mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-09 06:59:08 +02:00
* [client] Gate settings updates on value, not on field presence
The update-settings kill switch (--disable-update-settings /
NB_DISABLE_UPDATE_SETTINGS / the MDM DisableUpdateSettings key) forbids
changing settings, but it decided what a "change" was by looking at
whether a field was present in the request. The CLI fills the whole
config surface of SetConfigRequest and LoginRequest from its flags and
environment on every `netbird up` (setupSetConfigReq in cmd/up.go), so a
client configured by environment restates its own configuration on every
start and tripped the gate every time.
SetConfig only warned about that, but Login carries the same fields and
was gated the same way, and Login runs inside the CLI's backoff loop: the
daemon answered every attempt with codes.Unavailable, `netbird up` never
completed, and a container with NB_DISABLE_UPDATE_SETTINGS plus any
config env var (NB_MANAGEMENT_URL, for one) could not come up at all.
Both gates now compare values. Config.WouldChange is the dry-run half of
UpdateConfig: it runs the very same diff logic (Config.apply) against a
copy of the stored config, so the gate cannot drift from what an actual
update would do, nor go stale when a field is added. A request that
restates what the profile already holds changes nothing and is allowed; a
request that diverges is refused exactly as before, and a dry run that
cannot be evaluated fails closed. A profile with no config on disk yet is
judged against the config the daemon would create for it.
For Login, the compared input comes from loginOverridesInput, which
persistLoginOverrides also uses to perform the write, so the gate judges
precisely the two fields a login can persist (management URL, pre-shared
key) and no field it ignores.
Two adjacent defects surfaced while making the comparison exact:
- Config.apply compared URLs as raw strings, so the same endpoint spelled
without its default port ("https://api.netbird.io" vs
"https://api.netbird.io:443") counted as a new value and rewrote the
config. It now compares the parsed forms.
- UpdateConfig did not collapse the redacted pre-shared key, unlike
UpdateOrCreateConfig and DirectUpdateConfig, so a UI round-trip of the
mask replaced the stored key with asterisks.
The CLI warning for a refused SetConfig said the method was not available
in the daemon, which sent people looking for a version mismatch that was
not there; it now reports the refusal.
* [client] Do not write the profile config while only reading it to decide
The update-settings gate needs the stored config to decide whether a request
changes anything, so the previous commit moved that read ahead of the refusal.
The read is not side-effect free: profilemanager.GetConfig writes the config
back whenever apply() has to fill in a default the file was missing. A request
that the gate then refuses had therefore already rewritten the profile file.
PeekConfig is GetConfig without that write-back. The returned config is still
normalized in memory, which is what the decision needs; the file is left
exactly as it was found. Every caller of storedConfigAtPath feeds a gate that
can refuse, so they all peek.
Note for reviewers: the daemon still normalizes the file on startup and on
every real update, so nothing depends on a read performing that write.
* [client] Compare service URLs as endpoints, not as strings
Three places in one request path each had their own notion of "same
management URL": the config layer compared the parsed URLs as strings, the
privileged-change gate compared scheme + host + effective port, and the MDM
conflict check compared strings after filling in the default port. Only the
middle one was right.
A string comparison answers the wrong question. "https://api.netbird.io",
"https://api.netbird.io/" and "https://API.netbird.io:443" are one endpoint
written three ways, so a client restating its own management URL with a
trailing slash — a normal way to write it — was still read as a client asking
to be repointed, and the update-settings gate refused it. The MDM check had
the same flaw against the enforced value.
profilemanager.SameServiceURL is now the single comparison: same scheme, same
host case-insensitively as DNS names are, same effective port. The config
layer, the privileged-change gate and the MDM conflict check all defer to it,
so there is one answer to "did this URL change?" instead of three.
* [client] Stop the config dry run from generating throwaway keys
The dry run's baseline for a profile with no config file yet went through
createNewConfig, and apply() generates a WireGuard and an SSH key whenever it
finds those fields empty. The baseline is compared against and discarded, so
every evaluation minted a keypair it threw away — and logged "generated new
Wireguard key". The CLI retries Login in a backoff loop, so a first `netbird up`
on a fresh profile filled the daemon log with what reads like peer-key rotation.
The baseline now starts from the shared skeleton with placeholder keys, so
apply() has nothing to generate. No ConfigInput field maps to either key, so
the comparison is unaffected.
* [client] Cover the login the update-settings gate used to refuse
The gate's decision procedure was tested directly, but no test drove the Login
RPC that the refusal actually broke: the CLI retries Login in a backoff loop,
so a refused no-op login is what kept a client configured by environment from
ever coming up. The handler-level coverage stopped at the refusal case, which
passes on the pre-fix code too.
This test fails on the pre-fix daemon with "update settings are disabled" and
passes now. Past the gate the handler does real work the test does not stand
up, so it asserts only that the refusal did not happen.
* [client] Re-take the update-settings decision under the config lock
Login checks twice on purpose: the first check refuses the ordinary case
early, and authorizeAndPrepareLogin re-takes the authoritative one under
guardedConfigMu because the first is unsynchronized against a concurrent
privileged request. The update-settings decision is now equally
value-dependent — it compares the request against the stored config — but it
was taken only in the first, unlocked check.
So a login that was a no-op when it was checked could be written after a
concurrent writer had repointed the profile, which is exactly the window the
lock exists to close. The decision is now re-taken alongside the privilege one,
which also makes it the last read before persistLoginOverrides writes.
The test drives that interleaving through the existing afterLoginPreCheck seam
and fails without the re-check.
* [client] Drop an unreachable guard and fix two stale comments
- loginOverridesInput's nil-message guard cannot be reached: Login
dereferences the message well before it, in storedLoginConfig.
- The docstring above afterLoginPreCheck described persistLoginOverrides,
which lives further down the file and now carries its own.
- UpdateConfig's comment named DirectUpdateConfig; the function is
DirectUpdateOrCreateConfig.
* [client] Make config reads pure and provision the identity explicitly
Reading a config wrote it back. profilemanager.readConfig persisted whatever
apply() had filled in, and ReadConfig created and wrote the file outright when
it was absent, so every reader was quietly a writer: a gate deciding whether to
refuse a request, a UI listing profiles, a mobile getter reading one preference.
The previous commit worked around that with a PeekConfig variant, which left
two read functions with opposite side effects and the antipattern still there
for everyone else.
Only one thing in a read genuinely had to be persisted: apply() generated the
WireGuard and SSH keys when it found them empty, and a generated key cannot be
recomputed — losing it means the peer comes back with a different identity and
registers again. Everything else apply() fills in is a deterministic default
that the next read recomputes anyway.
So identity provisioning is now its own step, Config.EnsureIdentity, and the
callers that provision write the result out themselves, in the open:
- Server.getConfig, the daemon's provisioning point;
- the CLI's foreground login, which is about to dial management;
- update() / directUpdate(), the config write paths — a stored profile can
legitimately carry no identity, since a mobile logout clears the keys in
place, and the next write is what has to mint a new one.
ReadConfig and GetConfig no longer write anything, PeekConfig is gone, and the
dry-run baseline no longer needs placeholder keys to keep apply() from minting
real ones.
One deliberate leftover: readConfig still calls util.EnforcePermission, which
chmods a config file whose permissions are too broad. It changes no content and
is idempotent, and dropping it would leave a legacy file world-readable until
its first write.
* [client] Name the two config readers for what they do
ReadConfig and GetConfig differed in one thing — what happens when the file is
absent — and neither name said which was which:
- ReadConfig -> ReadOrGenerateConfig (reads it, or generates one in memory)
- GetConfig -> GetExistingConfig (reads it, or fails)
Three comments went with them:
- GetConfig's said "return with Config and if it was created. Errors out if it
does not exist", which described a bool it does not return and a creation it
never performs.
- ReadConfig's explained that it does not write, which is what a reader is
supposed to do anyway.
- Server.getConfig's said it "errors out if it does not exist", which it does
not — it resolves a default config, and now provisions the identity too.
* [client] Do not panic on a config with no sync message version
apply() wrote the incoming sync message version through the stored pointer,
without checking it was there: a config that carries no version yet made it
dereference nil. Reachable from the update-settings dry run, which runs inside
a request handler — where failing closed is the worst acceptable outcome, and a
panic is not one.
The field is now reassigned like every other optional one, which also means
apply() no longer mutates anything the caller still holds through a pointer, so
the dry run's copy has one less field to detach.
Reported by cubic-dev-ai on PR #7398.
* [client] Compare the client certificate paths before reporting a change
apply() assigned the incoming mTLS certificate and key paths and set updated
unconditionally, without comparing them to what the config already held. It is
the same presence-instead-of-value mistake this branch set out to fix, one
layer down: a caller restating its own certificate paths was reported as
changing them, which trips the value-aware update-settings gate.
Reported by cubic-dev-ai on PR #7398.
* [client] Address the remaining bot findings on PR #7398
- Login logged the active-profile-state error and returned the same cause; the
repo's guidelines call for one or the other, and the wrapped error is the one
that carries context. (CodeRabbit)
- `netbird up` reported a codes.Unavailable SetConfig failure as "the daemon
refused the settings update", but that code also covers a daemon that became
unreachable. It now reports what the daemon said without asserting why.
(cubic-dev-ai)
- TestLogin_ChangingTheManagementURLIsRefused asserted the error and nothing
else, while "refused before it can touch daemon state" is the contract. It now
checks the stored management URL, the in-progress login and the active profile,
matching its SetConfig counterpart. (cubic-dev-ai)
* [client] Keep the peer identity out of a read that finds no file
ReadOrGenerateConfig resolves a default config when the profile has no file
yet, and createNewConfig was minting the WireGuard and SSH keys while doing so.
That defeated the provisioning pair it was meant to serve: the CLI's foreground
login calls EnsureIdentity to find out whether it has to persist the keys, got
generated == false because the read had already generated them, and so never
wrote them out. The login then dialed management with an identity that only
existed in memory, and the next login registered a second peer.
createNewConfig no longer provisions. createProvisionedConfig is the variant
that does, and the callers whose contract is "usable as it comes back" use it:
CreateInMemoryConfig, whose callers connect with the result, and the two
create-and-write branches. A read gets a config with no identity, so the
caller's own EnsureIdentity reports the work and triggers the write.
Reported by CodeRabbit and cubic-dev-ai on PR #7398, both on the same defect.
* [client] Stop the gate test from dialing the real management server
TestLogin_RestatingTheStoredConfigPassesTheGate asserts that the gate lets a
no-op login through, and the handler then went on to do the login for real:
isLoginRequired builds an auth client when isLoginRequiredFn is unset, so the
test dialed the profile's management URL — api.netbird.io:443. It took 1.05s
locally and would hang on a runner with no egress, for a fact about the gate
that needs no network at all.
