteErrorNoUser": "Het spijt ons, maar de uitnodiging die u probeert te gebruiken is niet voor een bestaande gebruiker.",
|
||||
"inviteCreateUser": "U moet eerst een account aanmaken.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Ga naar huis",
|
||||
"inviteLogInOtherUser": "Log in als een andere gebruiker",
|
||||
"createAnAccount": "Account aanmaken",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Stel Resource Pincode in",
|
||||
"actionSetResourceEmailWhitelist": "Stel Resource e-mail whitelist in",
|
||||
"actionGetResourceEmailWhitelist": "Verkrijg Resource E-mail Whitelist",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Haal Bronbeleid op",
|
||||
"actionUpdateResourcePolicy": "Werk Bronbeleid bij",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Stel gebruikers van bronbeleid in",
|
||||
"actionSetResourcePolicyRoles": "Stel rollen van bronbeleid in",
|
||||
"actionSetResourcePolicyPassword": "Stel wachtwoord van bronbeleid in",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Upewnij się, że jesteś zalogowany jako właściwy użytkownik.",
|
||||
"inviteErrorNoUser": "Przykro nam, ale wygląda na to, że zaproszenie, do którego próbujesz uzyskać dostęp, nie jest dla użytkownika, który istnieje.",
|
||||
"inviteCreateUser": "Proszę najpierw utworzyć konto.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Przejdź do strony głównej",
|
||||
"inviteLogInOtherUser": "Zaloguj się jako inny użytkownik",
|
||||
"createAnAccount": "Utwórz konto",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Ustaw kod PIN zasobu",
|
||||
"actionSetResourceEmailWhitelist": "Ustaw białą listę email zasobu",
|
||||
"actionGetResourceEmailWhitelist": "Pobierz białą listę email zasobu",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Pobierz politykę zasobów",
|
||||
"actionUpdateResourcePolicy": "Zaktualizuj politykę zasobów",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Ustaw użytkowników polityki zasobów",
|
||||
"actionSetResourcePolicyRoles": "Ustaw role polityki zasobów",
|
||||
"actionSetResourcePolicyPassword": "Ustaw hasło polityki zasobów",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Verifique se você está logado como o utilizador correto.",
|
||||
"inviteErrorNoUser": "Desculpe, mas parece que o convite que está a tentar aceder não é para um utilizador que existe.",
|
||||
"inviteCreateUser": "Por favor, crie uma conta primeiro.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Voltar ao inicio",
|
||||
"inviteLogInOtherUser": "Fazer login como um utilizador diferente",
|
||||
"createAnAccount": "Crie uma conta",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Definir Código PIN do Recurso",
|
||||
"actionSetResourceEmailWhitelist": "Definir Lista Permitida de Emails do Recurso",
|
||||
"actionGetResourceEmailWhitelist": "Obter Lista Permitida de Emails do Recurso",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Obter Política de Recurso",
|
||||
"actionUpdateResourcePolicy": "Atualizar Política de Recurso",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Definir Utilizadores da Política de Recurso",
|
||||
"actionSetResourcePolicyRoles": "Definir Papéis da Política de Recurso",
|
||||
"actionSetResourcePolicyPassword": "Definir Palavra-passe da Política de Recurso",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Убедитесь, что вы вошли под правильным пользователем.",
|
||||
"inviteErrorNoUser": "Извините, но похоже, что приглашение, к которому вы пытаетесь получить доступ, предназначено для несуществующего пользователя.",
|
||||
"inviteCreateUser": "Сначала создайте аккаунт.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "На главную",
|
||||
"inviteLogInOtherUser": "Войти под другим пользователем",
|
||||
"createAnAccount": "Создать учётную запись",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Установить ПИН-код ресурса",
|
||||
"actionSetResourceEmailWhitelist": "Настроить белый список ресурсов email",
|
||||
"actionGetResourceEmailWhitelist": "Получить белый список ресурсов email",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Получить политику ресурса",
|
||||
"actionUpdateResourcePolicy": "Обновить политику ресурса",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Установить пользователей политики ресурса",
|
||||
"actionSetResourcePolicyRoles": "Установить роли политики ресурса",
|
||||
