mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-07 05:59:06 +02:00
* [client] Gate settings updates on value, not on field presence
The update-settings kill switch (--disable-update-settings /
NB_DISABLE_UPDATE_SETTINGS / the MDM DisableUpdateSettings key) forbids
changing settings, but it decided what a "change" was by looking at
whether a field was present in the request. The CLI fills the whole
config surface of SetConfigRequest and LoginRequest from its flags and
environment on every `netbird up` (setupSetConfigReq in cmd/up.go), so a
client configured by environment restates its own configuration on every
start and tripped the gate every time.
SetConfig only warned about that, but Login carries the same fields and
was gated the same way, and Login runs inside the CLI's backoff loop: the
daemon answered every attempt with codes.Unavailable, `netbird up` never
completed, and a container with NB_DISABLE_UPDATE_SETTINGS plus any
config env var (NB_MANAGEMENT_URL, for one) could not come up at all.
Both gates now compare values. Config.WouldChange is the dry-run half of
UpdateConfig: it runs the very same diff logic (Config.apply) against a
copy of the stored config, so the gate cannot drift from what an actual
update would do, nor go stale when a field is added. A request that
restates what the profile already holds changes nothing and is allowed; a
request that diverges is refused exactly as before, and a dry run that
cannot be evaluated fails closed. A profile with no config on disk yet is
judged against the config the daemon would create for it.
For Login, the compared input comes from loginOverridesInput, which
persistLoginOverrides also uses to perform the write, so the gate judges
precisely the two fields a login can persist (management URL, pre-shared
key) and no field it ignores.
Two adjacent defects surfaced while making the comparison exact:
- Config.apply compared URLs as raw strings, so the same endpoint spelled
without its default port ("https://api.netbird.io" vs
"https://api.netbird.io:443") counted as a new value and rewrote the
config. It now compares the parsed forms.
- UpdateConfig did not collapse the redacted pre-shared key, unlike
UpdateOrCreateConfig and DirectUpdateConfig, so a UI round-trip of the
mask replaced the stored key with asterisks.
The CLI warning for a refused SetConfig said the method was not available
in the daemon, which sent people looking for a version mismatch that was
not there; it now reports the refusal.
* [client] Do not write the profile config while only reading it to decide
The update-settings gate needs the stored config to decide whether a request
changes anything, so the previous commit moved that read ahead of the refusal.
The read is not side-effect free: profilemanager.GetConfig writes the config
back whenever apply() has to fill in a default the file was missing. A request
that the gate then refuses had therefore already rewritten the profile file.
PeekConfig is GetConfig without that write-back. The returned config is still
normalized in memory, which is what the decision needs; the file is left
exactly as it was found. Every caller of storedConfigAtPath feeds a gate that
can refuse, so they all peek.
Note for reviewers: the daemon still normalizes the file on startup and on
every real update, so nothing depends on a read performing that write.
* [client] Compare service URLs as endpoints, not as strings
Three places in one request path each had their own notion of "same
management URL": the config layer compared the parsed URLs as strings, the
privileged-change gate compared scheme + host + effective port, and the MDM
conflict check compared strings after filling in the default port. Only the
middle one was right.
A string comparison answers the wrong question. "https://api.netbird.io",
"https://api.netbird.io/" and "https://API.netbird.io:443" are one endpoint
written three ways, so a client restating its own management URL with a
trailing slash — a normal way to write it — was still read as a client asking
to be repointed, and the update-settings gate refused it. The MDM check had
the same flaw against the enforced value.
profilemanager.SameServiceURL is now the single comparison: same scheme, same
host case-insensitively as DNS names are, same effective port. The config
layer, the privileged-change gate and the MDM conflict check all defer to it,
so there is one answer to "did this URL change?" instead of three.
* [client] Stop the config dry run from generating throwaway keys
The dry run's baseline for a profile with no config file yet went through
createNewConfig, and apply() generates a WireGuard and an SSH key whenever it
finds those fields empty. The baseline is compared against and discarded, so
every evaluation minted a keypair it threw away — and logged "generated new
Wireguard key". The CLI retries Login in a backoff loop, so a first `netbird up`
on a fresh profile filled the daemon log with what reads like peer-key rotation.
The baseline now starts from the shared skeleton with placeholder keys, so
apply() has nothing to generate. No ConfigInput field maps to either key, so
the comparison is unaffected.
* [client] Cover the login the update-settings gate used to refuse
The gate's decision procedure was tested directly, but no test drove the Login
RPC that the refusal actually broke: the CLI retries Login in a backoff loop,
so a refused no-op login is what kept a client configured by environment from
ever coming up. The handler-level coverage stopped at the refusal case, which
passes on the pre-fix code too.
This test fails on the pre-fix daemon with "update settings are disabled" and
passes now. Past the gate the handler does real work the test does not stand
up, so it asserts only that the refusal did not happen.
