The family gate (decisions 63/64, R-780): family members with their own logins, a permanent forwardAuth door per family app, anchored exceptions, min_controller
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
- internal/family: the family list (bcrypt, generated 4x4 passwords shown once) + 30-day sessions in family.json (0600, atomic); a reset (generation), a removal or a logout ends sessions at the next request. - internal/stacks/family_gate.go: family_gate / family_gate_except / min_controller in .felhom.yml; the door is written BEFORE the first start (install and a removed app's restore), a life record in app.yaml, reconciled by the gate loop; priority below the install hold, setup gate and sign-up block; every exception anchored ^/prefix(/|$) (finding F1). - internal/web/family_gate.go: forwardAuth /__felhom_gate/family (app cookie felhom_famgate, host-only, names a store session); /__family/start|login|logout on the dashboard host (session cookie felhom_family, Path=/__family); sign-in counted per visitor (clientIP) AND per name, short windows; the household's dashboard session vouches. RequireAuth never reads a family cookie. The "Család" card on the security page: add / new password / remove. Red-proofs RP-F1..RP-F7 (felhom.eu audits/family-gate-2026-10-02/A/). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
{{define "familygate"}}
|
||||
<!DOCTYPE html>
|
||||
<html lang="{{T "layout.html_lang"}}">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<meta name="robots" content="noindex">
|
||||
<title>{{if .AppName}}{{.AppName}} — {{end}}{{T "family_gate.page_title"}}</title>
|
||||
<link rel="stylesheet" href="/static/style.css?v={{.Version}}">
|
||||
</head>
|
||||
<body class="login-body">
|
||||
<div class="login-card">
|
||||
<img src="/static/felhom-logo.svg?v={{.Version}}" alt="Felhom.eu" class="login-logo">
|
||||
{{- if .AppName}}
|
||||
<h1 class="login-title">{{.AppName}}</h1>
|
||||
{{- end}}
|
||||
{{- if .Notice}}
|
||||
<p class="alert alert-info" id="family-gate-notice">{{.Notice}}</p>
|
||||
{{- end}}
|
||||
{{- if .SignedIn}}
|
||||
<p id="family-gate-signed-in">{{T "family_gate.signed_in_note"}}</p>
|
||||
<form method="post" action="/__family/logout">
|
||||
<button type="submit" class="btn btn-outline btn-full">{{T "family_gate.sign_out"}}</button>
|
||||
</form>
|
||||
{{- else}}
|
||||
<p id="family-gate-text">{{T "family_gate.page_body"}}</p>
|
||||
<form method="post" action="/__family/login" class="login-form">
|
||||
<input type="hidden" name="_ft" value="{{.FormToken}}">
|
||||
<input type="hidden" name="rd" value="{{.RD}}">
|
||||
<div class="form-group">
|
||||
<label for="family-name">{{T "family_gate.name"}}</label>
|
||||
<input type="text" id="family-name" name="name" autocomplete="username" autocapitalize="none" required autofocus class="form-control">
|
||||
</div>
|
||||
<div class="form-group">
|
||||
<label for="family-password">{{T "family_gate.password"}}</label>
|
||||
<input type="password" id="family-password" name="password" autocomplete="current-password" required class="form-control">
|
||||
</div>
|
||||
<button type="submit" class="btn btn-primary btn-full">{{T "family_gate.sign_in"}}</button>
|
||||
</form>
|
||||
{{- end}}
|
||||
{{- if .Host}}
|
||||
<p class="login-footer">{{.Host}}</p>
|
||||
{{- end}}
|
||||
<div class="shell-lang">{{template "lang_globe" .}}</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
{{end}}
|
||||
@@ -403,6 +403,65 @@ function openDialog(opts){
|
||||
})();
|
||||
</script>
|
||||
|
||||
<!-- Section: Family (v0.287.0, decisions 63/64) — the family gate's members. Passwords come from the server ONCE,
|
||||
in the answer to the add/reset press; the page never contains one. -->
|
||||
<div class="settings-card" id="family-card">
|
||||