"actionSetResourcePolicyPassword": "Установить пароль политики ресурса",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "Lütfen doğru kullanıcı olarak oturum açtığınızdan emin olun.",
|
||||
"inviteErrorNoUser": "Üzgünüz, ancak erişmeye çalıştığınız davet, var olan bir kullanıcı için değil gibi görünüyor.",
|
||||
"inviteCreateUser": "Öncelikle bir hesap oluşturun.",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "Ana Sayfaya Dön",
|
||||
"inviteLogInOtherUser": "Başka bir kullanıcı olarak giriş yapın",
|
||||
"createAnAccount": "Bir Hesap Oluşturun",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "Kaynak PIN Kodunu Ayarla",
|
||||
"actionSetResourceEmailWhitelist": "Kaynak E-posta Beyaz Listesi Ayarla",
|
||||
"actionGetResourceEmailWhitelist": "Kaynak E-posta Beyaz Listesini Al",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "Kaynak Politikasını Al",
|
||||
"actionUpdateResourcePolicy": "Kaynak Politikasını Güncelle",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "Kaynak Politika Kullanıcılarını Ayarla",
|
||||
"actionSetResourcePolicyRoles": "Kaynak Politika Rolleri Ayarla",
|
||||
"actionSetResourcePolicyPassword": "Kaynak Politika Şifresini Ayarla",
|
||||
|
||||
@@ -43,6 +43,8 @@
|
||||
"inviteLoginUser": "请确保您以正确的用户登录。",
|
||||
"inviteErrorNoUser": "很抱歉,但看起来你想访问的邀请不是一个存在的用户。",
|
||||
"inviteCreateUser": "请先创建一个帐户。",
|
||||
"inviteErrorOidcNotAllowed": "Invites can only be accepted by internal accounts. Sign out and log in with your password for this email.",
|
||||
"inviteLoginInternalOnly": "Invites require an internal account with a password. Create an account or sign in with your password.",
|
||||
"goHome": "返回首页",
|
||||
"inviteLogInOtherUser": "以不同的用户登录",
|
||||
"createAnAccount": "创建帐户",
|
||||
@@ -1449,8 +1451,11 @@
|
||||
"actionSetResourcePincode": "设置资源粉码",
|
||||
"actionSetResourceEmailWhitelist": "设置资源电子邮件白名单",
|
||||
"actionGetResourceEmailWhitelist": "获取资源电子邮件白名单",
|
||||
"actionListResourcePolicies": "List Resource Policies",
|
||||
"actionCreateResourcePolicy": "Create Resource Policy",
|
||||
"actionGetResourcePolicy": "获取资源策略",
|
||||
"actionUpdateResourcePolicy": "更新资源策略",
|
||||
"actionDeleteResourcePolicy": "Delete Resource Policy",
|
||||
"actionSetResourcePolicyUsers": "设置资源策略用户",
|
||||
"actionSetResourcePolicyRoles": "设置资源策略角色",
|
||||
"actionSetResourcePolicyPassword": "设置资源策略密码",
|
||||
|
||||
@@ -95,8 +95,7 @@ export const subscriptions = pgTable("subscriptions", {
|
||||
billingCycleAnchor: bigint("billingCycleAnchor", { mode: "number" }),
|
||||
expiresAt: bigint("expiresAt", { mode: "number" }),
|
||||
trial: boolean("trial").default(false),
|
||||
type: varchar("type", { length: 50 }), // tier1, tier2, tier3, or license
|
||||
override: boolean("override").default(false)
|
||||
type: varchar("type", { length: 50 }) // tier1, tier2, tier3, or license
|
||||
});
|
||||
|
||||
export const subscriptionItems = pgTable("subscriptionItems", {
|
||||
|
||||
@@ -89,8 +89,7 @@ export const subscriptions = sqliteTable("subscriptions", {
|
||||
expiresAt: integer("expiresAt"),
|
||||
trial: integer("trial", { mode: "boolean" }).default(false),
|
||||
billingCycleAnchor: integer("billingCycleAnchor"),
|
||||
type: text("type"), // tier1, tier2, tier3, or license
|
||||
override: integer("override", { mode: "boolean" }).default(false)
|
||||
type: text("type") // tier1, tier2, tier3, or license
|
||||
});
|
||||
|
||||
export const subscriptionItems = sqliteTable("subscriptionItems", {
|
||||
|
||||
@@ -632,6 +632,7 @@ export const ResourcePolicySchema = z.object({
|
||||
})
|
||||
)
|
||||
)
|
||||
.max(50)
|
||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||
.optional()
|
||||
.default([]),
|
||||
|
||||
@@ -1,9 +1,8 @@
|
||||
import { db, idp, idpOrg, Transaction } from "@server/db";
|
||||
import { and, eq } from "drizzle-orm";
|
||||
import { build } from "@server/build";
|
||||
|
||||
export function isOrgIdentityProviderMode(): boolean {
|
||||
return build === "saas" || process.env.IDENTITY_PROVIDER_MODE === "org";
|
||||
return process.env.IDENTITY_PROVIDER_MODE === "org";
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
@@ -53,15 +53,6 @@ export async function handleSubscriptionDeleted(
|
||||
return;
|
||||
}
|
||||
|
||||
// If the subscription has been manually overridden, we lock it down
|
||||
// so Stripe can no longer change (or delete) its status locally.