Stubbed like the login_outcome tests do. The test now runs in 0.00s.
Reported by cubic-dev-ai on PR #7398.
* [client] Keep the admin panel path part of its identity
The endpoint comparison introduced for the management URL was applied to the
admin URL too, and that one is opened in a browser rather than dialed over
gRPC: a panel served under /netbird is not the panel served at the root. So a
config whose admin URL differed only by path reported no change, and the new
path was never persisted — a custom panel URL could not be updated at all.
SameServiceURLIncludingPath adds what a URL carries past its endpoint (path,
query, fragment, userinfo) while still treating equivalent spellings as equal:
a missing path and "/" are the same root, and so is a trailing slash. The
management URL keeps the endpoint-only comparison, since only the endpoint is
ever dialed.
Ports are also normalized numerically now, so ":0443" and ":443" are one port.
Reported by cubic-dev-ai on PR #7398 (two findings).
* [client] Treat a profile with no identity as already deregistered
Two findings on the same consequence of pure reads: a profile can legitimately
carry no keys, because logging out clears them in place.
- sendLogoutRequestWithConfig went straight to wgtypes.ParseKey and failed with
"incorrect key size: 0" on the second logout of the same profile. There is
nothing to deregister for a peer that was never registered, so it returns
cleanly. Before pure reads this case was hidden: the read minted a key and
the daemon dialed management with one it had never seen.
- The mobile logout read the config with the generating reader right after
checking the file exists. The two are not atomic, so a profile removed in
between was resolved from the defaults and recreated by the write that
follows. It uses the existing-file reader now.
Reported by cubic-dev-ai and CodeRabbit on PR #7398.
* [client] Fail `netbird up` when the daemon refuses the settings update
With the update-settings kill switch on, `netbird up --enable-rosenpass`
connected and said almost nothing: SetConfig refused the change, the CLI
downgraded that to a warning, and Login carries no rosenpass field to apply, so
the flag was silently dropped. The setting stayed disabled, which is the point
of the switch, but the caller was never told their request had been ignored.
The refusal now travels as codes.FailedPrecondition instead of
codes.Unavailable, and the CLI fails on it. Unavailable means "the daemon
cannot serve this call", which is why the CLI downgraded it and why
client/ui/services reads it as an unreachable daemon — both wrong for a daemon
that answered and refused. FailedPrecondition also matches what the MDM gate
already returns for a managed field, so both refusals are now one class of
error, and it is added to the login backoff's early-exit codes so a refused
login stops instead of retrying for 30s.
This does not put the container back in the deadlock: with the value-aware
gate, a client restating its own configuration is not refused at all, so
nothing reaches this path unless a real change was asked for.
* [client] Name the reader storedConfigAtPath actually calls
The purity note still said profilemanager.GetConfig, which the rename two
commits later turned into GetExistingConfig.
Reported by cubic-dev-ai on PR #7398.
* [client] Restore the gofmt alignment of the error constants
The comment added above errUpdateSettingsDisabled in the previous commit split
the const block's alignment group, so gofmt wants the two constants above it
re-aligned. CI runs gofmt, so this would have failed the lint job.
* [client] Let an unprivileged caller log out a profile with no identity
The empty-key check sat behind requirePrivilegeForDeregistration, so an
unprivileged logout of an identity-less profile was refused with
PermissionDenied instead of completing as the no-op it is. And it was refused
for most profiles, not a corner case: the gate arms whenever the SSH server is
enabled, and sshServerEnabled reads an absent ServerSSHAllowed as enabled, so
every legacy profile qualifies.
The check now runs first. What the gate protects against is handing this
machine's registered key to another management server; with no key there is
nothing to hand over and nothing to protect.
Reported by CodeRabbit and cubic-dev-ai on PR #7398, both on the same defect.
* [client] Stop `netbird login` from retrying a refusal for 30 seconds
`netbird up` and `netbird login` both run Login through the backoff cycle, and
each carried its own copy of the list of codes that end it. Only up.go learned
about codes.FailedPrecondition, so a refused `netbird login` kept retrying and
then reported "login backoff cycle failed" instead of what the daemon said.
terminalLoginError is now that list, once, next to WithBackOff — the duplicated
copies are what let the two commands disagree in the first place.
Reported by cubic-dev-ai on PR #7398.
* [client] Answer terminalLoginError's nil case on its own terms
A successful Login reaches terminalLoginError with a nil error, and nothing
covered that. It happens to work on grpc v1.80.0 — gstatus.FromError(nil)
answers (nil, true), and Status.Code tolerates a nil receiver by returning
codes.OK, which is not in the terminal set — but that is a chain of internal
details to be relying on for the common path, and none of it was asserted.
Now the nil error is handled where it is obvious, and the table covers it.
Reported by CodeRabbit on PR #7398, which called it a panic; measured on
v1.80.0 it is not one. The gap was the untested reliance, not a crash.
* [client] Treat an unset optional field as its default when diffing a config
Seven Config fields mean "the effective default" when they hold no value:
the five SSH toggles, the SSH JWT cache TTL, and the network monitor. Every
consumer already reads a nil as that default, but apply() diffed them by
presence — `config.X == nil || *input.X != *config.X` — so an input restating
the default counted as a change.
That made the update-settings gate refuse `netbird up` outright. The CLI
sends every flag whose value came from an environment variable
(SetFlagsFromEnvVars goes through pflag's FlagSet.Set, which marks the flag
Changed), and the config a plain login writes leaves all seven unset, so a
container configured with, say, NB_ENABLE_SSH_ROOT=false restated a default
the file held as null on every start and was answered with
FailedPrecondition.
apply() now resolves the seven up front, the way it already did for
ServerSSHAllowed and RemoteJobsAllowed, which also repairs such a profile on
its next write. With the values named, the comparisons below diff values
instead of presence, so their nil branches are gone.
The network monitor keeps its platform default — on for windows and darwin —
and naming it as false elsewhere is what createEngineConfig already read a
nil to be. getJWTCacheTTL reaches the same 0 through its own default, and
Android's GetEnableSSH* getters already answered nil with false.
* [client] Normalize the config before diffing it in WouldChange
apply() reports two different things through one bool: an input that changed
a value, and a field it had to fill in because the config carried none. The
update-settings gate reads that bool as "the caller asked for a change", so
any config still missing a default answered a request that asks for nothing
with a refusal.
Readers already hand out normalized configs — readConfig applies an empty
input for exactly this reason — which is why the gate got away with it. But a
handler that refuses a request must not depend on where its caller obtained
the config, and it must not start reading "this profile predates a field" as
"the caller asked for a change" the day someone adds one with a default.
WouldChange now runs the filling-in as a pass of its own and discards its
verdict, so the pass that answers the caller measures only what the input
did.
* [client] Stop the last config write that skipped normalization
Every path that creates or updates a profile config goes through apply(),
which resolves an optional field to its default — except RenameProfile,
which read the file with a bare json.Unmarshal, set the name, and wrote it
straight back. That copied whatever the file held, so a config written by a
client that stored these fields as null kept them null. It could not
introduce a null, only carry one forward, but renaming a profile is a poor
place to leave a half-resolved config behind. It now reads through
GetExistingConfig, which normalizes what it hands out.
The tests state the invariant the fix completes, over the *bool fields of
Config listed by reflection so a field added later is covered without
touching them: none may come out of apply() unset, and no write may store
one as null. An optional bool that can be nil, true or false forces every
reader to invent the meaning of nil, and makes a diff of the config compare
presence rather than value — which is exactly what refused `netbird up` for
a client restating its own defaults.
SyncMessageVersion stays a genuine three-state field and is not covered: it
is an *int whose absence means the client pins no version, and it travels to
management that way.
* [client] Refuse a serialized config that carries no peer identity
ConfigFromJSON still promised a "fully initialized" config after this PR
moved key generation out of apply() into EnsureIdentity, but identity stopped
being one of the defaults it applies. Its two callers both connect with what
they get back: the iOS SDK's Client.SetConfigFromJSON keeps it as the
preloaded config Run() uses on tvOS, and Auth.SetConfigFromJSON as the config
it authenticates with.
No caller feeds it a document without keys today — every stored document
comes from Auth.GetConfigJSON, whose config is provisioned by
DirectUpdateOrCreateConfig or CreateInMemoryConfig, and the tvOS app only
ever edits fields of a document it already has. This is a safety net for the
next caller, not a live bug.
Provisioning the identity here would be the wrong net. Neither caller can
hand a generated key back to the store the document came from — Client
exports no config at all — so the peer would connect under an identity
nothing persists and register anew on every launch, which is the failure the
EnsureIdentity split exists to prevent. A document with no identity means
nobody has logged in yet, and saying so is the only useful answer.
Both keys are required because both are dead ends when missing: an empty
WireGuard key fails the management login on its size, and an empty SSH key
fails ssh.GeneratePublicKey in ConnectClient before the engine starts.
* [client] Say that the null-on-disk fixture is synthesized, not written
The test comment described the null state in the present tense — "the config
a plain login writes leaves every one of them unset" — which was true before
this branch and is not any more: apply() now resolves those fields, so a
login writes them set. unsetOnDisk puts the null state back deliberately, to
stand in for a profile an older client wrote. Comments only.
* [client] Gather the optional-field defaults into one function
Resolving an unset optional field was spread over five places: the two
values newConfigSkeleton pre-sets, the block this branch added for the SSH
toggles, the network monitor's own if, the `else if` tails of
ServerSSHAllowed and RemoteJobsAllowed, and a trailing if for
DisableNotifications several hundred lines further down. Reading apply() left
no single answer to "what does this field default to, and who decides".
They now live in Config.resolveUnsetDefaults, which apply() calls before it
compares anything — the ordering being the point, since it is what lets
every comparison below diff values instead of presence. The comparisons for
ServerSSHAllowed, RemoteJobsAllowed and DisableNotifications lose their
`config.X == nil ||` clauses accordingly, as the other six already had.
newConfigSkeleton keeps its two, and that is the one asymmetry worth naming:
ServerSSHAllowed defaults to false for a new profile and to true for a
legacy one, and it only works because the skeleton runs first. The doc
comment says so, where before it was implied by the order of two distant
blocks.
Pure refactor. Verified as one: for the four fields whose branches moved,
plus two that did not and the JWT TTL, all 63 combinations of stored value
(nil/false/true) against input value (absent/false/true) produce byte-
identical resolved values and `updated` verdicts before and after.
* [client] Resolve the merge conflicts left in the tree
262ce8c3b landed with the conflict markers still in it, so client/server and
the iOS SDK did not compile. Four regions, resolved as follows.
client/server/mdm.go — main moved the MDM conflict-check machinery into the
mdm package (mdm.ResolveConflicts, mdm.ConflictBool, mdm.ConflictURL, ...).