<h3>{{T "family_gate.card_title"}}</h3>
|
||||
<p class="settings-card-desc">{{T "family_gate.card_desc"}}</p>
|
||||
<div id="family-list" class="settings-grid"></div>
|
||||
<p id="family-none" class="form-hint" style="display:none">{{T "family_gate.none"}}</p>
|
||||
<div id="family-pw" class="alert alert-info" style="display:none">
|
||||
{{T "family_gate.pw_once"}} <strong id="family-pw-name"></strong> — <span id="family-pw-value" class="mono"></span>
|
||||
</div>
|
||||
<form id="family-add" class="inline-form" onsubmit="familyAct(event, 'add', document.getElementById('family-new').value)">
|
||||
<input type="text" id="family-new" class="form-control" placeholder="{{T "family_gate.name_placeholder"}}" autocapitalize="none" required>
|
||||
<button type="submit" class="btn btn-sm btn-primary">{{T "family_gate.add"}}</button>
|
||||
</form>
|
||||
<span id="family-err" class="form-hint" style="display:none;color:var(--red)"></span>
|
||||
</div>
|
||||
<script>
|
||||
(function () {
|
||||
var T = {reset: '{{T "family_gate.reset"}}', remove: '{{T "family_gate.remove"}}',
|
||||
cReset: '{{T "family_gate.confirm_reset"}}', cRemove: '{{T "family_gate.confirm_remove"}}', err: '{{T "family_gate.error"}}'};
|
||||
function render(members) {
|
||||
var list = document.getElementById('family-list');
|
||||
list.textContent = '';
|
||||
document.getElementById('family-none').style.display = members.length ? 'none' : '';
|
||||
members.forEach(function (n) {
|
||||
var row = document.createElement('div'); row.className = 'settings-row'; row.setAttribute('data-family-member', n);
|
||||
var label = document.createElement('span'); label.className = 'settings-label mono'; label.textContent = n;
|
||||
var val = document.createElement('span'); val.className = 'settings-value';
|
||||
[['reset', T.reset, T.cReset, 'btn-outline'], ['remove', T.remove, T.cRemove, 'btn-danger']].forEach(function (a) {
|
||||
var b = document.createElement('button'); b.type = 'button'; b.className = 'btn btn-xs ' + a[3]; b.textContent = a[1];
|
||||
b.addEventListener('click', function () { felhomConfirm(b, a[2], function () { familyAct(null, a[0], n); }); });
|
||||
val.appendChild(b);
|
||||
});
|
||||
row.appendChild(label); row.appendChild(val); list.appendChild(row);
|
||||
});
|
||||
}
|
||||
window.familyAct = function (e, action, name) {
|
||||
if (e) e.preventDefault();
|
||||
var err = document.getElementById('family-err'); err.style.display = 'none';
|
||||
var body = new URLSearchParams(); body.set('name', name);
|
||||
fetch('/family/members/' + action, {method: 'POST', credentials: 'same-origin',
|
||||
headers: {'X-CSRF-Token': '{{.CSRFToken}}', 'Content-Type': 'application/x-www-form-urlencoded'}, body: body})
|
||||
.then(function (r) { return r.json(); }).then(function (j) {
|
||||
if (!j.ok) { err.textContent = j.error || T.err; err.style.display = 'inline'; return; }
|
||||
render(j.data.members || []);
|
||||
var box = document.getElementById('family-pw');
|
||||
if (j.data.password) {
|
||||
document.getElementById('family-pw-name').textContent = j.data.name;
|
||||
document.getElementById('family-pw-value').textContent = j.data.password;
|
||||
box.style.display = '';
|
||||
} else { box.style.display = 'none'; }
|
||||
if (action === 'add') document.getElementById('family-new').value = '';
|
||||
}).catch(function () { err.textContent = T.err; err.style.display = 'inline'; });
|
||||
};
|
||||
fetch('/family/members', {credentials: 'same-origin'}).then(function (r) { return r.json(); })
|
||||
.then(function (j) { if (j.ok) render(j.data.members || []); });
|
||||
})();
|
||||
</script>
|
||||
|
||||
<!-- Section: Recovery Info -->
|
||||
{{if .HasRetrievalPassword}}
|
||||
<div class="settings-card">
|
||||
|
||||
Reference in New Issue
Block a user