|
||||
if (existingSubscription.override === true) {
|
||||
logger.info(
|
||||
`Subscription ${subscription.id} is locked (override=true). Ignoring deletion event from Stripe.`
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
await db
|
||||
.delete(subscriptions)
|
||||
.where(eq(subscriptions.subscriptionId, subscription.id));
|
||||
|
||||
@@ -68,25 +68,11 @@ export async function handleSubscriptionUpdated(
|
||||
const type = getSubType(fullSubscription);
|
||||
const previousType = existingSubscription.type as SubscriptionType | null;
|
||||
|
||||
// If the subscription has been manually overridden, we lock the
|
||||
// status down so Stripe webhooks can no longer change it.
|
||||
const isLocked = existingSubscription.override === true;
|
||||
if (isLocked) {
|
||||
logger.info(
|
||||
`Subscription ${subscription.id} is locked (override=true). Ignoring status change from Stripe (would have been ${subscription.status}).`
|
||||
);
|
||||
}
|
||||
const effectiveStatus = isLocked
|
||||
? existingSubscription.status
|
||||
: subscription.status;
|
||||
|
||||
await db
|
||||
.update(subscriptions)
|
||||
.set({
|
||||
status: effectiveStatus,
|
||||
canceledAt: isLocked
|
||||
? existingSubscription.canceledAt
|
||||
: subscription.canceled_at
|
||||
status: subscription.status,
|
||||
canceledAt: subscription.canceled_at
|
||||
? subscription.canceled_at
|
||||
: null,
|
||||
updatedAt: Math.floor(Date.now() / 1000),
|
||||
@@ -289,23 +275,23 @@ export async function handleSubscriptionUpdated(
|
||||
// we only need to handle the limit lifecycle for saas subscriptions not for the licenses
|
||||
await handleSubscriptionLifesycle(
|
||||
customer.orgId,
|
||||
effectiveStatus,
|
||||
subscription.status,
|
||||
type
|
||||
);
|
||||
|
||||
// Handle feature lifecycle when subscription is canceled or becomes unpaid
|
||||
if (
|
||||
effectiveStatus === "canceled" ||
|
||||
effectiveStatus === "unpaid" ||
|
||||
effectiveStatus === "incomplete_expired"
|
||||
subscription.status === "canceled" ||
|
||||
subscription.status === "unpaid" ||
|
||||
subscription.status === "incomplete_expired"
|
||||
) {
|
||||
logger.info(
|
||||
`Subscription ${subscription.id} for org ${customer.orgId} is ${effectiveStatus}, disabling paid features`
|
||||
`Subscription ${subscription.id} for org ${customer.orgId} is ${subscription.status}, disabling paid features`
|
||||
);
|
||||
await handleTierChange(customer.orgId, null, previousType ?? undefined);
|
||||
}
|
||||
} else if (type === "license") {
|
||||
if (effectiveStatus === "canceled" || effectiveStatus == "unpaid" || effectiveStatus == "incomplete_expired") {
|
||||
if (subscription.status === "canceled" || subscription.status == "unpaid" || subscription.status == "incomplete_expired") {
|
||||
try {
|
||||
// WARNING:
|
||||
// this invalidates ALL OF THE ENTERPRISE LICENSES for this orgId
|
||||
|
||||
@@ -107,6 +107,7 @@ const createResourcePolicyBodySchema = z.strictObject({
|
||||
})
|
||||
)
|
||||
)
|
||||
.max(50)
|
||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||
.optional()
|
||||
.default([]),
|
||||
|
||||
@@ -19,6 +19,7 @@ const setResourcePolicyWhitelistBodySchema = z.strictObject({
|
||||
})
|
||||
)
|
||||
)
|
||||
.max(50)
|
||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||
});
|
||||
|
||||
|
||||
@@ -24,6 +24,7 @@ const setResourceWhitelistBodySchema = z.strictObject({
|
||||
})
|
||||
)
|
||||
)
|
||||
.max(50)
|
||||
.transform((v) => v.map((e) => e.toLowerCase()))
|
||||
});
|
||||
|
||||
|
||||
@@ -22,7 +22,6 @@ import { calculateUserClientsForOrgs } from "@server/lib/calculateUserClientsFor
|
||||
import { build } from "@server/build";
|
||||
import { assignUserToOrg } from "@server/lib/userOrg";
|
||||
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
||||
import { UserType } from "@server/types/UserTypes";
|
||||
|
||||
const acceptInviteBodySchema = z.strictObject({
|
||||
token: z.string(),
|
||||
@@ -67,17 +66,12 @@ export async function acceptInvite(
|
||||
);
|
||||
}
|
||||
|
||||
const [existingInternalUser] = await db
|
||||
const existingUser = await db
|
||||
.select()
|
||||
.from(users)
|
||||
.where(
|
||||
and(
|
||||
eq(users.email, existingInvite.email),
|
||||
eq(users.type, UserType.Internal)
|
||||
)
|
||||
