Files
felhom-controller/controller/internal/web/templates/login.html
T
admin 48f3336956
gates / gates (push) Successful in 23s
v0.254.0 — the saved notes follow the language, and the switch becomes a globe (R-557 slice 2 release C; SLICE 2 CLOSED)
The notes a background run SAVES — last night's backup line, the last error, the proof
result, the restore outcome — are written in the BOX's language at the moment they are
written. A household that switches sees the previous run's note in the old language until
the next run rewrites it: the operator's §16 option 1, stated rather than hidden.
EndRestoreOp no longer receives a Hungarian literal from anywhere.

The language switch is a globe. Two text links wrapped in the sidebar footer and asked the
reader to recognise "Magyar"/"English" as links; a globe is the one symbol every web user
already reads as "language", so nobody has to read Hungarian to escape Hungarian. It is
<details>/<summary> — a menu with no script, drawn inline because the icon sprite lives
only in layout.html and the visitor pages have their own shell.

Those visitor pages get the same globe, and a visitor's choice stays theirs: a display-only
felhom_lang cookie that langFor reads ONLY when there is no session. A signed-in household
can never inherit a language a previous visitor picked in the same browser. POST /lang is
CSRF-exempt for a narrow reason written at the exemption — its only achievable effect is the
language of the page the victim's own browser shows them — and safeBackPath refuses
//evil.example as well as https://, because "starts with /" alone is not the test. §16 taken:
a successful claim carries the cookie into the household's setting.

TWO PARITY EXCEPTIONS, MEASURED: 106 fixtures compared with a real diff — exactly two change
shapes (the dashboard footer, the globe in the shells) and 5 byte-identical, which are the
three pages that must not change.

I INTRODUCED A DEADLOCK AND THE SUITE CAUGHT IT BY HANGING. UpdateOffboxStatus holds the
settings write lock while running its callback; boxLang() wants the read lock; sync.RWMutex
is not reentrant. On a real box an off-site run would have hung forever HOLDING the settings
lock. Fixed by resolving the language before the callback, and guarded by a test that names
the file and line in a second instead of hanging for 25 minutes.

MinAgent: 0.131.0 (unchanged). No hub release needed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-18 14:19:31 +02:00

42 lines
1.8 KiB
HTML

{{define "login"}}
<!DOCTYPE html>
<html lang="{{T "layout.html_lang"}}">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{T "login.bejelentkezes_felhom"}}</title>
<link rel="stylesheet" href="/static/style.css">
</head>
<body class="login-body">
<div class="shell-lang">{{template "lang_globe" .}}</div>
<div class="login-card">
<img src="/static/felhom-logo.svg?v={{.Version}}" alt="Felhom.eu" class="login-logo">
<h1 class="login-title">{{T "login.otthoni"}} <span class="title-accent">{{T "login.vezerlopult"}}</span></h1>
<p class="login-subtitle">{{.CustomerName}}</p>
{{if .Flash}}<div class="alert alert-info">{{.Flash}}</div>{{end}}
{{if .Error}}<div class="alert alert-error">{{.Error}}</div>{{end}}
<form method="POST" action="/login">
<input type="hidden" name="next" id="next-field" value="">
<div class="form-group">
<label for="password">{{T "login.jelszo"}}</label>
<input type="password" id="password" name="password" required autofocus
placeholder="{{T "login.adja_meg_a_jelszavat"}}" class="form-control">
</div>
<button type="submit" class="btn btn-primary btn-full">{{T "login.bejelentkezes"}}</button>
</form>
<p style="text-align:center;margin:0.75rem 0 0;font-size:0.85rem"><a href="/claim">{{T "login.elfelejtett_jelszo"}}</a></p>
<p class="login-footer">{{T "login.felhom_otthoni_szerver_kezeles_felhom"}}</p>
</div>
<script>
(function() {
var params = new URLSearchParams(window.location.search);
var next = params.get('next');
if (next) {
document.getElementById('next-field').value = next;
}
})();
</script>
</body>
</html>
{{end}}