This branch had edited the local copies, which are now dead: dropped, along
with the profilemanager import that only the local conflictURL needed.
client/server/server.go, Login gate — this branch's value-aware gate stays
(the point of the PR: refuse a real divergence, let a restatement through),
so main's presence-based `loginRequestHasConfigOverrides` block goes; that
helper no longer exists here anyway. Main's other change in the same lines
is real and kept: the MDM policy now comes from the daemon-owned
s.mdmLoader.Load() instead of the package-level loadMDMPolicy, which main
removed. The stale call right below the conflict was the reason the file
would not have compiled even with the markers gone.
client/server/server.go, getConfig — both sides add something and both are
needed. The identity is provisioned and persisted first, then the MDM
overlay is applied, so what reaches disk stays the profile's own config: the
overlay is runtime-only and re-derived on every load.
client/ios/NetBirdSDK/client.go — main reworked SetConfigFromJSON to store
the JSON and re-parse it on each load, which is the shape kept; the parse is
now only a validity check, and this branch's reason for it (a document with
no peer identity is refused, not just an unparseable one) moves into that
comment.
client/server/update_settings_gate_test.go — follows the sentinel constant
to its new home, mdm.PreSharedKeyRedactedSentinel.
* [client] Reuse util's service-URL comparison instead of a second copy
The endpoint-comparison rules this branch introduced now live in util (PR
#7472 moved them there so the MDM conflict check could stop comparing URLs
as strings). Keeping a copy here is what produced that bug in the first
place: two implementations of "is this the same endpoint?" drift, and the
one that drifts starts refusing a URL that addresses the very server it
already points at.
So SameServiceURL delegates the port normalization to util.ServiceURLPort
and drops the local one, and SameServiceURLIncludingPath — endpoint plus
path, for the admin panel URL, which is opened rather than dialed — is
util.SameServiceURL plus the query, fragment and userinfo it adds on top,
so the local path normalization goes too.
What stays here is the distinction util does not make: SameServiceURL is
endpoint-only, because a management URL is dialed and only its host and port
are, while util.SameServiceURL includes the path.
Pure refactor. Verified as one: all 198 pairs of a 14-spelling matrix
(default and zero-padded ports, host case, trailing slash, path, query,
fragment, userinfo, both schemes, nil operands) answer identically for both
functions before and after.
* [client] Give a newly added profile its identity (review item 1)
AddProfile writes the config it builds straight to disk, but built it with
createNewConfig, which stopped generating the peer's keys when identity
generation moved out of apply() into EnsureIdentity. The profile file landed
with an empty PrivateKey and SSHKey.
Nothing lost the keys permanently — the daemon's own getConfig provisions and
persists them on first use — but every reader that does not write got a
config that cannot connect in the meantime, which is exactly the set this
branch grew: the update-settings gate deciding whether to refuse a request,
and the mobile SDKs loading a stored profile.
createProvisionedConfig exists for callers that persist or connect, and this
is one; before the split, createNewConfig produced the keys here too.
* [client] Let a logged-out profile deserialize again (review item 2)
ConfigFromJSON refused a document with no WireGuard or SSH key. A config
legitimately has none between a logout and the next login: mobile
LogoutProfile clears both in place and writes the profile back, so the peer
re-registers on the next login instead of returning as itself.
So the refusal broke the mobile flows it was meant to protect. On iOS and
tvOS the stored JSON of a logged-out profile stopped loading through
Client.SetConfigFromJSON and Auth.SetConfigFromJSON, and copyConfig — which
round-trips a Config through JSON to take an in-memory copy before applying
the MDM overlay — failed on the same document. Where the old code silently
minted a key, this returned an error, which is worse for logout and profile
switching alike: neither is asking to connect.
The deserializer now stays out of the identity question in both directions:
it does not generate one (a read cannot hand back keys nothing will write
down) and does not refuse one that is absent. Whoever goes on to connect is
where an absent identity has to be answered — and it already is, by the
login path that provisions and persists.
ErrConfigWithoutIdentity goes with it; nothing else used it.
* [client] Fold the scheme case here too, like util does (review item 6)
profilemanager.SameServiceURL compared the scheme with ==, util.SameServiceURL
with EqualFold. No observable difference — net/url lowercases the scheme when
it parses, and both functions take parsed URLs — but two functions of the same
name with two different rules is a trap for whoever reads one and assumes the
other.
* [client] Classify the daemon's refusals in the GUI (review item 3)
FailedPrecondition reached the classifier unmatched, so a refusal showed as
"Operation failed". It is the code both of the daemon's deliberate refusals
carry: the update-settings kill switch, and a field an MDM policy manages.
Both are now named — settings_locked and settings_managed_by_mdm, matched on
the message the daemon composes — and FailedPrecondition itself falls back to
change_refused, so a refusal the daemon grows later still reads as a refusal
rather than a failure.
Only the English strings are added. Bundle.Translate falls back to the
default language for a missing key, so other locales show English until the
usual translation pass, rather than the bare "error.<code>" the classifier
would otherwise surface.
Note: the package needs GTK4/WebKit to build, which this machine has not, so
the test is type-checked (go vet, GOOS=windows) but was not executed locally;
CI's Linux job runs it.
* [client] Cover the mobile profile round trip: create, logout, reload
Both mobile regressions this branch's review turned up lived on the same
path, and neither was visible from the desktop client: a profile created
without an identity, and a logged-out profile that would no longer
deserialize. The desktop never meets the second one — it is mobile logout
that clears the peer's keys in place, so the next login registers a new peer
instead of bringing the old one back.
The test walks a profile through the round its user puts it through —
created, logged out, loaded again, switched away from and back — and loads it
at each step the way the SDKs do: read the stored config, serialize it, load
it back. That is Client.SetConfigFromJSON storing the document for tvOS,
Auth.SetConfigFromJSON authenticating with it, and copyConfig taking an
in-memory copy before the MDM overlay.
Verified to fail on each regression separately: restoring the bare
constructor in AddProfile fails it with "a new profile was written with no
identity", and restoring the identity check in ConfigFromJSON fails it at
"load the profile back".
client/mobile already had the coverage for the first one in
TestLogoutProfile_DisableProfiles — which arrived from main with the MDM
work, and which I had not been running.
* [client] Name only the refusals, not every FailedPrecondition
The classifier gained a blanket FailedPrecondition -> change_refused fallback
so a refusal would stop reading as "Operation failed". It reaches too far:
the daemon returns that code for two dozen states that are not settings
refusals — "not logged in", "client is not running", "another capture is
already running", "session can no longer be extended, log in again to
reconnect" — and errorClassifier is shared with the session and connection
services, not just the settings save.
So the user was told the service had refused their change while what they
actually had to do was log in again. The two refusals the daemon composes
stay named by their message; everything else goes back to the generic
message, which says nothing rather than something wrong.
Reported by cubic on the PR.
* [client] Say what each assertion was checking in the mobile test
AGENTS.md asks for a context message on comparison and boolean assertions,
and four of the ones added with this test had none, so a failure would have
read as a bare Empty/Equal with no hint of which step of the round trip broke.
Reported by cubic on the PR.
* [client] Translate the two new error strings into every locale
The GUI classifier gained error.settings_locked and
error.settings_managed_by_mdm, and only the English strings were added: the
bundle falls back to the default language for a missing key, so nothing would
have shown a bare "error.<code>" to a user.
CI disagrees, and it is right to: check-translations.mjs requires every
locale to carry the full English key set, so English-only fails the gate
rather than degrading quietly.
The ten locales now carry both strings. These are my translations, not a
localization pass — worth a second pass by whoever owns the language, in
particular for the phrasing of "an administrator has locked them".
The uk file also loses two lines of stray 8-space indentation, normalized by
rewriting the file; no key or value changed with it.
* [client] Persist the profile before overlaying MDM on it (review item)
`netbird login` read the config, applied the MDM policy on top, and only then
provisioned the identity and wrote the result out. On a profile with no
identity yet — a first login — that write persisted the enforced values into
the user's own config file: an MDM-managed management URL or pre-shared key
became indistinguishable from one the user set, and stayed behind once the
policy was withdrawn.
Provisioning and its write now come first, and the overlay is applied to the
in-memory config afterwards, where it belongs: it is re-derived on every load
and never meant to reach disk from here. Server.getConfig already orders the
two this way; the two paths now agree.
Reported by cubic on the PR.
* [client] Assert against the stored config, not a resolved default (review item)
The login-gate test read the profile back with ReadOrGenerateConfig, which
resolves a default config in memory when the file is missing — and that
default's management URL is the very value the assertion checks. An erased or
mislocated profile would have passed the test instead of failing it.
The file is written by the test itself, so GetExistingConfig is the right
reader: it errors when the file is gone.
Reported by cubic on the PR.
* [client] Keep the mTLS pair off the gate's dry run (review item)
WouldChange runs the real apply() against a throwaway copy, and apply() loads
the client mTLS certificate and key from disk whenever the config names them.
So every gated SetConfig and Login read the pair — twice per request, once for
the normalization pass and once for the verdict — including requests that were
about to be refused or that changed nothing, and logged an error per request
when the files were missing. The gate used to be presence-based and never
called apply(), so this was new work on a request path.
The loaded pair feeds the connection and never the comparison: nothing in
apply() reads it back, and it does not move the `updated` verdict. A config
built only to be compared against now says so, and apply() skips the load for
it.
Reported by cubic on the PR.
* Makes it explicit that RenameProfile does write on disk
* [client] Provision the peer identity under the config lock (review item)
Login took the authoritative update-settings and privilege decisions under
guardedConfigMu, then released it and called getConfig, which mints the peer's
identity and writes the config out. Between that read and that write, a
SetConfig holding the same lock could land a change and answer its caller —
and then be overwritten by the config the login had already read.
The window is narrow: getConfig only writes when the profile has no identity
or no file, so in practice a first login racing a settings change on the same
profile. It is also narrower than before this branch, where the write happened
inside the reader on every read that filled in a default.
Provisioning now runs where the decision it belongs to runs: at the end of
authorizeAndPrepareLogin, with the lock already held, next to
persistLoginOverrides, which writes there too. No lock is taken that was not
held before, so the documented guardedConfigMu-then-mutex order is untouched.
getConfig keeps its behaviour by calling the same extracted helper; on the
login path it now finds the identity already there and writes nothing. The
other callers are unchanged, and still provision outside any lock — a
concurrent SetConfig is not part of their flow.
Reported by cubic on the PR.
* [client] Declare the probe marker to the debug-bundle field check
TestAddConfig_AllFieldsCovered walks Config by reflection and fails until every
field is either rendered in the debug bundle or listed as excluded with a
reason. The probe marker added for the gate's dry run was neither, so the
client unit suite went red on every platform.
It is excluded: it marks a throwaway copy built to be compared against and
discarded, so it is never set on a config anyone runs with, and rendering it
would only ever print false.