)
|
||||
.where(eq(users.email, existingInvite.email))
|
||||
.limit(1);
|
||||
if (!existingInternalUser) {
|
||||
if (!existingUser.length) {
|
||||
return next(
|
||||
createHttpError(
|
||||
HttpCode.BAD_REQUEST,
|
||||
@@ -86,8 +80,9 @@ export async function acceptInvite(
|
||||
);
|
||||
}
|
||||
|
||||
const { user } = await verifySession(req);
|
||||
const { user, session } = await verifySession(req);
|
||||
|
||||
// at this point we know the user exists
|
||||
if (!user) {
|
||||
return next(
|
||||
createHttpError(
|
||||
@@ -97,7 +92,7 @@ export async function acceptInvite(
|
||||
);
|
||||
}
|
||||
|
||||
if (user.email !== existingInvite.email) {
|
||||
if (user && user.email !== existingInvite.email) {
|
||||
return next(
|
||||
createHttpError(
|
||||
HttpCode.BAD_REQUEST,
|
||||
@@ -106,15 +101,6 @@ export async function acceptInvite(
|
||||
);
|
||||
}
|
||||
|
||||
if (user.type !== UserType.Internal) {
|
||||
return next(
|
||||
createHttpError(
|
||||
HttpCode.BAD_REQUEST,
|
||||
"Invites can only be accepted by internal users."
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
if (build == "saas") {
|
||||
const usage = await usageService.getUsage(
|
||||
existingInvite.orgId,
|
||||
@@ -209,7 +195,7 @@ export async function acceptInvite(
|
||||
await assignUserToOrg(
|
||||
org,
|
||||
{
|
||||
userId: user.userId,
|
||||
userId: existingUser[0].userId,
|
||||
orgId: existingInvite.orgId
|
||||
},
|
||||
inviteRoleIds,
|
||||
@@ -222,13 +208,13 @@ export async function acceptInvite(
|
||||
.where(eq(userInvites.inviteId, inviteId));
|
||||
|
||||
logger.debug(
|
||||
`User ${user.userId} accepted invite to org ${existingInvite.orgId}`
|
||||
`User ${existingUser[0].userId} accepted invite to org ${existingInvite.orgId}`
|
||||
);
|
||||
});
|
||||
|
||||
calculateUserClientsForOrgs(user.userId).catch((e) => {
|
||||
calculateUserClientsForOrgs(existingUser[0].userId).catch((e) => {
|
||||
logger.error(
|
||||
`Failed to calculate user clients after accepting invite for user ${user.userId}: ${e}`
|
||||
`Failed to calculate user clients after accepting invite for user ${existingUser[0].userId}: ${e}`
|
||||
);
|
||||
});
|
||||
|
||||
|
||||
@@ -20,7 +20,6 @@ import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
||||
import { assignUserToOrg } from "@server/lib/userOrg";
|
||||
import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed";
|
||||
import { isOrgRebuildRateLimited } from "@server/lib/rebuildClientAssociations";
|
||||
import { idpExistsForOrg } from "@server/lib/idp/idpExistsForOrg";
|
||||
|
||||
const paramsSchema = z.strictObject({
|
||||
orgId: z.string().nonempty()
|
||||
@@ -240,16 +239,6 @@ export async function createOrgUser(
|
||||
);
|
||||
}
|
||||
|
||||
const providerExists = await idpExistsForOrg(idpId, orgId);
|
||||
if (!providerExists) {
|
||||
return next(
|
||||
createHttpError(
|
||||
HttpCode.BAD_REQUEST,
|
||||
"Identity provider not found in this organization"
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
const [idpRes] = await db
|
||||
.select()
|
||||
.from(idp)
|
||||
|
||||
@@ -107,7 +107,7 @@ const listUsersSchema = z.strictObject({
|
||||
.filter((n) => Number.isInteger(n) && n > 0);
|
||||
const unique = [...new Set(nums)];
|
||||
return unique.length ? unique : undefined;
|
||||
}, z.array(z.number().int().positive()).optional())
|
||||
}, z.array(z.number().int().positive()).max(50).optional())
|
||||
.openapi({
|
||||
description:
|
||||
"Filter users who have any of these role ids in the organization (repeat query param)"
|
||||
|
||||
@@ -38,6 +38,18 @@ import { useEffect, useState } from "react";
|
||||
import { useForm } from "react-hook-form";
|
||||
import { z } from "zod";
|
||||
|
||||
const accessControlsFormSchema = z.object({
|
||||
username: z.string(),
|
||||
autoProvisioned: z.boolean(),
|
||||
roles: z.array(
|
||||
z.object({
|
||||
id: z.string(),
|
||||
text: z.string(),
|
||||
isAdmin: z.boolean().optional()
|
||||
})
|
||||
)
|
||||
});
|
||||
|
||||
export default function AccessControlsPage() {
|
||||
const { orgUser: user, updateOrgUser } = userOrgUserContext();
|
||||
const { user: sessionUser } = useUserContext();
|
||||
@@ -57,20 +69,6 @@ export default function AccessControlsPage() {
|
||||
(build === "enterprise" && !isPaid) ||
