feat(lock): main-window lock screen; harden env gating, sandbox and ssh teardown
Lock screen (main-window overlay, no second window): - scrypt password verifier in <userData>/lock.json (per-write salt, timingSafeEqual); salt/hash/password never leave the main process - lock now / idle auto-lock / lock at startup, growing failure cooldown, lock flags persisted so a quit-and-relaunch cannot bypass the lock - locked shell and body portals go inert while sessions keep running; menu accelerators (reload, DevTools, zoom) are swallowed while locked - settings gains a Lock tab; all copy in zh-CN/zh-TW/en/ja Security and stability: - packaged builds ignore ELECTRON_RENDERER_URL / OT_UPDATE_URL (devEnv) - renderer preload runs with sandbox: true - unreadable known_hosts store fails closed instead of being overwritten - connect-time secrets gated by the bookmark's auth method (connectPromptFor) - ssh stream teardown is idempotent: PTY_EXIT broadcasts exactly once - sysinfo polling is refcounted for split panes (forceStopPolling on close) - session-log index entries are path-contained; settings store writes atomically with EPERM/EBUSY retry - sync-changelog tolerates CRLF checkouts (was a silent no-op) - retry ssh2 host-key generation (flaky malformed key, ~1/500) Tests: lock-store + lock-controller suites; transport-death PTY_EXIT e2e; GitHub Actions CI (typecheck + 10 offline tests + build)
This commit is contained in:
1 parent
471f8c3e73
commit
35583b2c15
47 files changed
+3058
-105
No files matched your search
@@ -10,6 +10,7 @@ import type {
|
||||
} from './ipc'
|
||||
import type { AppSettings } from './settings'
|
||||
import type { ReleaseNote, UpdateState } from './ipc'
|
||||
import type { LockOperationResult, LockPasswordInput, LockSettingsState } from './ipc'
|
||||
import type {
|
||||
HostKeyAction,
|
||||
HostKeyPromptEvent,
|
||||
@@ -100,6 +101,17 @@ export interface AppApi {
|
||||
saveSettings(next: Partial<AppSettings>): Promise<AppSettings>
|
||||
onSettingsChanged(cb: (s: AppSettings) => void): () => void
|
||||
|
||||
// ---- lock screen (main-window overlay; main owns the lock state) ----
|
||||
getLockState(): Promise<LockSettingsState>
|
||||
/** set or replace the password; verifies currentPassword when one exists */
|
||||
setLockPassword(input: LockPasswordInput): Promise<LockOperationResult>
|
||||
/** remove the password; verifies currentPassword when one exists */
|
||||
clearLockPassword(input: { currentPassword?: string }): Promise<LockOperationResult>
|
||||
/** answer the lock screen; resets the failure cooldown on success */
|
||||
unlockLock(input: { password?: string }): Promise<LockOperationResult>
|
||||
lockNow(): Promise<LockSettingsState>
|
||||
onLockStateChanged(cb: (state: LockSettingsState) => void): () => void
|
||||
|
||||
// ---- fonts ----
|
||||
listFonts(): Promise<string[]>
|
||||
|
||||
|
||||
@@ -67,6 +67,28 @@ export interface SshSecretOverride {
|
||||
passphrase?: string
|
||||
}
|
||||
|
||||
/** The secret kind a connection must prompt for before connecting. */
|
||||
export type ConnectPromptKind = 'password' | 'passphrase'
|
||||
|
||||
/**
|
||||
* Which secret dialog (if any) a connect attempt for `conn` must show first.
|
||||
*
|
||||
* Single source of truth for Workspace's `handleConnectRequest` and
|
||||
* ConnectFlow's stage selection: both used to derive it independently and the
|
||||
* renderer-only check on ConnectFlow's side ignored `auth`, so a key-auth
|
||||
* bookmark with a stale `askPasswordAtConnect` flag (left over from an edit
|
||||
* that switched auth methods) popped a password dialog.
|
||||
*
|
||||
* Each ask* flag only counts for the auth method it belongs to; `null` means
|
||||
* saved credentials exist and the connection must start immediately (existing
|
||||
* UX — such connections must never route through the secret prompt).