* [client] Provision the peer identity on the iOS login path
Key generation used to happen inside apply(), so a config loaded from JSON with
no keys got them in memory on the way in, the login worked, and the app stored
the result. This branch moved generation into EnsureIdentity, and nothing in
the iOS SDK called it.
The consequence lands on the flow the mobile logout sets up: logout clears both
keys in place so the next login registers a new peer. The app then hands that
keyless JSON to Auth.SetConfigFromJSON, and the login calls auth.NewAuth with
an empty WireGuard key, which fails on key size before the SSO flow starts —
the user cannot sign back in.
Auth.setBaseConfig now provisions, which covers both entry points (NewAuth and
SetConfigFromJSON). It mints on the base config, the one GetConfigJSON returns
for the caller to persist, and writes it to disk itself when the profile has a
file — non-atomically, like NewAuth's own write, since the tvOS App Group
sandbox blocks temp-file-and-rename.
Not covered by a test: the package builds only under GOOS=ios, which the test
jobs do not run. Verified by building and vetting for GOOS=ios/arm64.
Reported by pappz in review.
* [client] Name the resolving reader for what it does, not what it makes
ReadOrGenerateConfig reads the profile config and falls back to the defaults in
memory when there is no file. "Generate" reads as "produces and stores", which
is the opposite of the property the rename it came from was meant to advertise:
the read is pure, writes nothing and mints no identity.
ReadConfigOrDefault says the same without the side effect, and pairs with
GetExistingConfig, which fails where this one falls back. Its doc comment now
states the absence of a write rather than only the fallback.
Pure rename; the two remaining mentions of the pre-branch name ReadConfig in
the tests go with it.
Reported by pappz in review.
* [client] Read an emptied NAT list as the absent one it matches
apply() compared NATExternalIPs with reflect.DeepEqual, which calls a nil
slice and an empty slice different. Both mean the same thing — no NAT
mappings — and the two meet on a perfectly ordinary start: a profile stores
the absent list as JSON null and reads it back nil, while `netbird up` sends
CleanNATExternalIPs, an empty list, whenever NB_EXTERNAL_IP_MAP is set to
nothing, which a deployment template does by default.
So the gate saw a change where nothing changed and refused the request with
FailedPrecondition. That is the same deadlock this branch exists to remove,
reached through another field: a container with the kill switch on could not
come up, and `netbird up` reported "the daemon refused the settings update".
The DNS label list next to it already used slices.Equal, which treats nil and
empty as the same list. The NAT list now does too, and the last use of
reflect in the package goes with it.
Reported by pappz in review.
1400 lines
42 KiB
JSON
1400 lines
42 KiB
JSON
{
|
||
"tray.tooltip": {
|
||
"message": "NetBird"
|
||
},
|
||
"tray.status.disconnected": {
|
||
"message": "已断开连接"
|
||
},
|
||
"tray.status.daemonUnavailable": {
|
||
"message": "未运行"
|
||
},
|
||
"tray.status.error": {
|
||
"message": "错误"
|
||
},
|
||
"tray.status.connected": {
|
||
"message": "已连接"
|
||
},
|
||
"tray.status.connecting": {
|
||
"message": "正在连接"
|
||
},
|
||
"tray.status.needsLogin": {
|
||
"message": "需要登录"
|
||
},
|
||
"tray.status.loginFailed": {
|
||
"message": "登录失败"
|
||
},
|
||
"tray.status.sessionExpired": {
|
||
"message": "会话已过期"
|
||
},
|
||
"tray.session.expiresIn": {
|
||
"message": "会话将在 {remaining} 后过期"
|
||
},
|
||
"tray.session.unit.lessThanMinute": {
|
||
"message": "不到一分钟"
|
||
},
|
||
"tray.session.unit.minute": {
|
||
"message": "1 分钟"
|
||
},
|
||
"tray.session.unit.minutes": {
|
||
"message": "{count} 分钟"
|
||
},
|
||
"tray.session.unit.hour": {
|
||
"message": "1 小时"
|
||
},
|
||
"tray.session.unit.hours": {
|
||
"message": "{count} 小时"
|
||
},
|
||
"tray.session.unit.day": {
|
||
"message": "1 天"
|
||
},
|
||
"tray.session.unit.days": {
|
||
"message": "{count} 天"
|
||
},
|
||
"tray.menu.open": {
|
||
"message": "打开 NetBird"
|
||
},
|
||
"tray.menu.connect": {
|
||
"message": "连接"
|
||
},
|
||
"tray.menu.disconnect": {
|
||
"message": "断开连接"
|
||
},
|
||
"tray.menu.exitNode": {
|
||
"message": "出口节点"
|
||
},
|
||
"tray.menu.networks": {
|
||
"message": "资源"
|
||
},
|
||
"tray.menu.profiles": {
|
||
"message": "配置文件"
|
||
},
|
||
"tray.menu.manageProfiles": {
|
||
"message": "管理配置文件"
|
||
},
|
||
"tray.menu.settings": {
|
||
"message": "设置…"
|
||
},
|
||
"tray.menu.debugBundle": {
|
||
"message": "创建调试包"
|
||
},
|
||
"tray.menu.about": {
|
||
"message": "帮助与支持"
|
||
},
|
||
"tray.menu.github": {
|
||
"message": "GitHub"
|
||
},
|
||
"tray.menu.documentation": {
|
||
"message": "文档"
|
||
},
|
||
"tray.menu.troubleshoot": {
|
||
"message": "故障排除"
|
||
},
|
||
"tray.menu.downloadLatest": {
|
||
"message": "下载最新版本"
|
||
},
|
||
"tray.menu.installVersion": {
|
||
"message": "安装 {version} 版本"
|
||
},
|
||
"tray.menu.guiVersion": {
|
||
"message": "GUI:{version}"
|
||
},
|
||
"tray.menu.daemonVersion": {
|
||
"message": "守护进程:{version}"
|
||
},
|
||
"tray.menu.versionUnknown": {
|
||
"message": "—"
|
||
},
|
||
"tray.menu.quit": {
|
||
"message": "退出 NetBird"
|
||
},
|
||
"notify.daemonOutdated.title": {
|
||
"message": "NetBird 服务版本过旧"
|
||
},
|
||
"notify.daemonOutdated.body": {
|
||
"message": "请更新 NetBird 服务以使用此应用。"
|
||
},
|
||
"notify.update.title": {
|
||
"message": "NetBird 有可用更新"
|
||
},
|
||
"notify.update.body": {
|
||
"message": "NetBird {version} 已可用。"
|
||
},
|
||
"notify.update.enforcedSuffix": {
|
||
"message": " 您的管理员要求进行此次更新。"
|
||
},
|
||
"notify.error.title": {
|
||
"message": "错误"
|
||
},
|
||
"notify.error.connect": {
|
||
"message": "连接失败"
|
||
},
|
||
"notify.error.disconnect": {
|
||
"message": "断开连接失败"
|
||
},
|
||
"notify.error.switchProfile": {
|
||
"message": "切换到 {profile} 失败"
|
||
},
|
||
"notify.error.exitNode": {
|
||
"message": "更新出口节点 {name} 失败"
|
||
},
|
||
"notify.sessionExpired.title": {
|
||
"message": "NetBird 会话已过期"
|
||
},
|
||
"notify.sessionExpired.body": {
|
||
"message": "您的 NetBird 会话已过期。请重新登录。"
|
||
},
|
||
"notify.sessionWarning.title": {
|
||
"message": "会话即将过期"
|
||
},
|
||
"notify.sessionWarning.body": {
|
||
"message": "您的 NetBird 会话将在 {remaining} 后过期。点击“立即延长”以续期。"
|
||
},
|
||
"notify.sessionWarning.bodyGeneric": {
|
||
"message": "您的 NetBird 会话即将过期。点击“立即延长”以续期。"
|
||
},
|
||
"notify.sessionWarning.extend": {
|
||
"message": "立即延长"
|
||
},
|
||
"notify.sessionWarning.dismiss": {
|
||
"message": "忽略"
|
||
},
|
||
"notify.sessionWarning.failed": {
|
||
"message": "延长 NetBird 会话失败"
|
||
},
|
||
"notify.sessionWarning.successTitle": {
|
||
"message": "NetBird 会话已延长"
|
||
},
|
||
"notify.sessionWarning.successBody": {
|
||
"message": "您的会话已刷新。"
|
||
},
|
||
"notify.sessionDeadlineRejected.title": {
|
||
"message": "会话截止时间被拒绝"
|
||
},
|
||
"notify.sessionDeadlineRejected.body": {
|
||
"message": "服务器发送了无效的会话截止时间。请重新登录。"
|
||
},
|
||
"notify.mdm.policyApplied.title": {
|
||
"message": "NetBird 设置已更新"
|
||
},
|
||
"notify.mdm.policyApplied.body": {
|
||
"message": "您的 NetBird 配置已根据 IT 策略更新。"
|
||
},
|
||
"common.cancel": {
|
||
"message": "取消"
|
||
},
|
||
"common.save": {
|
||
"message": "保存"
|
||
},
|
||
"common.saveChanges": {
|
||
"message": "保存更改"
|
||
},
|
||
"common.saving": {
|
||
"message": "正在保存…"
|
||
},
|
||
"common.close": {
|
||
"message": "关闭"
|
||
},
|
||
"common.copy": {
|
||
"message": "复制"
|
||
},
|
||
"common.togglePasswordVisibility": {
|
||
"message": "切换密码可见性"
|
||
},
|
||
"common.increase": {
|
||
"message": "增加"
|
||
},
|
||
"common.decrease": {
|
||
"message": "减少"
|
||
},
|
||
"common.delete": {
|
||
"message": "删除"
|
||
},
|
||
"common.create": {
|
||
"message": "创建"
|
||
},
|
||
"common.add": {
|
||
"message": "添加"
|
||
},
|
||
"common.remove": {
|
||
"message": "移除"
|
||
},
|
||
"common.refresh": {
|
||
"message": "刷新"
|
||
},
|
||
"common.loading": {
|
||
"message": "正在加载…"