|
||||
(build === "oss" && !isPaid));
|
||||
|
||||
const accessControlsFormSchema = z.object({
|
||||
username: z.string(),
|
||||
autoProvisioned: z.boolean(),
|
||||
roles: z
|
||||
.array(
|
||||
z.object({
|
||||
id: z.string(),
|
||||
text: z.string(),
|
||||
isAdmin: z.boolean().optional()
|
||||
})
|
||||
)
|
||||
.min(1, { message: t("accessRoleSelectPlease") })
|
||||
});
|
||||
|
||||
const form = useForm({
|
||||
resolver: zodResolver(accessControlsFormSchema),
|
||||
defaultValues: {
|
||||
@@ -110,6 +108,15 @@ export default function AccessControlsPage() {
|
||||
async function executeSave() {
|
||||
const values = form.getValues();
|
||||
|
||||
if (values.roles.length === 0) {
|
||||
toast({
|
||||
variant: "destructive",
|
||||
title: t("accessRoleRequired"),
|
||||
description: t("accessRoleSelectPlease")
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
setIsSaving(true);
|
||||
try {
|
||||
const roleIds = values.roles.map((r) => parseInt(r.id, 10));
|
||||
@@ -163,6 +170,15 @@ export default function AccessControlsPage() {
|
||||
|
||||
const values = form.getValues();
|
||||
|
||||
if (values.roles.length === 0) {
|
||||
toast({
|
||||
variant: "destructive",
|
||||
title: t("accessRoleRequired"),
|
||||
description: t("accessRoleSelectPlease")
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
const willHaveAdminRole = values.roles.some((r) => r.isAdmin === true);
|
||||
|
||||
const isRemovingOwnAdmin =
|
||||
|
||||
@@ -237,13 +237,10 @@ export default function Page() {
|
||||
return;
|
||||
}
|
||||
|
||||
const useOrgIdps =
|
||||
build === "saas" || env.app.identityProviderMode === "org";
|
||||
|
||||
const res = await api
|
||||
.get<
|
||||
AxiosResponse<ListIdpsResponse>
|
||||
>(useOrgIdps ? `/org/${orgId}/idp` : "/idp")
|
||||
>(build === "saas" ? `/org/${orgId}/idp` : "/idp")
|
||||
.catch((e) => {
|
||||
console.error(e);
|
||||
toast({
|
||||
@@ -304,7 +301,8 @@ export default function Page() {
|
||||
);
|
||||
const [isSubmittingExternal, setIsSubmittingExternal] = useState(false);
|
||||
|
||||
const loading = isSubmittingInternal || isSubmittingExternal;
|
||||
const loading =
|
||||
isSubmittingInternal || isSubmittingExternal;
|
||||
|
||||
async function onSubmitInternal() {
|
||||
const isValid = await internalForm.trigger();
|
||||
|
||||
@@ -193,10 +193,7 @@ export default async function Page(props: {
|
||||
redirect={redirectUrl}
|
||||
forceLogin={forceLogin}
|
||||
defaultUser={defaultUser}
|
||||
inviteMode={isInvite}
|
||||
lastUsedIdp={
|
||||
isInvite ? null : lastUsedIdpForSmartLogin
|
||||
}
|
||||
lastUsedIdp={lastUsedIdpForSmartLogin}
|
||||
orgSignIn={
|
||||
!isInvite &&
|
||||
(build === "saas" ||
|
||||
@@ -216,7 +213,7 @@ export default async function Page(props: {
|
||||
) : (
|
||||
<DashboardLoginForm
|
||||
redirect={redirectUrl}
|
||||
idps={isInvite ? [] : loginIdps}
|
||||
idps={loginIdps}
|
||||
forceLogin={forceLogin}
|
||||
showOrgLogin={
|
||||
!isInvite &&
|
||||
|
||||
@@ -53,7 +53,7 @@ import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
||||
import { usePaidStatus } from "@/hooks/usePaidStatus";
|
||||
import { TierFeature, tierMatrix } from "@server/lib/billing/tierMatrix";
|
||||
import { toUnicode } from "punycode";
|
||||
import { useCallback, useEffect, useMemo, useRef, useState } from "react";
|
||||
import { useCallback, useEffect, useMemo, useState } from "react";
|
||||
import { useUserContext } from "@app/hooks/useUserContext";
|
||||
|
||||
type AvailableOption = {
|
||||
@@ -166,19 +166,8 @@ export default function DomainPicker({
|
||||
const [selectedProvidedDomain, setSelectedProvidedDomain] =
|
||||
useState<AvailableOption | null>(null);
|
||||
|
||||
// Only run the initial base-domain selection once the domains have
|
||||
// loaded. This must not re-run on later `defaultDomainId`/`defaultSubdomain`
|
||||
// changes, because selecting a provided (namespace) domain calls
|
||||
// onDomainChange(null), which the parent form echoes back as
|
||||
// defaultDomainId/defaultSubdomain becoming undefined — re-running this
|
||||
// effect on that change would immediately snap the selector back to the
|
||||
// organization domain, making provided domains unselectable whenever one
|
||||
// was already set.