|
||||
*/
|
||||
export function connectPromptFor(conn: SshConnection): ConnectPromptKind | null {
|
||||
if (conn.auth === 'password' && conn.askPasswordAtConnect) return 'password'
|
||||
if (conn.auth === 'privateKey' && conn.askPassphraseAtConnect) return 'passphrase'
|
||||
return null
|
||||
}
|
||||
|
||||
export interface SessionOpenOptions {
|
||||
kind: 'local' | 'ssh'
|
||||
/** ssh only */
|
||||
|
||||
@@ -17,6 +17,7 @@ const main: Record<string, string> = {
|
||||
|
||||
'main.ssh.connectTimeout': 'Connection timed out ({host}:{port})',
|
||||
'main.ssh.saveFingerprintFailed': 'Failed to save the host fingerprint: {detail}',
|
||||
'main.ssh.knownHostsUnreadable': 'The known-hosts file (ssh_known_hosts.json) exists but could not be read. The connection was refused to protect the pinned fingerprints. Repair or delete the file and try again.',
|
||||
'main.ssh.hostKeyRejected': 'The user rejected the host key',
|
||||
'main.ssh.connectFailed': 'Connection failed {host}:{port}: {detail}',
|
||||
'main.ssh.shellOpenFailed': 'Could not open the SSH shell ({host}:{port}): {detail}',
|
||||
|
||||
@@ -7,6 +7,7 @@ const settings: Record<string, string> = {
|
||||
'settings.tabs.highlight': 'Highlighting',
|
||||
'settings.tabs.theme': 'Themes',
|
||||
'settings.tabs.system': 'System',
|
||||
'settings.tabs.lock': 'Lock',
|
||||
'settings.tabs.about': 'About',
|
||||
'settings.resizeHandle': 'Drag to resize',
|
||||
'settings.preview': 'Preview',
|
||||
@@ -100,6 +101,52 @@ const settings: Record<string, string> = {
|
||||
'settings.system.shortcutPlaceholder': 'Click and press a shortcut, leave empty to disable',
|
||||
'settings.system.shortcutConflict':
|
||||
'This shortcut is already used by the app (Ctrl+= / Ctrl+- / Ctrl+0 / Ctrl+PgUp / Ctrl+PgDn). Please choose another.',
|
||||
'settings.lock.password.title': 'Lock password',
|
||||
'settings.lock.password.desc': 'A password is required before the lock can be enabled',
|
||||
'settings.lock.password.configured': 'Set',
|
||||
'settings.lock.password.notConfigured': 'Not set',
|
||||
'settings.lock.password.current': 'Current password',
|
||||
'settings.lock.password.currentPlaceholder': 'Enter the current password',
|
||||
'settings.lock.password.new': 'New password',
|
||||
'settings.lock.password.newPlaceholder': 'Enter a new password',
|
||||
'settings.lock.password.confirm': 'Confirm new password',
|
||||
'settings.lock.password.confirmPlaceholder': 'Repeat the new password',
|
||||
'settings.lock.password.set': 'Set password',
|
||||
'settings.lock.password.change': 'Change password',
|
||||
'settings.lock.password.clear': 'Remove password',
|
||||
'settings.lock.password.clearTitle': 'Remove the lock password?',
|
||||
'settings.lock.password.clearDesc':
|
||||
'The lock is turned off along with it. The current password is required to confirm.',
