Offer administration only on a device marked as your own

A session signed in without "This is my own device" can no longer
administer. The server withholds the account's permissions from it and the
JMAP proxy refuses registry methods beyond the account's own, the same gate
ADMINISTRATION=0 uses. A borrowed or shared machine is where nobody should
be able to reset a password or remove a domain.

An administrator in such a session still sees Administration in the account
menu, greyed out, with the reason and the fix: sign in again with the box
ticked. The server tells that session only that the account administers.

The gate now reads the body only when it could name a registry method --
"x: in the text, or a \u escape that could spell one -- so ordinary mail
traffic from an untrusted session is forwarded untouched.

1 new string, translated in all nine catalogues, quoting each language's own
label for the tickbox; strings falling back to English stay at 16.
This commit is contained in:
2026-09-13 16:34:20 -07:00
parent 93c9660421
commit f1638b2fee
15 changed files with 145 additions and 19 deletions
+1
View File
@@ -103,6 +103,7 @@ export const catalog: Catalog = {
"also {names}": "别名:{names}",
"The server did not say whether the domain was created.": "服务器没有说明域名是否已创建。",
// ── Administration: accounts ───────────────────────────────────
"Only on a device you've marked as your own. Sign in again with \u201cThis is my own device\u201d ticked.": "仅限在您标记为自己设备的设备上使用。请勾选「这是我自己的设备」后重新登录。",
"Change your own password in {settings}.": "请在{settings}中更改您自己的密码。",
"Administration": "管理",
"Directory": "目录",