|
||||
const didSelectInitialDomainRef = useRef(false);
|
||||
|
||||
useEffect(() => {
|
||||
if (!loadingDomains && !didSelectInitialDomainRef.current) {
|
||||
didSelectInitialDomainRef.current = true;
|
||||
if (!loadingDomains) {
|
||||
let domainOptionToSelect: DomainOption | null = null;
|
||||
if (organizationDomains.length > 0) {
|
||||
// Select the first organization domain or the one provided from props
|
||||
|
||||
@@ -44,7 +44,6 @@ export default function InviteStatusCard({
|
||||
| "user_does_not_exist"
|
||||
| "not_logged_in"
|
||||
| "user_limit_exceeded"
|
||||
| "oidc_not_allowed"
|
||||
>("rejected");
|
||||
|
||||
useEffect(() => {
|
||||
@@ -70,12 +69,6 @@ export default function InviteStatusCard({
|
||||
function cardType() {
|
||||
if (error.includes("Invite is not for this user")) {
|
||||
return "wrong_user";
|
||||
} else if (
|
||||
error.includes(
|
||||
"Invites can only be accepted by internal users."
|
||||
)
|
||||
) {
|
||||
return "oidc_not_allowed";
|
||||
} else if (
|
||||
error.includes(
|
||||
"User does not exist. Please create an account first."
|
||||
@@ -173,14 +166,6 @@ export default function InviteStatusCard({
|
||||
<p className="text-center">{t("inviteCreateUser")}</p>
|
||||
</div>
|
||||
);
|
||||
} else if (type === "oidc_not_allowed") {
|
||||
return (
|
||||
<div>
|
||||
<p className="text-center mb-4">
|
||||
{t("inviteErrorOidcNotAllowed")}
|
||||
</p>
|
||||
</div>
|
||||
);
|
||||
} else if (type === "user_limit_exceeded") {
|
||||
return (
|
||||
<div>
|
||||
@@ -214,10 +199,6 @@ export default function InviteStatusCard({
|
||||
);
|
||||
} else if (type === "user_does_not_exist") {
|
||||
return <Button onClick={goToSignup}>{t("createAnAccount")}</Button>;
|
||||
} else if (type === "oidc_not_allowed") {
|
||||
return (
|
||||
<Button onClick={goToLogin}>{t("inviteLogInOtherUser")}</Button>
|
||||
);
|
||||
} else if (type === "user_limit_exceeded") {
|
||||
return (
|
||||
<Button
|
||||
|
||||
@@ -8,7 +8,6 @@ import {
|
||||
InfoSections,
|
||||
InfoSectionTitle
|
||||
} from "@app/components/InfoSection";
|
||||
import CopyToClipboard from "@app/components/CopyToClipboard";
|
||||
import { useTranslations } from "next-intl";
|
||||
|
||||
type OrgInfoCardProps = {};
|
||||
@@ -27,9 +26,7 @@ export default function OrgInfoCard({}: OrgInfoCardProps) {
|
||||
</InfoSection>
|
||||
<InfoSection>
|
||||
<InfoSectionTitle>{t("orgId")}</InfoSectionTitle>
|
||||
<InfoSectionContent>
|
||||
<CopyToClipboard text={org.org.orgId} />
|
||||
</InfoSectionContent>
|
||||
<InfoSectionContent>{org.org.orgId}</InfoSectionContent>
|
||||
</InfoSection>
|
||||
<InfoSection>
|
||||
<InfoSectionTitle>{t("subnet")}</InfoSectionTitle>
|
||||
|
||||
@@ -9,15 +9,17 @@ import {
|
||||
FormMessage
|
||||
} from "@app/components/ui/form";
|
||||
|
||||
import { toast } from "@app/hooks/useToast";
|
||||
import { useTranslations } from "next-intl";
|
||||
|
||||
import { useRef } from "react";
|
||||
import type { FieldValues, Path, UseFormReturn } from "react-hook-form";
|
||||
import { RolesSelector, type SelectedRole } from "./roles-selector";
|
||||
|
||||
type OrgRolesTagFieldProps<TFieldValues extends FieldValues> = {
|
||||
form: Pick<
|
||||
UseFormReturn<TFieldValues>,
|
||||
"control" | "getValues" | "setValue" | "clearErrors"
|
||||
"control" | "getValues" | "setValue"
|
||||
>;
|
||||
orgId: string;
|
||||
/** Field in the form that holds Tag[] (role tags). Default: `"roles"`. */
|
||||
@@ -40,6 +42,46 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