|
||||
'settings.lock.password.mismatch': 'The two new passwords do not match',
|
||||
'settings.lock.password.empty': 'Enter a password',
|
||||
'settings.lock.password.saved': 'Password saved',
|
||||
'settings.lock.password.cleared': 'Lock password removed',
|
||||
'settings.lock.password.forgot':
|
||||
'A forgotten lock password cannot be recovered from any cloud or backdoor: the only way back in is deleting this machine\u2019s lock data and setting a new one.',
|
||||
'settings.lock.enabled': 'Enable lock',
|
||||
'settings.lock.enabledDesc':
|
||||
'Lock the main window when idle or at startup; unlocking needs the password above',
|
||||
'settings.lock.needPassword': 'Set a lock password first',
|
||||
'settings.lock.autoLock': 'Lock when idle',
|
||||
'settings.lock.autoLockDesc': 'Lock once the system has been idle this long (0 = never)',
|
||||
'settings.lock.autoLockOff': 'Off',
|
||||
'settings.lock.autoLockMinutes': '{n} min',
|
||||
'settings.lock.lockAtStartup': 'Lock at startup',
|
||||
'settings.lock.lockAtStartupDesc': 'Ask for the password right after every launch',
|
||||
'settings.lock.lockNow': 'Lock now',
|
||||
'settings.lock.lockNowDesc': 'Lock the main window immediately (sessions keep running)',
|
||||
'settings.lock.title': 'Locked',
|
||||
'settings.lock.screenDesc': 'Enter the lock password to unlock',
|
||||
'settings.lock.passwordPlaceholder': 'Password',
|
||||
'settings.lock.unlock': 'Unlock',
|
||||
'settings.lock.unlocking': 'Unlocking…',
|
||||
'settings.lock.screenForgot':
|
||||
'Forgot it? The lock password cannot be recovered \u2014 the only way out is deleting this machine\u2019s lock data.',
|
||||
'settings.lock.error.invalidPassword': 'Password is invalid (empty or too short)',
|
||||
'settings.lock.error.wrongPassword': 'Wrong password',
|
||||
'settings.lock.error.cooldown': 'Too many attempts \u2014 try again in {n}s',
|
||||
'settings.lock.error.cooldownGeneric': 'Too many attempts \u2014 try again later',
|
||||
'settings.lock.error.saveFailed': 'Save failed, please retry',
|
||||
'settings.resetTerminal': 'Reset terminal settings',
|
||||
'settings.resetTerminalTitle': 'Reset terminal settings?',
|
||||
'settings.resetTerminalDesc': 'All terminal settings — font, cursor, rendering and theme — will be restored to defaults.',
|
||||
|
||||
@@ -17,6 +17,7 @@ const main: Record<string, string> = {
|
||||
|
||||
'main.ssh.connectTimeout': '接続がタイムアウトしました ({host}:{port})',
|
||||
'main.ssh.saveFingerprintFailed': 'ホスト鍵のフィンガープリントを保存できませんでした: {detail}',
|
||||
'main.ssh.knownHostsUnreadable': '既知ホストファイル (ssh_known_hosts.json) が存在しますが読み取れないため、保存済みフィンガープリントを保護するために接続を拒否しました。ファイルを修復または削除してから再試行してください。',
|
||||
'main.ssh.hostKeyRejected': 'ユーザーがホスト鍵を拒否しました',
|
||||
'main.ssh.connectFailed': '接続に失敗しました {host}:{port}: {detail}',
|
||||
'main.ssh.shellOpenFailed': 'SSH シェルを開けません ({host}:{port}): {detail}',