|
||
},
|
||
"common.netbird": {
|
||
"message": "NetBird"
|
||
},
|
||
"common.noResults.title": {
|
||
"message": "未找到任何结果"
|
||
},
|
||
"common.noResults.description": {
|
||
"message": "我们未能找到任何结果。请尝试其他搜索词或更改筛选条件。"
|
||
},
|
||
"notConnected.title": {
|
||
"message": "已断开连接"
|
||
},
|
||
"notConnected.description": {
|
||
"message": "请先连接到 NetBird,以查看有关对等节点、网络资源和出口节点的详细信息。"
|
||
},
|
||
"connect.status.disconnected": {
|
||
"message": "已断开连接"
|
||
},
|
||
"connect.status.connecting": {
|
||
"message": "正在连接…"
|
||
},
|
||
"connect.status.connected": {
|
||
"message": "已连接"
|
||
},
|
||
"connect.status.disconnecting": {
|
||
"message": "正在断开连接…"
|
||
},
|
||
"connect.status.daemonUnavailable": {
|
||
"message": "守护进程不可用"
|
||
},
|
||
"connect.status.loginRequired": {
|
||
"message": "需要登录"
|
||
},
|
||
"connect.error.loginTitle": {
|
||
"message": "登录失败"
|
||
},
|
||
"connect.error.connectTitle": {
|
||
"message": "连接失败"
|
||
},
|
||
"connect.error.disconnectTitle": {
|
||
"message": "断开连接失败"
|
||
},
|
||
"nav.peers.title": {
|
||
"message": "对等节点"
|
||
},
|
||
"nav.peers.description": {
|
||
"message": "{total} 个中已连接 {connected} 个"
|
||
},
|
||
"nav.resources.title": {
|
||
"message": "资源"
|
||
},
|
||
"nav.resources.description": {
|
||
"message": "{total} 个中已激活 {active} 个"
|
||
},
|
||
"nav.exitNode.title": {
|
||
"message": "出口节点"
|
||
},
|
||
"nav.exitNode.none": {
|
||
"message": "未激活"
|
||
},
|
||
"nav.exitNode.using": {
|
||
"message": "经由 {name}"
|
||
},
|
||
"header.openSettings": {
|
||
"message": "打开设置"
|
||
},
|
||
"header.togglePanel": {
|
||
"message": "切换侧边栏"
|
||
},
|
||
"profile.selector.loading": {
|
||
"message": "正在加载…"
|
||
},
|
||
"profile.selector.noProfile": {
|
||
"message": "无配置文件"
|
||
},
|
||
"profile.selector.searchPlaceholder": {
|
||
"message": "按名称搜索配置文件…"
|
||
},
|
||
"profile.selector.emptyTitle": {
|
||
"message": "未找到配置文件"
|
||
},
|
||
"profile.selector.emptyDescription": {
|
||
"message": "请尝试其他搜索词或创建新的配置文件。"
|
||
},
|
||
"profile.selector.newProfile": {
|
||
"message": "新建配置文件"
|
||
},
|
||
"profile.selector.moreOptions": {
|
||
"message": "更多选项"
|
||
},
|
||
"profile.selector.deregister": {
|
||
"message": "注销"
|
||
},
|
||
"profile.selector.delete": {
|
||
"message": "删除"
|
||
},
|
||
"profile.selector.switchTo": {
|
||
"message": "切换到此配置文件"
|
||
},
|
||
"profile.selector.edit": {
|
||
"message": "编辑"
|
||
},
|
||
"profile.edit.title": {
|
||
"message": "编辑配置文件"
|
||
},
|
||
"profile.edit.submit": {
|
||
"message": "保存更改"
|
||
},
|
||
"profile.dialog.title": {
|
||
"message": "输入配置文件名称"
|
||
},
|
||
"profile.dialog.nameLabel": {
|
||
"message": "配置文件名称"
|
||
},
|
||
"profile.dialog.description": {
|
||
"message": "为您的配置文件设置一个易于识别的名称。"
|
||
},
|
||
"profile.dialog.placeholder": {
|
||
"message": "例如:工作"
|
||
},
|
||
"profile.dialog.submit": {
|
||
"message": "添加配置文件"
|
||
},
|
||
"profile.dialog.required": {
|
||
"message": "请输入配置文件名称,例如:工作、家庭"
|
||
},
|
||
"profile.dialog.managementHelp": {
|
||
"message": "使用 NetBird Cloud 或您自己的服务器。"
|
||
},
|
||
"profile.dialog.urlUnreachable": {
|
||
"message": "无法连接到此服务器。请检查 URL,如果确认无误,也可以照常添加该配置文件。"
|
||
},
|
||
"header.menu.settings": {
|
||
"message": "设置…"
|
||
},
|
||
"header.menu.defaultView": {
|
||
"message": "默认视图"
|
||
},
|
||
"header.menu.advancedView": {
|
||
"message": "高级视图"
|
||
},
|
||
"header.menu.updateAvailable": {
|
||
"message": "有可用更新"
|
||
},
|
||
"header.menu.open": {
|
||
"message": "打开菜单"
|
||
},
|
||
"header.profile.switch": {
|
||
"message": "切换配置文件"
|
||
},
|
||
"connect.toggle.label": {
|
||
"message": "切换 NetBird 连接"
|
||
},
|
||
"connect.localIp.label": {
|
||
"message": "本地 IP 地址"
|
||
},
|
||
"common.search": {
|
||
"message": "搜索"
|
||
},
|
||
"common.filter": {
|
||
"message": "筛选"
|
||
},
|
||
"exitNodes.dropdown.trigger": {
|
||
"message": "选择出口节点"
|
||
},
|
||
"peers.row.label": {
|
||
"message": "打开 {name} 的详情,{status}"
|
||
},
|
||
"peers.dialog.title": {
|
||
"message": "对等节点详情"
|
||
},
|
||
"networks.row.toggle": {
|
||
"message": "切换 {name}"
|
||
},
|
||
"networks.bulk.label": {
|
||
"message": "切换所有可见资源"
|
||
},
|
||
"profile.switch.title": {
|
||
"message": "切换到配置文件“{name}”?"
|
||
},
|
||
"profile.switch.message": {
|
||
"message": "您确定要切换配置文件吗?\n您当前的配置文件将被断开连接。"
|
||
},
|
||
"profile.switch.confirm": {
|
||
"message": "确认"
|
||
},
|
||
"profile.deregister.title": {
|
||
"message": "注销配置文件“{name}”?"
|
||
},
|
||
"profile.deregister.message": {
|
||
"message": "您确定要注销此配置文件吗?\n您将需要重新登录才能使用它。"
|
||
},
|
||
"profile.deregister.confirm": {
|
||
"message": "注销"
|
||
},
|
||
"profile.delete.title": {
|
||
"message": "删除配置文件“{name}”?"
|
||
},
|
||
"profile.delete.message": {
|
||
"message": "您确定要删除此配置文件吗?\n此操作无法撤销。"
|
||
},
|
||
"profile.delete.disabledActive": {
|
||
"message": "无法删除处于活动状态的配置文件。请先切换到其他配置文件,再删除此配置文件。"
|
||
},
|
||
"profile.delete.disabledDefault": {
|
||
"message": "无法删除默认配置文件。"
|
||
},
|
||
"profile.error.switchTitle": {
|
||
"message": "切换配置文件失败"
|
||
},
|
||
"profile.error.deregisterTitle": {
|
||
"message": "注销配置文件失败"
|
||
},
|
||
"profile.error.deleteTitle": {
|
||
"message": "删除配置文件失败"
|
||
},
|
||
"profile.error.createTitle": {
|
||
"message": "创建配置文件失败"
|
||
},
|
||
"profile.error.editTitle": {
|
||
"message": "编辑配置文件失败"
|
||
},
|
||
"profile.error.loadTitle": {
|
||
"message": "加载配置文件失败"
|
||
},
|
||
"profile.dropdown.activeProfile": {
|
||
"message": "当前配置文件"
|
||
},
|
||
"profile.dropdown.switchProfile": {
|
||
"message": "切换配置文件"
|
||
},
|
||
"profile.dropdown.noEmail": {
|
||
"message": "其他"
|
||
},
|
||
"profile.dropdown.addProfile": {
|
||
"message": "添加配置文件"
|
||
},
|
||
"profile.dropdown.manageProfiles": {
|
||
"message": "管理配置文件"
|
||
},
|
||
"profile.dropdown.settings": {
|
||
"message": "设置"
|
||
},
|
||
"settings.profiles.section.profiles": {
|
||
"message": "配置文件"
|
||
},
|
||
"settings.profiles.intro": {
|
||
"message": "并行保留多个独立的 NetBird 身份,例如工作和个人账户,或不同的管理服务器。可在下方添加、注销或删除配置文件。"
|
||
},
|
||
"settings.profiles.addProfile": {
|
||
"message": "添加配置文件"
|
||
},
|
||
"settings.profiles.active": {
|
||
"message": "活动"
|
||
},
|
||
"settings.profiles.emptyTitle": {
|
||
"message": "无配置文件"
|
||
},
|
||
"settings.profiles.emptyDescription": {
|
||
"message": "创建一个配置文件以连接到 NetBird 管理服务器。"
|
||
},
|
||
"settings.error.loadTitle": {
|
||
"message": "加载设置失败"
|
||
},
|
||
"settings.error.saveTitle": {
|
||
"message": "保存设置失败"
|
||
},
|
||
"settings.error.debugBundleTitle": {
|
||
"message": "创建调试包失败"
|
||
},
|
||
"settings.nav.label": {
|
||
"message": "设置部分"
|
||
},
|
||
"settings.tabs.general": {
|
||
"message": "常规"
|
||
},
|
||
"settings.tabs.network": {
|
||
"message": "网络"
|
||
},
|
||
"settings.tabs.security": {
|
||
"message": "安全"
|
||
},
|
||
"settings.tabs.profiles": {
|
||
"message": "配置文件"
|
||
},
|
||
"settings.tabs.ssh": {
|
||
"message": "SSH"
|
||
},
|
||
"settings.tabs.advanced": {
|
||
"message": "高级"
|
||
},
|
||
"settings.tabs.troubleshooting": {
|
||
"message": "故障排除"
|
||
},
|
||
"settings.tabs.about": {
|
||
"message": "关于"
|
||
},
|
||
"settings.tabs.updateAvailable": {
|
||
"message": "有可用更新"
|
||
},
|
||
"settings.general.section.general": {
|
||
"message": "常规"
|
||
},
|
||
"settings.general.section.connection": {
|
||
"message": "连接"
|
||
},
|
||
"settings.general.connectOnStartup.label": {
|
||
"message": "启动时连接"
|
||
},
|
||
"settings.general.connectOnStartup.help": {
|
||
"message": "在服务启动时自动建立连接。"
|
||
},
|
||
"settings.general.notifications.label": {
|
||
"message": "桌面通知"
|
||
},
|
||
"settings.general.notifications.help": {
|
||
"message": "显示有关新更新和连接事件的桌面通知。"
|
||
},
|
||
"settings.general.autostart.label": {
|
||
"message": "登录时启动 NetBird 界面"
|
||
},
|
||
"settings.general.autostart.help": {
|
||
"message": "在您登录时自动启动 NetBird 界面。此设置仅影响图形界面,不影响后台服务。"
|
||
},
|
||
"settings.general.autostart.errorTitle": {
|
||
"message": "更改自启动设置失败"
|
||
},
|
||
"settings.general.keepConnectedOnQuit.label": {
|
||
"message": "退出后保持连接",
|
||
"description": "Toggle label: keep the VPN connection up after quitting the UI."