||||
disabled
|
||||
}: OrgRolesTagFieldProps<TFieldValues>) {
|
||||
const t = useTranslations();
|
||||
const isPopoverOpenRef = useRef(false);
|
||||
const lastValidRolesRef = useRef<SelectedRole[]>(
|
||||
(form.getValues(name) as SelectedRole[]) ?? []
|
||||
);
|
||||
|
||||
function validateRolesSelection() {
|
||||
const current = form.getValues(name) as SelectedRole[];
|
||||
|
||||
if (current.length === 0 && lastValidRolesRef.current.length > 0) {
|
||||
form.setValue(name, lastValidRolesRef.current as never, {
|
||||
shouldDirty: true
|
||||
});
|
||||
toast({
|
||||
variant: "destructive",
|
||||
title: t("accessRoleRequired"),
|
||||
description: t("accessRoleSelectPlease")
|
||||
});
|
||||
return false;
|
||||
}
|
||||
|
||||
if (current.length > 0) {
|
||||
lastValidRolesRef.current = current;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
function handlePopoverOpenChange(open: boolean) {
|
||||
isPopoverOpenRef.current = open;
|
||||
|
||||
if (open) {
|
||||
const current = form.getValues(name) as SelectedRole[];
|
||||
if (current.length > 0) {
|
||||
lastValidRolesRef.current = current;
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
validateRolesSelection();
|
||||
}
|
||||
|
||||
function setRoleTags(nextValue: SelectedRole[]) {
|
||||
const prev = form.getValues(name) as SelectedRole[];
|
||||
@@ -57,14 +99,15 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
||||
form.setValue(name, [prev[prev.length - 1]] as never, {
|
||||
shouldDirty: true
|
||||
});
|
||||
form.clearErrors(name);
|
||||
return;
|
||||
}
|
||||
|
||||
form.setValue(name, next as never, { shouldDirty: true });
|
||||
|
||||
if (next.length > 0) {
|
||||
form.clearErrors(name);
|
||||
if (next.length > 0 && !isPopoverOpenRef.current) {
|
||||
lastValidRolesRef.current = next;
|
||||
} else if (!isPopoverOpenRef.current) {
|
||||
validateRolesSelection();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -74,6 +117,9 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
||||
name={name}
|
||||
render={({ field }) => {
|
||||
const selectedRoles = (field.value ?? []) as SelectedRole[];
|
||||
if (!isPopoverOpenRef.current && selectedRoles.length > 0) {
|
||||
lastValidRolesRef.current = selectedRoles;
|
||||
}
|
||||
|
||||
return (
|
||||
<FormItem className="flex flex-col items-start">
|
||||
@@ -83,6 +129,7 @@ export default function OrgRolesTagField<TFieldValues extends FieldValues>({
|
||||
orgId={orgId}
|
||||
selectedRoles={selectedRoles}
|
||||
onSelectRoles={setRoleTags}
|
||||
onPopoverOpenChange={handlePopoverOpenChange}
|
||||
disabled={disabled}
|
||||
/>
|
||||
</FormControl>
|
||||
|
||||
@@ -56,7 +56,6 @@ type SmartLoginFormProps = {
|
||||
defaultUser?: string;
|
||||
orgSignIn?: OrgSignInConfig;
|
||||
lastUsedIdp?: (LoginFormIDP & { orgId?: string }) | null;
|
||||
inviteMode?: boolean;
|
||||
};
|
||||
|
||||
type ViewState =
|
||||
@@ -94,8 +93,7 @@ export default function SmartLoginForm({
|
||||
forceLogin,
|
||||
defaultUser,
|
||||
orgSignIn,
|
||||
lastUsedIdp,
|
||||
inviteMode = false
|
||||
lastUsedIdp
|
||||
}: SmartLoginFormProps) {
|
||||
const router = useRouter();
|
||||
const { env } = useEnvContext();
|
||||
@@ -138,10 +136,6 @@ export default function SmartLoginForm({
|
||||
return;
|
||||
}
|
||||
|
||||
const signupUrl = redirect
|
||||
? `/auth/signup?email=${encodeURIComponent(identifier)}&redirect=${encodeURIComponent(redirect)}&fromSmartLogin=true`
|
||||
: `/auth/signup?email=${encodeURIComponent(identifier)}&fromSmartLogin=true`;