|
||||
|
||||
@@ -7,6 +7,7 @@ const settings: Record<string, string> = {
|
||||
'settings.tabs.highlight': 'ハイライト',
|
||||
'settings.tabs.theme': 'テーマ',
|
||||
'settings.tabs.system': 'システム',
|
||||
'settings.tabs.lock': 'ロック',
|
||||
'settings.tabs.about': 'このアプリについて',
|
||||
'settings.resizeHandle': 'ドラッグしてサイズ変更',
|
||||
'settings.preview': 'プレビュー',
|
||||
@@ -97,6 +98,52 @@ const settings: Record<string, string> = {
|
||||
'settings.system.shortcutPlaceholder': 'クリックしてショートカットを押す。空欄で無効',
|
||||
'settings.system.shortcutConflict':
|
||||
'このショートカットはアプリ内で既に使用されています(Ctrl+= / Ctrl+- / Ctrl+0 / Ctrl+PgUp / Ctrl+PgDn)。別のものを選んでください。',
|
||||
'settings.lock.password.title': 'ロックパスワード',
|
||||
'settings.lock.password.desc': 'パスワードを設定するとロックを有効にできます',
|
||||
'settings.lock.password.configured': '設定済み',
|
||||
'settings.lock.password.notConfigured': '未設定',
|
||||
'settings.lock.password.current': '現在のパスワード',
|
||||
'settings.lock.password.currentPlaceholder': '現在のパスワードを入力',
|
||||
'settings.lock.password.new': '新しいパスワード',
|
||||
'settings.lock.password.newPlaceholder': '新しいパスワードを入力',
|
||||
'settings.lock.password.confirm': '新しいパスワード(確認)',
|
||||
'settings.lock.password.confirmPlaceholder': 'もう一度入力してください',
|
||||
'settings.lock.password.set': 'パスワードを設定',
|
||||
'settings.lock.password.change': 'パスワードを変更',
|
||||
'settings.lock.password.clear': 'パスワードを削除',
|
||||
'settings.lock.password.clearTitle': 'ロックパスワードを削除しますか?',
|
||||
'settings.lock.password.clearDesc':
|
||||
'削除するとロックも無効になります。確認のため現在のパスワードが必要です。',
|
||||
'settings.lock.password.mismatch': '新しいパスワードが一致しません',
|
||||
'settings.lock.password.empty': 'パスワードを入力してください',
|
||||
'settings.lock.password.saved': 'パスワードを保存しました',
|
||||
'settings.lock.password.cleared': 'ロックパスワードを削除しました',
|
||||
'settings.lock.password.forgot':
|
||||
'パスワードを忘れてもクラウドから復元する方法はなく、回避手段もありません。本機のロックデータを削除して設定し直すしかありません。',
|
||||
'settings.lock.enabled': 'ロックを有効にする',
|
||||
'settings.lock.enabledDesc':
|
||||
'アイドル時と起動時にメインウィンドウをロックします。解除には上のパスワードが必要です',
|
||||
'settings.lock.needPassword': '先にロックパスワードを設定してください',
|
||||
'settings.lock.autoLock': 'アイドル時に自動ロック',
|
||||
'settings.lock.autoLockDesc': 'システムがこの時間アイドル状態になったらロックします(0 は無効)',
|
||||
'settings.lock.autoLockOff': '無効',
|
||||
'settings.lock.autoLockMinutes': '{n} 分',
|
||||
'settings.lock.lockAtStartup': '起動時にロック',
|
||||
'settings.lock.lockAtStartupDesc': '起動直後にパスワードの入力を求めます',
|
||||
'settings.lock.lockNow': '今すぐロック',
|
||||
'settings.lock.lockNowDesc': 'メインウィンドウをすぐにロックします(セッションは動作を続けます)',
|
||||
'settings.lock.title': 'ロック中',
|
||||
'settings.lock.screenDesc': 'ロックパスワードを入力して解除します',
|
||||
'settings.lock.passwordPlaceholder': 'パスワード',
|
||||
'settings.lock.unlock': '解除',
|
||||
'settings.lock.unlocking': '解除中…',
|
||||
'settings.lock.screenForgot':
|
||||
'パスワードを忘れた場合、復元する方法はありません。本機のロックデータを削除するしかありません。',
|
||||
