Add Tenants to Administration, and let an account be put in one

A tenant is a separate organisation on one server: its own people,
domains and limits, and an administrator who manages only what is in it.
It gets a section under Access, gated by sysTenantQuery and sysTenantGet,
with a notice on a server that does not report Enterprise, where anyone
inside a tenant is held to an ordinary user's permissions.

The panel edits the tenant's name, logo, role and limits. The logo is an
https address, drawn through the image proxy the strict image policy
requires, or an image data URL. Limits change one quotas/<name> pointer
each, so the four ihasmail does not offer keep their values, and an empty
field is no limit. The role is the most anyone inside can be allowed.

Stalwart keeps no list on a tenant -- each account, group, domain, list and
role names its own -- so what a tenant holds is counted with memberTenantId
queries and shown against its limits. Domains are added and taken out from
the tenant's panel, one memberTenantId change each; only a domain in no
tenant can be added, and its accounts stay where they are. Delete is offered
once every count reads zero.

A tenant does nothing until someone administers it, so the account panel
gains a Tenant choice for an administrator who can read tenants: an
Administrator inside a tenant administers that tenant. Nobody moves their
own account.

The mock has a tenant holding a domain and an administrator, a spare domain
to assign, memberTenantId filters on every query, and Stalwart's rule that
only an administrator outside every tenant may move things into one. A test
of taking a domain back out found that the mock's pointer handling dropped a
top-level null instead of storing it, so nothing had ever been cleared that
way; it stores null now, as the server reads it back.

Nothing about tenants has been written on a live server: production has
none. KNOWN-ISSUES says what was read from source.

Thirty-nine new strings and one plural, in all nine catalogues.
This commit is contained in:
2026-09-15 09:28:39 -07:00
parent 7e46ddeb7d
commit fd104a1f34
29 changed files with 1467 additions and 25 deletions
+40
View File
@@ -250,6 +250,45 @@ export const catalog: Catalog = {
"This role no longer exists. Someone may have deleted it.": "このロールはもう存在しません。誰かが削除した可能性があります。",
"the default roles": "既定のロール設定",
"The server did not say whether the role was created.": "ロールが作成されたかどうか、サーバーから返答がありませんでした。",
"No tenant": "テナントなし",
"You can't move your own account into a tenant.": "自分のアカウントをテナントに移すことはできません。",
"An account in a tenant is limited by the tenant's role and counts towards its limits, and Administrator means administrator of that tenant.": "テナント内のアカウントは、テナントのロールによって制限され、テナントの上限に数えられます。また、管理者はそのテナントの管理者を意味します。",
"Tenants": "テナント",
"Storage in GB": "ストレージ (GB)",
"Default tenant roles": "テナントの既定ロール",
"A tenant needs a name.": "テナントには名前が必要です。",
"New tenant": "新しいテナント",
"{used} used": "{used} 使用中",
"Your role lets you view tenants but not change them.": "あなたのロールでは、テナントの閲覧はできますが変更はできません。",
"Logo": "ロゴ",
"An https address or a data URL of an image. Stalwart shows it to the tenant's people where it shows a logo.": "https のアドレス、または画像の data URL です。Stalwart はロゴを表示する場所で、テナントの利用者に表示します。",
"What it holds": "含まれるもの",
"{n} of {limit}": "{limit} 件中 {n} 件",
"Limits": "上限",
"Stalwart refuses to create more than a limit allows. An empty field is no limit.": "Stalwart は上限を超える作成を拒否します。空欄は上限なしです。",
"The most anyone in this tenant can be allowed: their own roles are cut down to what these grant. Only roles whose permissions you hold yourself are offered.": "このテナント内の誰にでも許可できる最大の範囲です。各自のロールは、これらが付与する範囲に絞られます。表示されるのは、あなた自身が権限を持つロールだけです。",
"Checking what is still in this tenant…": "このテナントに残っているものを確認しています…",
"It still holds accounts, domains or other things. Move them out first.": "まだアカウント、ドメインなどが含まれています。先に移動してください。",
"Create tenant": "テナントを作成",
"Added {domain} to {tenant}": "{domain} を {tenant} に追加しました",
"Took {domain} out of {tenant}": "{domain} を {tenant} から外しました",
"Take {domain} out of the tenant": "{domain} をテナントから外す",
"No domains in this tenant yet": "このテナントにはまだドメインがありません",
"Domain to add": "追加するドメイン",
"Only domains in no tenant can be added. The accounts already on a domain stay where they are; move each from its own panel.": "追加できるのは、どのテナントにも属していないドメインだけです。ドメイン上の既存のアカウントはそのまま残るため、それぞれのパネルから移動してください。",
"An empty tenant can be deleted.": "空のテナントは削除できます。",
"Delete tenant…": "テナントを削除…",
"Still holds {things}. Move them out first.": "まだ {things} が含まれています。先に移動してください。",
"Delete tenant": "テナントを削除",
"Separate organisations on one server, each with its own people, domains and limits.": "1 台のサーバー上の別々の組織で、それぞれに利用者、ドメイン、上限があります。",
"Tenants are a Stalwart Enterprise feature. This server does not report Enterprise, so anyone inside a tenant has only an ordinary user's permissions.": "テナントは Stalwart Enterprise の機能です。このサーバーは Enterprise と報告していないため、テナント内の利用者は通常のユーザーの権限しか持ちません。",
"Search tenants": "テナントを検索",
"No tenants match": "一致するテナントはありません",
"No tenants yet": "まだテナントがありません",
"Account limit": "アカウント上限",
"The server allows no more tenants.": "サーバーはこれ以上のテナントを許可していません。",
"This tenant no longer exists. Someone may have deleted it.": "このテナントはもう存在しません。誰かが削除した可能性があります。",
"The server did not say whether the tenant was created.": "テナントが作成されたかどうか、サーバーから返答がありませんでした。",
"User": "ユーザー",
"Administrator": "管理者",
"Custom role": "カスタムロール",
@@ -1657,6 +1696,7 @@ export const catalog: Catalog = {
"{n} recipients": { other: "{n} 件の受信者" },
"Grants {n} permissions": { other: "{n} 件の権限を付与" },
"{n} roles": { other: "{n} 件のロール" },
"{n} tenants": { other: "{n} 件のテナント" },
"{n} DKIM keys": { other: "{n} 個の DKIM 鍵" },
"{n} other items": { other: "その他 {n} 件" },
// ── Administration ────────────────────────────────────────────────