|
||
},
|
||
"settings.general.keepConnectedOnQuit.help": {
|
||
"message": "关闭 NetBird 后,连接会在后台保持。只有你自己断开时才会停止。",
|
||
"description": "Helper text for the stay-connected-after-quitting toggle."
|
||
},
|
||
"settings.general.language.label": {
|
||
"message": "显示语言"
|
||
},
|
||
"settings.general.language.help": {
|
||
"message": "选择 NetBird 界面的语言。"
|
||
},
|
||
"settings.general.language.search": {
|
||
"message": "搜索语言…"
|
||
},
|
||
"settings.general.language.empty": {
|
||
"message": "没有匹配的语言。"
|
||
},
|
||
"settings.general.theme.label": {
|
||
"message": "主题"
|
||
},
|
||
"settings.general.theme.help": {
|
||
"message": "选择浅色、深色或跟随系统外观。"
|
||
},
|
||
"settings.general.theme.system": {
|
||
"message": "跟随系统"
|
||
},
|
||
"settings.general.theme.light": {
|
||
"message": "浅色"
|
||
},
|
||
"settings.general.theme.dark": {
|
||
"message": "深色"
|
||
},
|
||
"settings.general.management.label": {
|
||
"message": "管理服务器"
|
||
},
|
||
"settings.general.management.help": {
|
||
"message": "连接到 NetBird Cloud 或您自己的自托管管理服务器。更改将使客户端重新连接。"
|
||
},
|
||
"settings.general.management.cloud": {
|
||
"message": "Cloud"
|
||
},
|
||
"settings.general.management.selfHosted": {
|
||
"message": "自托管"
|
||
},
|
||
"settings.general.management.urlPlaceholder": {
|
||
"message": "https://netbird.selfhosted.com:443"
|
||
},
|
||
"settings.general.management.urlError": {
|
||
"message": "请输入有效的 URL,例如:https://netbird.selfhosted.com:443"
|
||
},
|
||
"settings.general.management.urlUnreachable": {
|
||
"message": "无法连接到此服务器。请检查 URL,如果确认无误,也可以照常保存。"
|
||
},
|
||
"settings.general.management.switchCloudTitle": {
|
||
"message": "切换到 NetBird Cloud?"
|
||
},
|
||
"settings.general.management.switchCloudMessage": {
|
||
"message": "这将断开您的自托管服务器。\n您可能需要重新登录。"
|
||
},
|
||
"settings.general.management.switchCloudConfirm": {
|
||
"message": "切换到 Cloud"
|
||
},
|
||
"settings.network.section.connectivity": {
|
||
"message": "连接性"
|
||
},
|
||
"settings.network.section.routingDns": {
|
||
"message": "路由与 DNS"
|
||
},
|
||
"settings.network.monitor.label": {
|
||
"message": "网络变化时重新连接"
|
||
},
|
||
"settings.network.monitor.help": {
|
||
"message": "监测网络,并在发生变化时自动重新连接,例如切换 Wi-Fi、以太网变化或从睡眠中恢复。"
|
||
},
|
||
"settings.network.dns.label": {
|
||
"message": "启用 DNS"
|
||
},
|
||
"settings.network.dns.help": {
|
||
"message": "将 NetBird 管理的 DNS 设置应用到主机解析器。"
|
||
},
|
||
"settings.network.clientRoutes.label": {
|
||
"message": "启用客户端路由"
|
||
},
|
||
"settings.network.clientRoutes.help": {
|
||
"message": "接受来自其他对等节点的路由,以访问它们的网络。"
|
||
},
|
||
"settings.network.serverRoutes.label": {
|
||
"message": "启用服务器路由"
|
||
},
|
||
"settings.network.serverRoutes.help": {
|
||
"message": "向其他对等节点通告此主机的本地路由。"
|
||
},
|
||
"settings.network.ipv6.label": {
|
||
"message": "启用 IPv6"
|
||
},
|
||
"settings.network.ipv6.help": {
|
||
"message": "为 NetBird 叠加网络使用 IPv6 寻址。"
|
||
},
|
||
"settings.security.section.firewall": {
|
||
"message": "防火墙"
|
||
},
|
||
"settings.security.section.encryption": {
|
||
"message": "加密"
|
||
},
|
||
"settings.security.blockInbound.label": {
|
||
"message": "阻止入站流量"
|
||
},
|
||
"settings.security.blockInbound.help": {
|
||
"message": "拒绝对等节点向本设备及其路由的任何网络发起的未经请求的连接。出站流量不受影响。"
|
||
},
|
||
"settings.security.blockLan.label": {
|
||
"message": "阻止 LAN 访问"
|
||
},
|
||
"settings.security.blockLan.help": {
|
||
"message": "当本设备为对等节点路由流量时,阻止它们访问您的本地网络或其设备。"
|
||
},
|
||
"settings.security.rosenpass.label": {
|
||
"message": "启用抗量子加密"
|
||
},
|
||
"settings.security.rosenpass.help": {
|
||
"message": "在 WireGuard® 之上通过 Rosenpass 添加后量子密钥交换。"
|
||
},
|
||
"settings.security.rosenpassPermissive.label": {
|
||
"message": "启用宽松模式"
|
||
},
|
||
"settings.security.rosenpassPermissive.help": {
|
||
"message": "允许连接到不支持抗量子加密的对等节点。"
|
||
},
|
||
"settings.ssh.section.server": {
|
||
"message": "服务器"
|
||
},
|
||
"settings.ssh.section.capabilities": {
|
||
"message": "功能"
|
||
},
|
||
"settings.ssh.section.authentication": {
|
||
"message": "身份验证"
|
||
},
|
||
"settings.ssh.server.label": {
|
||
"message": "启用 SSH 服务器"
|
||
},
|
||
"settings.ssh.server.help": {
|
||
"message": "在此主机上运行 NetBird SSH 服务器,以便其他对等节点可以连接到它。"
|
||
},
|
||
"settings.ssh.root.label": {
|
||
"message": "允许 root 登录"
|
||
},
|
||
"settings.ssh.root.help": {
|
||
"message": "允许对等节点以 root 用户身份登录。禁用后将要求使用非特权账户。"
|
||
},
|
||
"settings.ssh.sftp.label": {
|
||
"message": "允许 SFTP"
|
||
},
|
||
"settings.ssh.sftp.help": {
|
||
"message": "使用原生 SFTP 或 SCP 客户端安全地传输文件。"
|
||
},
|
||
"settings.ssh.localForward.label": {
|
||
"message": "本地端口转发"
|
||
},
|
||
"settings.ssh.localForward.help": {
|
||
"message": "允许连接的对等节点将本地端口隧道转发到此主机可访问的服务。"
|
||
},
|
||
"settings.ssh.remoteForward.label": {
|
||
"message": "远程端口转发"
|
||
},
|
||
"settings.ssh.remoteForward.help": {
|
||
"message": "允许连接的对等节点将此主机上的端口反向暴露到它们自己的机器。"
|
||
},
|
||
"settings.ssh.jwt.label": {
|
||
"message": "启用 JWT 身份验证"
|
||
},
|
||
"settings.ssh.jwt.help": {
|
||
"message": "针对您的 IdP 验证每个 SSH 会话,以确认用户身份并进行审计。禁用后将仅依赖网络 ACL 策略,在没有可用 IdP 时很有用。"
|
||
},
|
||
"settings.ssh.jwtTtl.label": {
|
||
"message": "JWT 缓存 TTL"
|
||
},
|
||
"settings.ssh.jwtTtl.help": {
|
||
"message": "在出站 SSH 连接再次提示前,此客户端缓存 JWT 的时长。设为 0 可禁用缓存,每次连接都进行身份验证。"
|
||
},
|
||
"settings.ssh.jwtTtl.suffix": {
|
||
"message": "秒"
|
||
},
|
||
"settings.advanced.section.interface": {
|
||
"message": "接口"
|
||
},
|
||
"settings.advanced.section.security": {
|
||
"message": "安全"
|
||
},
|
||
"settings.advanced.interfaceName.label": {
|
||
"message": "名称"
|
||
},
|
||
"settings.advanced.interfaceName.error": {
|
||
"message": "请使用 1-15 个字母、数字、点、连字符或下划线。"
|
||
},
|
||
"settings.advanced.interfaceName.errorMac": {
|
||
"message": "必须以“utun”开头,后跟一个数字(例如 utun100)。"
|
||
},
|
||
"settings.advanced.port.label": {
|
||
"message": "端口"
|
||
},
|
||
"settings.advanced.port.error": {
|
||
"message": "请输入介于 {min} 和 {max} 之间的端口。"
|
||
},
|
||
"settings.advanced.port.help": {
|
||
"message": "如果设为 0,将使用一个随机的空闲端口。"
|
||
},
|
||
"settings.advanced.mtu.label": {
|
||
"message": "MTU"
|
||
},
|
||
"settings.advanced.mtu.error": {
|
||
"message": "请输入介于 {min} 和 {max} 之间的 MTU 值。"
|
||
},
|
||
"settings.advanced.psk.label": {
|
||
"message": "预共享密钥"
|
||
},
|
||
"settings.advanced.psk.help": {
|
||
"message": "可选的 WireGuard PSK,用于额外的对称加密。它与 NetBird 设置密钥不同。您将只能与使用相同预共享密钥的对等节点通信。"
|
||
},
|
||
"settings.troubleshooting.section.title": {
|
||
"message": "调试包"
|
||
},
|
||
"settings.troubleshooting.anonymize.label": {
|
||
"message": "匿名化敏感信息"
|
||
},
|
||
"settings.troubleshooting.anonymize.help": {
|
||
"message": "隐藏 IP 地址、域名和其他敏感值。"
|
||
},
|
||
"settings.troubleshooting.anonymize.info": {
|
||
"message": "默认级别保留内部 IPv4 地址和对等节点名称,便于支持人员阅读。严格级别还会匿名化私有 (RFC 1918)、CGNAT 和链路本地 IP 地址、对等节点名称以及 WireGuard 公钥。相同的值会映射到相同的占位符,因此对等节点仍可区分。向组织外部分享调试包时请使用严格级别。"
|
||
},
|
||
"settings.troubleshooting.anonymize.none": {
|
||
"message": "无"
|
||
},
|
||
"settings.troubleshooting.anonymize.default": {
|
||
"message": "默认"
|
||
},
|
||
"settings.troubleshooting.anonymize.strict": {
|
||
"message": "严格"
|
||
},
|
||
"settings.troubleshooting.systemInfo.label": {
|
||
"message": "包含系统信息"
|
||
},
|
||
"settings.troubleshooting.systemInfo.help": {
|
||
"message": "包含操作系统、内核、网络接口和路由表。"
|
||
},
|
||
"settings.troubleshooting.upload.label": {
|
||
"message": "将调试包上传到 NetBird 服务器"
|
||
},
|
||
"settings.troubleshooting.upload.help": {
|
||
"message": "返回一个上传密钥,供您分享给 NetBird 支持团队。"
|
||
},
|
||
"settings.troubleshooting.trace.label": {
|
||
"message": "启用跟踪日志"
|
||
},
|
||
"settings.troubleshooting.trace.help": {
|
||
"message": "将日志级别提升到 TRACE,之后再恢复原级别。"
|
||
},
|
||
"settings.troubleshooting.capture.label": {
|
||
"message": "捕获会话"
|
||
},
|
||
"settings.troubleshooting.capture.help": {
|
||
"message": "重新连接并等待,以便您复现问题。"
|
||
},
|
||
"settings.troubleshooting.packets.label": {
|
||
"message": "捕获网络数据包"
|
||
},
|
||
"settings.troubleshooting.packets.help": {
|
||
"message": "在捕获期间将网络流量保存为 .pcap 文件。"
|
||
},
|
||
"settings.troubleshooting.duration.label": {
|
||
"message": "捕获时长"
|
||
},
|
||
"settings.troubleshooting.duration.help": {
|
||
"message": "捕获会话运行的时长。"
|
||
},
|
||
"settings.troubleshooting.duration.suffix": {
|
||
"message": "分钟"
|
||
},
|
||
"settings.troubleshooting.create": {
|
||
"message": "创建调试包"
|
||
},
|
||
"settings.troubleshooting.progress.description": {
|
||
"message": "正在收集日志、系统详情和连接状态。这通常只需片刻——请保持此窗口打开,直到完成。"
|
||
},
|
||
"settings.troubleshooting.cancelling": {
|
||
"message": "正在取消…"
|
||
},
|
||
"settings.troubleshooting.done.uploadedTitle": {
|
||
"message": "调试包已成功上传!"