|
||||
|
||||
if (!result.found || result.accounts.length === 0) {
|
||||
// No accounts found
|
||||
if (!isEmail || forceLogin) {
|
||||
@@ -153,36 +147,13 @@ export default function SmartLoginForm({
|
||||
return;
|
||||
}
|
||||
// Valid email but no accounts and not forceLogin - redirect to signup
|
||||
const signupUrl = redirect
|
||||
? `/auth/signup?email=${encodeURIComponent(identifier)}&redirect=${encodeURIComponent(redirect)}&fromSmartLogin=true`
|
||||
: `/auth/signup?email=${encodeURIComponent(identifier)}&fromSmartLogin=true`;
|
||||
router.push(signupUrl);
|
||||
return;
|
||||
}
|
||||
|
||||
// Invite accept only supports internal (password) accounts
|
||||
if (inviteMode) {
|
||||
const internalAccount = result.accounts.find(
|
||||
(acc) => acc.hasInternalAuth
|
||||
);
|
||||
if (internalAccount) {
|
||||
setViewState({
|
||||
type: "password",
|
||||
identifier,
|
||||
account: internalAccount
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
if (isEmail && !forceLogin) {
|
||||
router.push(signupUrl);
|
||||
return;
|
||||
}
|
||||
|
||||
form.setError("identifier", {
|
||||
type: "manual",
|
||||
message: t("inviteLoginInternalOnly")
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
// Determine which view to show
|
||||
const account = result.accounts[0]; // Use first account for now
|
||||
|
||||
|
||||
@@ -15,14 +15,11 @@ import {
|
||||
} from "@app/components/ui/popover";
|
||||
import { cn } from "@app/lib/cn";
|
||||
import { ListUserOrgsResponse } from "@server/routers/org";
|
||||
import { Check, ChevronDown, Plus } from "lucide-react";
|
||||
import { Check, ChevronDown, ChevronsUpDown } from "lucide-react";
|
||||
import { usePathname, useRouter } from "next/navigation";
|
||||
import { useMemo, useState } from "react";
|
||||
import { useTranslations } from "next-intl";
|
||||
import { Button } from "@app/components/ui/button";
|
||||
import { useEnvContext } from "@app/hooks/useEnvContext";
|
||||
import { useUserContext } from "@app/hooks/useUserContext";
|
||||
import { build } from "@server/build";
|
||||
|
||||
type LauncherOrgSelectorProps = {
|
||||
orgId?: string;
|
||||
@@ -34,16 +31,9 @@ export function LauncherOrgSelector({ orgId, orgs }: LauncherOrgSelectorProps) {
|
||||
const router = useRouter();
|
||||
const pathname = usePathname();
|
||||
const t = useTranslations();
|
||||
const { env } = useEnvContext();
|
||||
const { user } = useUserContext();
|
||||
|
||||
const selectedOrg = orgs?.find((org) => org.orgId === orgId);
|
||||
|
||||
let canCreateOrg = !env.flags.disableUserCreateOrg || user.serverAdmin;
|
||||
if (build === "saas" && user.type !== "internal") {
|
||||
canCreateOrg = false;
|
||||
}
|
||||
|
||||
const sortedOrgs = useMemo(() => {
|
||||
if (!orgs?.length) {
|
||||
return orgs ?? [];
|
||||
@@ -118,22 +108,6 @@ export function LauncherOrgSelector({ orgId, orgs }: LauncherOrgSelectorProps) {
|
||||
</CommandGroup>
|
||||
</CommandList>
|
||||
</Command>
|
||||
{canCreateOrg && (
|
||||
<div className="p-2 border-t border-border">
|
||||
<Button
|
||||
variant="ghost"
|
||||
size="sm"
|
||||
className="w-full justify-start h-8 font-normal text-muted-foreground"
|
||||
onClick={() => {
|
||||
setOpen(false);
|
||||
router.push("/setup");
|
||||
}}
|
||||
>
|
||||
<Plus className="h-3.5 w-3.5 mr-2" />
|
||||
{t("setupNewOrg")}
|
||||
</Button>
|
||||
</div>
|
||||
)}
|
||||
</PopoverContent>
|
||||
</Popover>
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user