'settings.lock.error.invalidPassword': 'パスワードが無効です(空または短すぎます)',
|
||||
'settings.lock.error.wrongPassword': 'パスワードが違います',
|
||||
'settings.lock.error.cooldown': '試行回数が多すぎます。{n} 秒後にもう一度お試しください',
|
||||
'settings.lock.error.cooldownGeneric': '試行回数が多すぎます。しばらくしてからお試しください',
|
||||
'settings.lock.error.saveFailed': '保存に失敗しました。もう一度お試しください',
|
||||
'settings.resetTerminal': 'ターミナル設定をリセット',
|
||||
'settings.resetTerminalTitle': 'ターミナル設定をリセットしますか?',
|
||||
'settings.resetTerminalDesc': 'フォント、カーソル、レンダリング、テーマなどすべてのターミナル設定がデフォルトに戻ります。',
|
||||
|
||||
@@ -17,6 +17,7 @@ const main: Record<string, string> = {
|
||||
|
||||
'main.ssh.connectTimeout': '连接超时 ({host}:{port})',
|
||||
'main.ssh.saveFingerprintFailed': '保存主机指纹失败: {detail}',
|
||||
'main.ssh.knownHostsUnreadable': '已知主机文件 (ssh_known_hosts.json) 存在但无法读取,为避免覆盖已保存的指纹,本次连接被拒绝。请修复或删除该文件后重试。',
|
||||
'main.ssh.hostKeyRejected': '用户拒绝了主机指纹',
|
||||
'main.ssh.connectFailed': '连接失败 {host}:{port}: {detail}',
|
||||
'main.ssh.shellOpenFailed': '无法打开 SSH shell ({host}:{port}): {detail}',
|
||||
|
||||
@@ -7,6 +7,7 @@ const settings: Record<string, string> = {
|
||||
'settings.tabs.highlight': '高亮',
|
||||
'settings.tabs.theme': '主题',
|
||||
'settings.tabs.system': '系统',
|
||||
'settings.tabs.lock': '锁屏',
|
||||
'settings.tabs.about': '关于',
|
||||
'settings.resizeHandle': '拖拽调整大小',
|
||||
'settings.preview': '预览',
|
||||
@@ -94,6 +95,49 @@ const settings: Record<string, string> = {
|
||||
'settings.system.shortcutPlaceholder': '点击后按下快捷键,留空禁用',
|
||||
'settings.system.shortcutConflict':
|
||||
'该组合键已被应用内快捷键占用(Ctrl+= / Ctrl+- / Ctrl+0 / Ctrl+PgUp / Ctrl+PgDn),请换一个。',
|
||||
'settings.lock.password.title': '锁屏密码',
|
||||
'settings.lock.password.desc': '设置密码后才能启用锁屏',
|
||||
'settings.lock.password.configured': '已配置',
|
||||
'settings.lock.password.notConfigured': '未配置',
|
||||
'settings.lock.password.current': '当前密码',
|
||||
'settings.lock.password.currentPlaceholder': '请输入当前密码',
|
||||
'settings.lock.password.new': '新密码',
|
||||
'settings.lock.password.newPlaceholder': '请输入新密码',
|
||||
'settings.lock.password.confirm': '确认新密码',
|
||||
'settings.lock.password.confirmPlaceholder': '再次输入新密码',
|
||||
'settings.lock.password.set': '设置密码',
|
||||
'settings.lock.password.change': '修改密码',
|
||||
'settings.lock.password.clear': '清除密码',
|
||||
'settings.lock.password.clearTitle': '清除锁屏密码?',
|
||||
'settings.lock.password.clearDesc': '清除后锁屏会一并关闭,需要当前密码确认。',
|
||||
'settings.lock.password.mismatch': '两次输入的新密码不一致',
|
||||
'settings.lock.password.empty': '请填写密码',
|
||||
'settings.lock.password.saved': '密码已保存',
|
||||
'settings.lock.password.cleared': '锁屏密码已清除',
|
||||
'settings.lock.password.forgot':
|
||||
'忘记锁屏密码无法通过云端找回,也没有后门:只能删除本机锁屏数据后重新设置。',
|
||||
'settings.lock.enabled': '启用锁屏',
|
||||
'settings.lock.enabledDesc': '闲置或启动时锁定主窗口,解锁需要上面的密码',
|
||||
'settings.lock.needPassword': '请先设置锁屏密码',
|