|
||
},
|
||
"settings.troubleshooting.done.savedTitle": {
|
||
"message": "调试包已保存"
|
||
},
|
||
"settings.troubleshooting.done.uploadedDescription": {
|
||
"message": "请将下方的上传密钥分享给 <docs>NetBird 支持团队</docs>。本地也已保存了一份副本。"
|
||
},
|
||
"settings.troubleshooting.done.savedDescription": {
|
||
"message": "您的调试包已保存在本地。"
|
||
},
|
||
"settings.troubleshooting.done.copyKey": {
|
||
"message": "复制密钥"
|
||
},
|
||
"settings.troubleshooting.done.openFolder": {
|
||
"message": "打开文件夹"
|
||
},
|
||
"settings.troubleshooting.done.openFileLocation": {
|
||
"message": "打开文件位置"
|
||
},
|
||
"settings.troubleshooting.uploadFailedWithReason": {
|
||
"message": "上传失败:{reason} 调试包仍已保存在本地。"
|
||
},
|
||
"settings.troubleshooting.uploadFailed": {
|
||
"message": "上传失败。调试包仍已保存在本地。"
|
||
},
|
||
"settings.troubleshooting.stage.reconnecting": {
|
||
"message": "正在重新连接 NetBird…"
|
||
},
|
||
"settings.troubleshooting.stage.capturing": {
|
||
"message": "正在捕获调试日志"
|
||
},
|
||
"settings.troubleshooting.stage.bundling": {
|
||
"message": "正在生成调试包…"
|
||
},
|
||
"settings.troubleshooting.stage.uploading": {
|
||
"message": "正在上传到 NetBird…"
|
||
},
|
||
"settings.troubleshooting.stage.cancelling": {
|
||
"message": "正在取消…"
|
||
},
|
||
"settings.about.client": {
|
||
"message": "NetBird 客户端 v{version}"
|
||
},
|
||
"settings.about.clientName": {
|
||
"message": "NetBird 客户端"
|
||
},
|
||
"settings.about.development": {
|
||
"message": "[开发版]"
|
||
},
|
||
"settings.about.gui": {
|
||
"message": "GUI v{version}"
|
||
},
|
||
"settings.about.guiName": {
|
||
"message": "GUI"
|
||
},
|
||
"settings.about.copyright": {
|
||
"message": "© {year} NetBird。保留所有权利。"
|
||
},
|
||
"settings.about.links.imprint": {
|
||
"message": "法律声明"
|
||
},
|
||
"settings.about.links.privacy": {
|
||
"message": "隐私"
|
||
},
|
||
"settings.about.links.cla": {
|
||
"message": "CLA"
|
||
},
|
||
"settings.about.links.terms": {
|
||
"message": "服务条款"
|
||
},
|
||
"settings.about.community.github": {
|
||
"message": "GitHub"
|
||
},
|
||
"settings.about.community.slack": {
|
||
"message": "Slack"
|
||
},
|
||
"settings.about.community.forum": {
|
||
"message": "论坛"
|
||
},
|
||
"settings.about.community.documentation": {
|
||
"message": "文档"
|
||
},
|
||
"settings.about.community.feedback": {
|
||
"message": "反馈"
|
||
},
|
||
"update.banner.message": {
|
||
"message": "NetBird {version} 已准备好安装。"
|
||
},
|
||
"update.banner.later": {
|
||
"message": "稍后"
|
||
},
|
||
"update.banner.installNow": {
|
||
"message": "立即安装"
|
||
},
|
||
"update.card.versionAvailableDownload": {
|
||
"message": "{version} 版本可供下载。"
|
||
},
|
||
"update.card.versionAvailableInstall": {
|
||
"message": "{version} 版本可供安装。"
|
||
},
|
||
"update.card.whatsNew": {
|
||
"message": "更新内容?"
|
||
},
|
||
"update.card.installNow": {
|
||
"message": "立即安装"
|
||
},
|
||
"update.card.getInstaller": {
|
||
"message": "下载"
|
||
},
|
||
"update.card.autoCheckInterval": {
|
||
"message": "NetBird 会在后台检查更新。"
|
||
},
|
||
"update.card.changelog": {
|
||
"message": "更新日志"
|
||
},
|
||
"update.card.onLatestVersion": {
|
||
"message": "您已是最新版本"
|
||
},
|
||
"update.header.tooltip": {
|
||
"message": "有可用更新"
|
||
},
|
||
"update.overlay.updatingVersion": {
|
||
"message": "正在将 NetBird 更新到 v{version}"
|
||
},
|
||
"update.overlay.updating": {
|
||
"message": "正在更新 NetBird"
|
||
},
|
||
"update.overlay.description": {
|
||
"message": "有更新的版本可用,正在安装。更新完成后,NetBird 将自动重启。"
|
||
},
|
||
"update.overlay.error.timeoutTitle": {
|
||
"message": "更新耗时过长"
|
||
},
|
||
"update.overlay.error.timeoutDescription": {
|
||
"message": "安装 {target} 耗时过长,未能完成。"
|
||
},
|
||
"update.overlay.error.canceledTitle": {
|
||
"message": "更新已停止"
|
||
},
|
||
"update.overlay.error.canceledDescription": {
|
||
"message": "对 {target} 的更新在完成前已被取消。"
|
||
},
|
||
"update.overlay.error.failTitle": {
|
||
"message": "无法安装更新"
|
||
},
|
||
"update.overlay.error.failDescription": {
|
||
"message": "无法安装 {target}。"
|
||
},
|
||
"update.overlay.error.unknownMessage": {
|
||
"message": "未知错误"
|
||
},
|
||
"update.overlay.error.targetVersion": {
|
||
"message": "v{version}"
|
||
},
|
||
"update.overlay.error.targetFallback": {
|
||
"message": "新版本"
|
||
},
|
||
"update.error.loadStateTitle": {
|
||
"message": "加载更新状态失败"
|
||
},
|
||
"update.error.triggerTitle": {
|
||
"message": "启动更新失败"
|
||
},
|
||
"update.page.versionLine": {
|
||
"message": "正在将客户端更新到:{version}。"
|
||
},
|
||
"update.page.versionLineGeneric": {
|
||
"message": "正在更新客户端。"
|
||
},
|
||
"update.page.outdated": {
|
||
"message": "您的客户端版本早于管理服务器中设置的自动更新版本。"
|
||
},
|
||
"update.page.status.running": {
|
||
"message": "正在更新"
|
||
},
|
||
"update.page.status.timeout": {
|
||
"message": "更新超时。请重试。"
|
||
},
|
||
"update.page.status.canceled": {
|
||
"message": "更新已取消。"
|
||
},
|
||
"update.page.status.failed": {
|
||
"message": "更新失败:{message}"
|
||
},
|
||
"update.page.status.unknownError": {
|
||
"message": "未知的更新错误"
|
||
},
|
||
"update.page.failedTitle": {
|
||
"message": "更新失败"
|
||
},
|
||
"update.page.timeoutMessage": {
|
||
"message": "更新超时。"
|
||
},
|
||
"update.page.dontClose": {
|
||
"message": "请勿关闭此窗口。"
|
||
},
|
||
"update.page.updating": {
|
||
"message": "正在更新…"
|
||
},
|
||
"update.page.complete": {
|
||
"message": "更新完成"
|
||
},
|
||
"update.page.failed": {
|
||
"message": "更新失败"
|
||
},
|
||
"window.title.settings": {
|
||
"message": "设置"
|
||
},
|
||
"window.title.signIn": {
|
||
"message": "登录"
|
||
},
|
||
"window.title.sessionExpiration": {
|
||
"message": "会话即将过期"
|
||
},
|
||
"window.title.updating": {
|
||
"message": "正在更新"
|
||
},
|
||
"window.title.welcome": {
|
||
"message": "欢迎使用 NetBird"
|
||
},
|
||
"window.title.error": {
|
||
"message": "错误"
|
||
},
|
||
"welcome.title": {
|
||
"message": "在托盘中查找 NetBird"
|
||
},
|
||
"welcome.titleMac": {
|
||
"message": "在菜单栏中查找 NetBird"
|
||
},
|
||
"welcome.description": {
|
||
"message": "NetBird 驻留在您的托盘中。点击图标即可连接、切换配置文件或打开设置。"
|
||
},
|
||
"welcome.descriptionMac": {
|
||
"message": "NetBird 驻留在您的菜单栏中。点击图标即可连接、切换配置文件或打开设置。"
|
||
},
|
||
"welcome.continue": {
|
||
"message": "继续"
|
||
},
|
||
"welcome.back": {
|
||
"message": "返回"
|
||
},
|
||
"welcome.management.title": {
|
||
"message": "设置 NetBird"
|
||
},
|
||
"welcome.management.description": {
|
||
"message": "点击“继续”即可开始;如果您有自己的 NetBird 服务器,请选择“自托管”。"
|
||
},
|
||
"welcome.management.cloud.title": {
|
||
"message": "NetBird Cloud"
|
||
},
|
||
"welcome.management.cloud.description": {
|
||
"message": "使用我们的托管服务。无需任何设置。"
|
||
},
|
||
"welcome.management.selfHosted.title": {
|
||
"message": "自托管"
|
||
},
|
||
"welcome.management.selfHosted.description": {
|
||
"message": "连接到您自己的管理服务器。"
|
||
},
|
||
"welcome.management.urlLabel": {
|
||
"message": "管理服务器 URL"
|
||
},
|
||
"welcome.management.urlPlaceholder": {
|
||
"message": "https://netbird.selfhosted.com:443"
|
||
},
|
||
"welcome.management.urlInvalid": {
|
||
"message": "请输入有效的 URL,例如:https://netbird.selfhosted.com:443"
|
||
},
|
||
"welcome.management.urlUnreachable": {
|
||
"message": "无法连接到此服务器。请检查 URL 或您的网络,如果确认无误,再继续。"
|
||
},
|
||
"welcome.management.checking": {
|
||
"message": "正在检查…"
|
||
},
|
||
"browserLogin.title": {
|
||
"message": "请在浏览器中继续以完成登录"
|
||
},
|
||
"browserLogin.notSeeing": {
|
||
"message": "没看到浏览器标签页?"