* [client] Re-take the update-settings decision under the config lock
Login checks twice on purpose: the first check refuses the ordinary case
early, and authorizeAndPrepareLogin re-takes the authoritative one under
guardedConfigMu because the first is unsynchronized against a concurrent
privileged request. The update-settings decision is now equally
value-dependent — it compares the request against the stored config — but it
was taken only in the first, unlocked check.
So a login that was a no-op when it was checked could be written after a
concurrent writer had repointed the profile, which is exactly the window the
lock exists to close. The decision is now re-taken alongside the privilege one,
which also makes it the last read before persistLoginOverrides writes.
The test drives that interleaving through the existing afterLoginPreCheck seam
and fails without the re-check.
* [client] Drop an unreachable guard and fix two stale comments
- loginOverridesInput's nil-message guard cannot be reached: Login
dereferences the message well before it, in storedLoginConfig.
- The docstring above afterLoginPreCheck described persistLoginOverrides,
which lives further down the file and now carries its own.
- UpdateConfig's comment named DirectUpdateConfig; the function is
DirectUpdateOrCreateConfig.
* [client] Make config reads pure and provision the identity explicitly
Reading a config wrote it back. profilemanager.readConfig persisted whatever
apply() had filled in, and ReadConfig created and wrote the file outright when
it was absent, so every reader was quietly a writer: a gate deciding whether to
refuse a request, a UI listing profiles, a mobile getter reading one preference.
The previous commit worked around that with a PeekConfig variant, which left
two read functions with opposite side effects and the antipattern still there
for everyone else.
Only one thing in a read genuinely had to be persisted: apply() generated the
WireGuard and SSH keys when it found them empty, and a generated key cannot be
recomputed — losing it means the peer comes back with a different identity and
registers again. Everything else apply() fills in is a deterministic default
that the next read recomputes anyway.
So identity provisioning is now its own step, Config.EnsureIdentity, and the
callers that provision write the result out themselves, in the open:
- Server.getConfig, the daemon's provisioning point;
- the CLI's foreground login, which is about to dial management;
- update() / directUpdate(), the config write paths — a stored profile can
legitimately carry no identity, since a mobile logout clears the keys in
place, and the next write is what has to mint a new one.
ReadConfig and GetConfig no longer write anything, PeekConfig is gone, and the
dry-run baseline no longer needs placeholder keys to keep apply() from minting
real ones.
One deliberate leftover: readConfig still calls util.EnforcePermission, which
chmods a config file whose permissions are too broad. It changes no content and
is idempotent, and dropping it would leave a legacy file world-readable until
its first write.
* [client] Name the two config readers for what they do
ReadConfig and GetConfig differed in one thing — what happens when the file is
absent — and neither name said which was which:
- ReadConfig -> ReadOrGenerateConfig (reads it, or generates one in memory)
- GetConfig -> GetExistingConfig (reads it, or fails)
Three comments went with them:
- GetConfig's said "return with Config and if it was created. Errors out if it
does not exist", which described a bool it does not return and a creation it
never performs.
- ReadConfig's explained that it does not write, which is what a reader is
supposed to do anyway.
- Server.getConfig's said it "errors out if it does not exist", which it does
not — it resolves a default config, and now provisions the identity too.
* [client] Do not panic on a config with no sync message version
apply() wrote the incoming sync message version through the stored pointer,
without checking it was there: a config that carries no version yet made it
dereference nil. Reachable from the update-settings dry run, which runs inside
a request handler — where failing closed is the worst acceptable outcome, and a
panic is not one.
The field is now reassigned like every other optional one, which also means
apply() no longer mutates anything the caller still holds through a pointer, so
the dry run's copy has one less field to detach.
Reported by cubic-dev-ai on PR #7398.
* [client] Compare the client certificate paths before reporting a change
apply() assigned the incoming mTLS certificate and key paths and set updated
unconditionally, without comparing them to what the config already held. It is
the same presence-instead-of-value mistake this branch set out to fix, one
layer down: a caller restating its own certificate paths was reported as
changing them, which trips the value-aware update-settings gate.
Reported by cubic-dev-ai on PR #7398.
* [client] Address the remaining bot findings on PR #7398
- Login logged the active-profile-state error and returned the same cause; the
repo's guidelines call for one or the other, and the wrapped error is the one
that carries context. (CodeRabbit)
- `netbird up` reported a codes.Unavailable SetConfig failure as "the daemon
refused the settings update", but that code also covers a daemon that became
unreachable. It now reports what the daemon said without asserting why.
(cubic-dev-ai)
- TestLogin_ChangingTheManagementURLIsRefused asserted the error and nothing
else, while "refused before it can touch daemon state" is the contract. It now
checks the stored management URL, the in-progress login and the active profile,
matching its SetConfig counterpart. (cubic-dev-ai)
* [client] Keep the peer identity out of a read that finds no file
ReadOrGenerateConfig resolves a default config when the profile has no file
yet, and createNewConfig was minting the WireGuard and SSH keys while doing so.