||||
'settings.lock.autoLock': '闲置自动锁屏',
|
||||
'settings.lock.autoLockDesc': '系统闲置超过该时长后自动锁定(0 表示从不)',
|
||||
'settings.lock.autoLockOff': '关闭',
|
||||
'settings.lock.autoLockMinutes': '{n} 分钟',
|
||||
'settings.lock.lockAtStartup': '启动时锁屏',
|
||||
'settings.lock.lockAtStartupDesc': '每次启动后先要求输入密码',
|
||||
'settings.lock.lockNow': '立即锁屏',
|
||||
'settings.lock.lockNowDesc': '马上锁定主窗口(会话保持运行)',
|
||||
'settings.lock.title': '已锁定',
|
||||
'settings.lock.screenDesc': '输入锁屏密码解锁',
|
||||
'settings.lock.passwordPlaceholder': '密码',
|
||||
'settings.lock.unlock': '解锁',
|
||||
'settings.lock.unlocking': '解锁中…',
|
||||
'settings.lock.screenForgot': '忘记密码?锁屏密码无法找回,只能删除本机锁屏数据。',
|
||||
'settings.lock.error.invalidPassword': '密码无效(不能为空或过短)',
|
||||
'settings.lock.error.wrongPassword': '密码错误',
|
||||
'settings.lock.error.cooldown': '尝试次数过多,请等待 {n} 秒后重试',
|
||||
'settings.lock.error.cooldownGeneric': '尝试次数过多,请稍后再试',
|
||||
'settings.lock.error.saveFailed': '保存失败,请重试',
|
||||
'settings.resetTerminal': '恢复默认终端设置',
|
||||
'settings.resetTerminalTitle': '恢复默认终端设置?',
|
||||
'settings.resetTerminalDesc': '字体、光标、渲染与主题等全部终端设置将恢复为默认值。',
|
||||
|
||||
@@ -17,6 +17,7 @@ const main: Record<string, string> = {
|
||||
|
||||
'main.ssh.connectTimeout': '連線逾時 ({host}:{port})',
|
||||
'main.ssh.saveFingerprintFailed': '儲存主機指紋失敗: {detail}',
|
||||
'main.ssh.knownHostsUnreadable': '已知主機檔案 (ssh_known_hosts.json) 存在但無法讀取,為避免覆寫已儲存的指紋,本次連線被拒絕。請修復或刪除該檔案後重試。',
|
||||
'main.ssh.hostKeyRejected': '使用者拒絕了主機指紋',
|
||||
'main.ssh.connectFailed': '連線失敗 {host}:{port}: {detail}',
|
||||
'main.ssh.shellOpenFailed': '無法開啟 SSH shell ({host}:{port}): {detail}',
|
||||
|
||||
@@ -7,6 +7,7 @@ const settings: Record<string, string> = {
|
||||
'settings.tabs.highlight': '高亮',
|
||||
'settings.tabs.theme': '主題',
|
||||
'settings.tabs.system': '系統',
|
||||
'settings.tabs.lock': '鎖定畫面',
|
||||
'settings.tabs.about': '關於',
|
||||
'settings.resizeHandle': '拖曳調整大小',
|
||||
'settings.preview': '預覽',
|
||||
@@ -94,6 +95,49 @@ const settings: Record<string, string> = {
|
||||
'settings.system.shortcutPlaceholder': '點擊後按下快速鍵,留空為停用',
|
||||
'settings.system.shortcutConflict':
|
||||
'此組合鍵已被應用內快捷鍵佔用(Ctrl+= / Ctrl+- / Ctrl+0 / Ctrl+PgUp / Ctrl+PgDn),請換一個。',
|
||||
'settings.lock.password.title': '鎖定密碼',
|
||||
'settings.lock.password.desc': '設定密碼後才能啟用鎖定',
|
||||
'settings.lock.password.configured': '已設定',
|
||||
'settings.lock.password.notConfigured': '未設定',
|
||||
'settings.lock.password.current': '目前密碼',
|
||||
'settings.lock.password.currentPlaceholder': '請輸入目前密碼',
|
||||
'settings.lock.password.new': '新密碼',
|
||||
'settings.lock.password.newPlaceholder': '請輸入新密碼',
|
||||
'settings.lock.password.confirm': '確認新密碼',
|
||||
'settings.lock.password.confirmPlaceholder': '再次輸入新密碼',
|
||||
'settings.lock.password.set': '設定密碼',
|
||||
'settings.lock.password.change': '變更密碼',
|
||||