|
||
},
|
||
"browserLogin.tryAgain": {
|
||
"message": "重试"
|
||
},
|
||
"browserLogin.openFailedTitle": {
|
||
"message": "打开浏览器失败"
|
||
},
|
||
"sessionExpiration.title": {
|
||
"message": "会话即将过期"
|
||
},
|
||
"sessionExpiration.titleLater": {
|
||
"message": "您的会话即将过期"
|
||
},
|
||
"sessionExpiration.description": {
|
||
"message": "此设备即将断开连接。通过浏览器登录进行续期。"
|
||
},
|
||
"sessionExpiration.descriptionLater": {
|
||
"message": "通过浏览器登录可让此设备保持连接到您的网络。"
|
||
},
|
||
"sessionExpiration.stay": {
|
||
"message": "续期会话"
|
||
},
|
||
"sessionExpiration.authenticate": {
|
||
"message": "进行身份验证"
|
||
},
|
||
"sessionExpiration.logout": {
|
||
"message": "退出登录"
|
||
},
|
||
"sessionExpiration.expired": {
|
||
"message": "会话已过期"
|
||
},
|
||
"sessionExpiration.expiredDescription": {
|
||
"message": "设备已断开连接。通过浏览器登录进行身份验证以重新连接。"
|
||
},
|
||
"sessionExpiration.close": {
|
||
"message": "关闭"
|
||
},
|
||
"sessionExpiration.extendFailedTitle": {
|
||
"message": "延长会话失败"
|
||
},
|
||
"sessionExpiration.logoutFailedTitle": {
|
||
"message": "退出登录失败"
|
||
},
|
||
"peers.search.placeholder": {
|
||
"message": "按名称或 IP 搜索"
|
||
},
|
||
"peers.filter.all": {
|
||
"message": "全部"
|
||
},
|
||
"peers.filter.online": {
|
||
"message": "在线"
|
||
},
|
||
"peers.filter.offline": {
|
||
"message": "离线"
|
||
},
|
||
"peers.empty.title": {
|
||
"message": "无可用的对等节点"
|
||
},
|
||
"peers.empty.description": {
|
||
"message": "您可能没有任何可用的对等节点,或者无权访问其中任何一个。"
|
||
},
|
||
"peers.details.domain": {
|
||
"message": "域名"
|
||
},
|
||
"peers.details.netbirdIp": {
|
||
"message": "NetBird IP"
|
||
},
|
||
"peers.details.netbirdIpv6": {
|
||
"message": "NetBird IPv6"
|
||
},
|
||
"peers.details.publicKey": {
|
||
"message": "公钥"
|
||
},
|
||
"peers.details.connection": {
|
||
"message": "连接"
|
||
},
|
||
"peers.details.latency": {
|
||
"message": "延迟"
|
||
},
|
||
"peers.details.lastHandshake": {
|
||
"message": "上次握手"
|
||
},
|
||
"peers.details.statusSince": {
|
||
"message": "上次连接更新"
|
||
},
|
||
"peers.details.bytes": {
|
||
"message": "字节"
|
||
},
|
||
"peers.details.bytesSent": {
|
||
"message": "已发送"
|
||
},
|
||
"peers.details.bytesReceived": {
|
||
"message": "已接收"
|
||
},
|
||
"peers.details.localIce": {
|
||
"message": "本地 ICE"
|
||
},
|
||
"peers.details.remoteIce": {
|
||
"message": "远程 ICE"
|
||
},
|
||
"peers.details.never": {
|
||
"message": "从不"
|
||
},
|
||
"peers.details.justNow": {
|
||
"message": "刚刚"
|
||
},
|
||
"peers.details.refresh": {
|
||
"message": "刷新"
|
||
},
|
||
"peers.status.connected": {
|
||
"message": "已连接"
|
||
},
|
||
"peers.status.connecting": {
|
||
"message": "正在连接"
|
||
},
|
||
"peers.status.disconnected": {
|
||
"message": "已断开连接"
|
||
},
|
||
"peers.details.relayAddress": {
|
||
"message": "中继"
|
||
},
|
||
"peers.details.networks": {
|
||
"message": "资源"
|
||
},
|
||
"peers.details.relayed": {
|
||
"message": "经中继"
|
||
},
|
||
"peers.details.p2p": {
|
||
"message": "P2P"
|
||
},
|
||
"peers.details.rosenpass": {
|
||
"message": "已启用 Rosenpass"
|
||
},
|
||
"networks.search.placeholder": {
|
||
"message": "按网络或域名搜索"
|
||
},
|
||
"networks.filter.all": {
|
||
"message": "全部"
|
||
},
|
||
"networks.filter.active": {
|
||
"message": "活动"
|
||
},
|
||
"networks.filter.overlapping": {
|
||
"message": "重叠"
|
||
},
|
||
"networks.empty.title": {
|
||
"message": "无可用资源"
|
||
},
|
||
"networks.empty.description": {
|
||
"message": "您可能没有任何可用的网络资源,或者无权访问其中任何一个。"
|
||
},
|
||
"networks.selected": {
|
||
"message": "已选择"
|
||
},
|
||
"networks.unselected": {
|
||
"message": "未选择"
|
||
},
|
||
"networks.ips.heading": {
|
||
"message": "已解析的 IP"
|
||
},
|
||
"networks.bulk.selectionCount": {
|
||
"message": "{total} 个中已激活 {selected} 个"
|
||
},
|
||
"networks.bulk.enableAll": {
|
||
"message": "全部启用"
|
||
},
|
||
"networks.bulk.disableAll": {
|
||
"message": "全部禁用"
|
||
},
|
||
"exitNodes.search.placeholder": {
|
||
"message": "搜索出口节点"
|
||
},
|
||
"exitNodes.none": {
|
||
"message": "无"
|
||
},
|
||
"exitNodes.empty.title": {
|
||
"message": "无可用的出口节点"
|
||
},
|
||
"exitNodes.empty.description": {
|
||
"message": "尚未向此对等节点共享任何出口节点。"
|
||
},
|
||
"exitNodes.card.title": {
|
||
"message": "出口节点"
|
||
},
|
||
"exitNodes.card.statusActive": {
|
||
"message": "活动"
|
||
},
|
||
"exitNodes.card.statusInactive": {
|
||
"message": "非活动"
|
||
},
|
||
"exitNodes.dropdown.noneTitle": {
|
||
"message": "无"
|
||
},
|
||
"exitNodes.dropdown.noneDescription": {
|
||
"message": "不使用出口节点的直接连接"
|
||
},
|
||
"quickActions.connect": {
|
||
"message": "连接"
|
||
},
|
||
"quickActions.disconnect": {
|
||
"message": "断开连接"
|
||
},
|
||
"daemon.unavailable.title": {
|
||
"message": "NetBird 服务未运行"
|
||
},
|
||
"daemon.unavailable.description": {
|
||
"message": "服务运行后,应用将自动重新连接。"
|
||
},
|
||
"daemon.unavailable.docsLink": {
|
||
"message": "文档"
|
||
},
|
||
"daemon.outdated.title": {
|
||
"message": "NetBird 客户端版本过旧"
|
||
},
|
||
"daemon.outdated.description": {
|
||
"message": "新版 GUI 与您较旧的客户端不兼容。请更新客户端以使用新应用。"
|
||
},
|
||
"daemon.outdated.download": {
|
||
"message": "下载最新版本"
|
||
},
|
||
"error.jwt_clock_skew": {
|
||
"message": "登录失败:此设备的时钟与服务器不同步。请同步您的系统时钟后重试。"
|
||
},
|
||
"error.jwt_expired": {
|
||
"message": "您的登录令牌已过期。请重新登录。"
|
||
},
|
||
"error.jwt_signature_invalid": {
|
||
"message": "登录失败:令牌签名无效。请联系您的管理员。"
|
||
},
|
||
"error.session_expired": {
|
||
"message": "您的会话已过期。请重新登录。"
|
||
},
|
||
"error.invalid_setup_key": {
|
||
"message": "设置密钥缺失或无效。"
|
||
},
|
||
"error.permission_denied": {
|
||
"message": "登录被服务器拒绝。"
|
||
},
|
||
"error.daemon_unreachable": {
|
||
"message": "NetBird 守护进程无响应。请检查服务是否正在运行。"
|
||
},
|
||
"error.settings_locked": {
|
||
"message": "此设备上的设置无法更改:管理员已将其锁定。"
|
||
},
|
||
"error.settings_managed_by_mdm": {
|
||
"message": "此设置由您的组织管理,无法更改。"
|
||
},
|
||
"error.unknown": {
|
||
"message": "操作失败。"
|
||
},
|
||
"error.elevation_unavailable": {
|
||
"message": "NetBird 无法向此系统请求所需的权限。请改为运行:"
|
||
},
|
||
"error.elevation_failed": {
|
||
"message": "即使使用提升的权限也无法应用此更改。请改为运行:"
|
||
},
|
||
"settings.ssh.privilege.actorRoot": {
|
||
"message": "root 权限"
|
||
},
|
||
"settings.ssh.privilege.actorAdministrator": {
|
||
"message": "管理员权限"
|
||
},
|
||
"settings.ssh.privilege.hint": {
|
||
"message": "需要{actor}。请改为运行:"
|
||
},
|
||
"settings.ssh.privilege.oneWay": {
|
||
"message": "您可以关闭此项,但重新开启需要{actor}。"
|
||
},
|
||
"settings.ssh.privilege.oneWayInverted": {
|
||
"message": "您可以开启此项,但再次关闭需要{actor}。"
|
||
},
|
||
"settings.ssh.privilege.authorizePending": {
|
||
"message": "正在等待授权…"
|
||
}
|
||
}
|