{{define "recovery"}} {{T "recovery.adatok_visszaszerzese_felhom"}}
{{template "lang_globe" .}}
{{if .Unlocked}}

{{T "recovery.a_menteseid"}} {{T "recovery.elerhetok"}}

{{if .Flash}}
{{.Flash}}
{{end}} {{if .Error}}
{{.Error}}
{{end}} {{if .InvUnavailable}} {{else if .InvEmpty}}
{{T "recovery.a_tarolo_megnyilt_de_nincs"}}
{{else if .InvUntagged}}
{{T "recovery.a_tarolo_megnyilt_es_van"}}
{{else}}

{{T "recovery.ezek_a_te_menteseid_a"}}

{{range .InvApps}} {{end}}
{{T "recovery.alkalmazas"}}{{T "recovery.legutobbi_mentes"}}{{T "recovery.meret"}}
{{.App}} {{fmtTime .LatestAt}} {{if gt .SizeBytes 0}}{{humanBytes .SizeBytes}}{{else}}—{{end}}
{{end}}

{{T "recovery.a_visszaallitas_alkalmazasonkent_torteni"}}

{{T "recovery.tovabb_a_visszaallitashoz"}} {{T "recovery.vissza_a_kezdolapra"}}
{{else}}

{{T "recovery.adatok"}} {{T "recovery.visszaszerzese"}}

{{.CustomerName}}

{{if .Flash}}
{{.Flash}}
{{end}} {{if .Error}}
{{.Error}}
{{end}}

{{T "recovery.ezt_a_gepet_ujratelepitettek_a"}}{{with .SealedAt}}{{T "recovery.amelyet_zartunk_le"}}{{end}}{{T "recovery.a_csomagot_csak_a_te"}}

{{T "recovery.a_helyreallitasi_kodot_senki_nem"}}

{{T "recovery.ha_megadod_a_kodot_feloldjuk"}}

{{.CSRFField}}
{{.CSRFField}}
{{/* R-227 — A RESTART MID-UNLOCK MUST NOT SHOW A RAW ENGLISH GATEWAY ERROR. Measured 2026-08-05 (CAMPAIGN-11 F8): the controller was restarted 0.7 s into an unlock and the customer got traefik's `Bad Gateway` — a raw upstream error, in English, naming no reason and saying nothing about whether the key was installed. The state was clean; only the page was not. It breaches I3 (every refusal names a reason a person can act on, in Hungarian, with no raw error). WHICH LAYER ANSWERS: traefik, and its config IS generated by this repo (internal/infra/templates/traefik*.tmpl). A fully branded proxy error page is therefore possible here — but traefik v3 serves no static files itself, so it would need a new always-up container purely to hold an error page, for every 502 on the box. That is out of proportion to this finding and is scoped in the report rather than built. What ships instead is the second sanctioned option: the unlock posts via fetch, so a gateway error or a dropped connection is caught in the page and answered in Hungarian, without leaving it. PROGRESSIVE ENHANCEMENT — with no JS the plain POST is unchanged, and that path still shows the proxy's own error. Said plainly rather than implied. */}}

{{T "recovery.a_most_nem_csak_azt"}}


{{if .ConfirmSetAside}} {{/* §7.3 / §2.4 — THE COPY CHANGES WITH THE BEHAVIOUR (v0.206.0, R-241). It used to promise "félretesszük — nem töröljük". After this change the set-aside history IS deleted, on a date, together with the sealed package that protects it — which is what lets the question end instead of returning at every login. A confirmation that still said "we do not delete" would be the most consequential false sentence on the whole surface. */}}

{{T "recovery.biztosan_nem_kered_vissza_a"}}

{{T "recovery.ha_megerosited"}}

{{T "recovery.ha_csak_most_nincs_keznel"}}

{{.CSRFField}}
{{T "recovery.megsem"}}
{{else}}

{{T "recovery.ha_a_helyreallitasi_kodod_veglegesen"}} {{if .CanSetAside}} {{T "recovery.nem_kerem_vissza_a_korabbi"}} {{else}} {{T "recovery.ez_a_lehetoseg_akkor_valik"}} {{end}}

{{end}} {{end}}
{{end}}