'settings.lock.password.clear': '清除密碼',
|
||||
'settings.lock.password.clearTitle': '清除鎖定密碼?',
|
||||
'settings.lock.password.clearDesc': '清除後鎖定會一併關閉,需要目前密碼確認。',
|
||||
'settings.lock.password.mismatch': '兩次輸入的新密碼不一致',
|
||||
'settings.lock.password.empty': '請填寫密碼',
|
||||
'settings.lock.password.saved': '密碼已儲存',
|
||||
'settings.lock.password.cleared': '鎖定密碼已清除',
|
||||
'settings.lock.password.forgot':
|
||||
'忘記鎖定密碼無法透過雲端找回,也沒有後門:只能刪除本機鎖定資料後重新設定。',
|
||||
'settings.lock.enabled': '啟用鎖定',
|
||||
'settings.lock.enabledDesc': '閒置或啟動時鎖定主視窗,解鎖需要上面的密碼',
|
||||
'settings.lock.needPassword': '請先設定鎖定密碼',
|
||||
'settings.lock.autoLock': '閒置自動鎖定',
|
||||
'settings.lock.autoLockDesc': '系統閒置超過該時間後自動鎖定(0 表示從不)',
|
||||
'settings.lock.autoLockOff': '關閉',
|
||||
'settings.lock.autoLockMinutes': '{n} 分鐘',
|
||||
'settings.lock.lockAtStartup': '啟動時鎖定',
|
||||
'settings.lock.lockAtStartupDesc': '每次啟動後先要求輸入密碼',
|
||||
'settings.lock.lockNow': '立即鎖定',
|
||||
'settings.lock.lockNowDesc': '馬上鎖定主視窗(工作階段保持運作)',
|
||||
'settings.lock.title': '已鎖定',
|
||||
'settings.lock.screenDesc': '輸入鎖定密碼以解鎖',
|
||||
'settings.lock.passwordPlaceholder': '密碼',
|
||||
'settings.lock.unlock': '解鎖',
|
||||
'settings.lock.unlocking': '解鎖中…',
|
||||
'settings.lock.screenForgot': '忘記密碼?鎖定密碼無法找回,只能刪除本機鎖定資料。',
|
||||
'settings.lock.error.invalidPassword': '密碼無效(不能為空或過短)',
|
||||
'settings.lock.error.wrongPassword': '密碼錯誤',
|
||||
'settings.lock.error.cooldown': '嘗試次數過多,請等待 {n} 秒後重試',
|
||||
'settings.lock.error.cooldownGeneric': '嘗試次數過多,請稍後再試',
|
||||
'settings.lock.error.saveFailed': '儲存失敗,請重試',
|
||||
'settings.resetTerminal': '恢復預設終端設定',
|
||||
'settings.resetTerminalTitle': '恢復預設終端設定?',
|
||||
'settings.resetTerminalDesc': '字體、游標、渲染與主題等全部終端設定將恢復為預設值。',
|
||||
|
||||
+52
-1
@@ -110,9 +110,60 @@ export const Ipc = {
|
||||
/** normalize a cwd reported by the shell (OSC 7 / OSC 9;9) */
|
||||
CWD_REPORT: 'session:cwdReport',
|
||||
/** open a local directory in the OS file manager (terminal toolbar) */
|
||||
CWD_OPEN: 'session:cwdOpen'
|
||||
CWD_OPEN: 'session:cwdOpen',
|
||||
|
||||
// ---- lock screen (main-window overlay; the main process owns the state) ----
|
||||
/** renderer pulls the current lock state without changing it */
|
||||
LOCK_STATE_GET: 'lock:stateGet',
|
||||
/** set or replace the password; an existing one must be verified first */
|
||||
LOCK_SET_PASSWORD: 'lock:setPassword',
|
||||
/** remove the password; the existing one must be verified first */
|
||||
LOCK_CLEAR_PASSWORD: 'lock:clearPassword',
|
||||
LOCK_UNLOCK: 'lock:unlock',
|
||||
LOCK_NOW: 'lock:now',
|
||||
/** main -> renderer broadcast: LockSettingsState */
|
||||
LOCK_STATE_CHANGED: 'lock:state'
|
||||
} as const
|
||||
|
||||
/**
|
||||
* The lock state the renderer sees. Deliberately free of salt, hash and
|
||||
* password: the stored verifier never leaves the main process.
