The family gate (decisions 63/64, R-780): family members with their own logins, a permanent forwardAuth door per family app, anchored exceptions, min_controller
gates / gates (push) Successful in 27s
gates / gates (push) Successful in 27s
- internal/family: the family list (bcrypt, generated 4x4 passwords shown once) + 30-day sessions in family.json (0600, atomic); a reset (generation), a removal or a logout ends sessions at the next request. - internal/stacks/family_gate.go: family_gate / family_gate_except / min_controller in .felhom.yml; the door is written BEFORE the first start (install and a removed app's restore), a life record in app.yaml, reconciled by the gate loop; priority below the install hold, setup gate and sign-up block; every exception anchored ^/prefix(/|$) (finding F1). - internal/web/family_gate.go: forwardAuth /__felhom_gate/family (app cookie felhom_famgate, host-only, names a store session); /__family/start|login|logout on the dashboard host (session cookie felhom_family, Path=/__family); sign-in counted per visitor (clientIP) AND per name, short windows; the household's dashboard session vouches. RequireAuth never reads a family cookie. The "Család" card on the security page: add / new password / remove. Red-proofs RP-F1..RP-F7 (felhom.eu audits/family-gate-2026-10-02/A/). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -562,6 +562,64 @@ function openDialog(opts){
|
||||
</script>
|
||||
|
||||
|
||||
<div class="settings-card" id="family-card">
|
||||
<h3>Család</h3>
|
||||
<p class="settings-card-desc">A családtagok a saját nevükkel és jelszavukkal lépnek be a családi kapus alkalmazásokba. Ezzel a vezérlőpultot nem érik el.</p>
|
||||
<div id="family-list" class="settings-grid"></div>
|
||||
<p id="family-none" class="form-hint" style="display:none">Még nincs családtag.</p>
|
||||
<div id="family-pw" class="alert alert-info" style="display:none">
|
||||
A jelszó csak most látszik. Írd fel, vagy add át a családtagnak: <strong id="family-pw-name"></strong> — <span id="family-pw-value" class="mono"></span>
|
||||
</div>
|
||||
<form id="family-add" class="inline-form" onsubmit="familyAct(event, 'add', document.getElementById('family-new').value)">
|
||||
<input type="text" id="family-new" class="form-control" placeholder="pl. anna" autocapitalize="none" required>
|
||||
<button type="submit" class="btn btn-sm btn-primary">Családtag hozzáadása</button>
|
||||
</form>
|
||||
<span id="family-err" class="form-hint" style="display:none;color:var(--red)"></span>
|
||||
</div>
|
||||
<script>
|
||||
(function () {
|
||||
var T = {reset: 'Új jelszó', remove: 'Eltávolítás',
|
||||
cReset: 'Új jelszót adsz? A régi azonnal megszűnik.', cRemove: 'Eltávolítod? A belépései azonnal megszűnnek.', err: 'Nem sikerült. Próbáld újra.'};
|
||||
function render(members) {
|
||||
var list = document.getElementById('family-list');
|
||||
list.textContent = '';
|
||||
document.getElementById('family-none').style.display = members.length ? 'none' : '';
|
||||
members.forEach(function (n) {
|
||||
var row = document.createElement('div'); row.className = 'settings-row'; row.setAttribute('data-family-member', n);
|
||||
var label = document.createElement('span'); label.className = 'settings-label mono'; label.textContent = n;
|
||||
var val = document.createElement('span'); val.className = 'settings-value';
|
||||
[['reset', T.reset, T.cReset, 'btn-outline'], ['remove', T.remove, T.cRemove, 'btn-danger']].forEach(function (a) {
|
||||
var b = document.createElement('button'); b.type = 'button'; b.className = 'btn btn-xs ' + a[3]; b.textContent = a[1];
|
||||
b.addEventListener('click', function () { felhomConfirm(b, a[2], function () { familyAct(null, a[0], n); }); });
|
||||
val.appendChild(b);
|
||||
});
|
||||
row.appendChild(label); row.appendChild(val); list.appendChild(row);
|
||||
});
|
||||
}
|
||||
window.familyAct = function (e, action, name) {
|
||||
if (e) e.preventDefault();
|
||||
var err = document.getElementById('family-err'); err.style.display = 'none';
|
||||
var body = new URLSearchParams(); body.set('name', name);
|
||||
fetch('/family/members/' + action, {method: 'POST', credentials: 'same-origin',
|
||||
headers: {'X-CSRF-Token': 'tok', 'Content-Type': 'application/x-www-form-urlencoded'}, body: body})
|
||||
.then(function (r) { return r.json(); }).then(function (j) {
|
||||
if (!j.ok) { err.textContent = j.error || T.err; err.style.display = 'inline'; return; }
|
||||
render(j.data.members || []);
|
||||
var box = document.getElementById('family-pw');
|
||||
if (j.data.password) {
|
||||
document.getElementById('family-pw-name').textContent = j.data.name;
|
||||
document.getElementById('family-pw-value').textContent = j.data.password;
|
||||
box.style.display = '';
|
||||
} else { box.style.display = 'none'; }
|
||||
if (action === 'add') document.getElementById('family-new').value = '';
|
||||
}).catch(function () { err.textContent = T.err; err.style.display = 'inline'; });
|
||||
};
|
||||
fetch('/family/members', {credentials: 'same-origin'}).then(function (r) { return r.json(); })
|
||||
.then(function (j) { if (j.ok) render(j.data.members || []); });
|
||||
})();
|
||||
</script>
|
||||
|
||||
|
||||
|
||||
<div class="settings-card">
|
||||
<h3>Vészhelyzeti információk</h3>
|
||||
|
||||
Reference in New Issue
Block a user