|
||||
*/
|
||||
export interface LockSettingsState {
|
||||
/** a password is set, so the lock can engage at all */
|
||||
configured: boolean
|
||||
enabled: boolean
|
||||
autoLockMinutes: number
|
||||
lockAtStartup: boolean
|
||||
locked: boolean
|
||||
/** remaining lockout in ms; absent while no cooldown is running */
|
||||
cooldownMs?: number
|
||||
}
|
||||
|
||||
/** Passwords travel one way only: in. Neither field is ever echoed back. */
|
||||
export interface LockPasswordInput {
|
||||
/** required when a password is already set (replace / clear) */
|
||||
currentPassword?: string
|
||||
/** required when setting or replacing */
|
||||
newPassword?: string
|
||||
}
|
||||
|
||||
export type LockOperationError =
|
||||
/** the offered new password is unusable (empty, too short, too long) */
|
||||
| 'invalid-password'
|
||||
/** the offered current password does not match */
|
||||
| 'wrong-password'
|
||||
/** too many failed attempts: retry after state.cooldownMs */
|
||||
| 'cooldown'
|
||||
/** the verifier could not be written to disk */
|
||||
| 'save-failed'
|
||||
|
||||
export interface LockOperationResult {
|
||||
ok: boolean
|
||||
state: LockSettingsState
|
||||
error?: LockOperationError
|
||||
}
|
||||
|
||||
export interface PtyCreateOptions {
|
||||
cwd?: string
|
||||
/** executable; omit for platform default shell */
|
||||
|
||||
+41
-1
@@ -125,6 +125,41 @@ export function highlightModeOf(value: unknown): HighlightMode {
|
||||
return value === 'basic' || value === 'off' ? value : 'all'
|
||||
}
|
||||
|
||||
/**
|
||||
* The delays offered for the idle auto-lock, in minutes. A closed set rather
|
||||
* than a free number: `0` means "never", and the settings UI, the sanitizer and
|
||||
* the idle watcher all read this one list so they cannot disagree.
|
||||
*/
|
||||
export type LockAutoDelay = 0 | 1 | 5 | 15 | 30 | 60
|
||||
|
||||
export const LOCK_AUTO_DELAYS: LockAutoDelay[] = [0, 1, 5, 15, 30, 60]
|
||||
|
||||
/**
|
||||
* Read a stored auto-lock delay, tolerating a hand-edited settings.json: only a
|
||||
* whitelisted value survives, anything else falls back to 0 (never).
|
||||
*/
|
||||
export function lockAutoDelayOf(value: unknown): LockAutoDelay {
|
||||
return LOCK_AUTO_DELAYS.includes(value as LockAutoDelay) ? (value as LockAutoDelay) : 0
|
||||
}
|
||||
|
||||
export function isLockAutoDelay(value: unknown): value is LockAutoDelay {
|
||||
return LOCK_AUTO_DELAYS.includes(value as LockAutoDelay)
|
||||
}
|
||||
|
||||
/**
|
||||
* Screen-lock preferences. The password itself is never stored here — the
|
||||
* verifier lives in `<userData>/lock.json` (src/main/lockStore.ts), so settings
|
||||
* can be copied around, synced or logged without leaking it.
|
||||
*/
|
||||
export interface LockSettings {
|
||||
/** master switch: without it nothing ever locks, idle watcher included */
|
||||
enabled: boolean
|
||||
/** minutes of system idle before the screen locks; 0 = never */
|
||||
autoLockMinutes: LockAutoDelay
|
||||
/** start each run locked (asks for the password before the app is usable) */
|
||||
lockAtStartup: boolean
|
||||
}
|
||||
|
||||
export interface SystemSettings {
|
||||
/** register the app to launch at OS login */
|
||||
launchAtLogin: boolean
|
||||
@@ -171,6 +206,8 @@ export interface AppSettings {
|
||||
/** named rule subsets for per-host highlighting (see terminal.highlightPerHost) */
|
||||
highlightProfiles: HighlightProfile[]
|
||||
system: SystemSettings
|
||||
/** screen lock; the password verifier lives outside settings (lock.json) */
|
||||
lock: LockSettings
|
||||
}
|
||||
|
||||
const RULE = (
|
||||
@@ -429,5 +466,8 @@ export const DEFAULT_SETTINGS: AppSettings = {
|
||||
customThemes: [],
|
||||
highlightRules: DEFAULT_HIGHLIGHT_RULES,
|
||||
highlightProfiles: [],
|
||||
system: { launchAtLogin: false, preventSleep: false, globalShowHide: '', closeAction: 'tray', autoCheckUpdate: true, restoreSession: true, shellIntegration: false, language: 'zh-CN' }
|
||||
system: { launchAtLogin: false, preventSleep: false, globalShowHide: '', closeAction: 'tray', autoCheckUpdate: true, restoreSession: true, shellIntegration: false, language: 'zh-CN' },
|
||||
// Off until the user sets a password and turns it on: an app that locks
|
||||
// itself out of the box would be a support ticket, not a feature.
|
||||
lock: { enabled: false, autoLockMinutes: 0, lockAtStartup: false }
|
||||
}
|
||||
Reference in new issue
Block a user