That defeated the provisioning pair it was meant to serve: the CLI's foreground
login calls EnsureIdentity to find out whether it has to persist the keys, got
generated == false because the read had already generated them, and so never
wrote them out. The login then dialed management with an identity that only
existed in memory, and the next login registered a second peer.
createNewConfig no longer provisions. createProvisionedConfig is the variant
that does, and the callers whose contract is "usable as it comes back" use it:
CreateInMemoryConfig, whose callers connect with the result, and the two
create-and-write branches. A read gets a config with no identity, so the
caller's own EnsureIdentity reports the work and triggers the write.
Reported by CodeRabbit and cubic-dev-ai on PR #7398, both on the same defect.
* [client] Stop the gate test from dialing the real management server
TestLogin_RestatingTheStoredConfigPassesTheGate asserts that the gate lets a
no-op login through, and the handler then went on to do the login for real:
isLoginRequired builds an auth client when isLoginRequiredFn is unset, so the
test dialed the profile's management URL — api.netbird.io:443. It took 1.05s
locally and would hang on a runner with no egress, for a fact about the gate
that needs no network at all.
Stubbed like the login_outcome tests do. The test now runs in 0.00s.
Reported by cubic-dev-ai on PR #7398.
* [client] Keep the admin panel path part of its identity
The endpoint comparison introduced for the management URL was applied to the
admin URL too, and that one is opened in a browser rather than dialed over
gRPC: a panel served under /netbird is not the panel served at the root. So a
config whose admin URL differed only by path reported no change, and the new
path was never persisted — a custom panel URL could not be updated at all.
SameServiceURLIncludingPath adds what a URL carries past its endpoint (path,
query, fragment, userinfo) while still treating equivalent spellings as equal:
a missing path and "/" are the same root, and so is a trailing slash. The
management URL keeps the endpoint-only comparison, since only the endpoint is
ever dialed.
Ports are also normalized numerically now, so ":0443" and ":443" are one port.
Reported by cubic-dev-ai on PR #7398 (two findings).
* [client] Treat a profile with no identity as already deregistered
Two findings on the same consequence of pure reads: a profile can legitimately
carry no keys, because logging out clears them in place.
- sendLogoutRequestWithConfig went straight to wgtypes.ParseKey and failed with
"incorrect key size: 0" on the second logout of the same profile. There is
nothing to deregister for a peer that was never registered, so it returns
cleanly. Before pure reads this case was hidden: the read minted a key and
the daemon dialed management with one it had never seen.
- The mobile logout read the config with the generating reader right after
checking the file exists. The two are not atomic, so a profile removed in
between was resolved from the defaults and recreated by the write that
follows. It uses the existing-file reader now.
Reported by cubic-dev-ai and CodeRabbit on PR #7398.
* [client] Fail `netbird up` when the daemon refuses the settings update
With the update-settings kill switch on, `netbird up --enable-rosenpass`
connected and said almost nothing: SetConfig refused the change, the CLI
downgraded that to a warning, and Login carries no rosenpass field to apply, so
the flag was silently dropped. The setting stayed disabled, which is the point
of the switch, but the caller was never told their request had been ignored.
The refusal now travels as codes.FailedPrecondition instead of
codes.Unavailable, and the CLI fails on it. Unavailable means "the daemon
cannot serve this call", which is why the CLI downgraded it and why
client/ui/services reads it as an unreachable daemon — both wrong for a daemon
that answered and refused. FailedPrecondition also matches what the MDM gate
already returns for a managed field, so both refusals are now one class of
error, and it is added to the login backoff's early-exit codes so a refused
login stops instead of retrying for 30s.
This does not put the container back in the deadlock: with the value-aware
gate, a client restating its own configuration is not refused at all, so
nothing reaches this path unless a real change was asked for.
* [client] Name the reader storedConfigAtPath actually calls
The purity note still said profilemanager.GetConfig, which the rename two
commits later turned into GetExistingConfig.
Reported by cubic-dev-ai on PR #7398.
* [client] Restore the gofmt alignment of the error constants
The comment added above errUpdateSettingsDisabled in the previous commit split
the const block's alignment group, so gofmt wants the two constants above it
re-aligned. CI runs gofmt, so this would have failed the lint job.
* [client] Let an unprivileged caller log out a profile with no identity
The empty-key check sat behind requirePrivilegeForDeregistration, so an
unprivileged logout of an identity-less profile was refused with
PermissionDenied instead of completing as the no-op it is. And it was refused
for most profiles, not a corner case: the gate arms whenever the SSH server is
enabled, and sshServerEnabled reads an absent ServerSSHAllowed as enabled, so
every legacy profile qualifies.
The check now runs first. What the gate protects against is handing this
machine's registered key to another management server; with no key there is
nothing to hand over and nothing to protect.
Reported by CodeRabbit and cubic-dev-ai on PR #7398, both on the same defect.
* [client] Stop `netbird login` from retrying a refusal for 30 seconds
`netbird up` and `netbird login` both run Login through the backoff cycle, and
each carried its own copy of the list of codes that end it. Only up.go learned
about codes.FailedPrecondition, so a refused `netbird login` kept retrying and
then reported "login backoff cycle failed" instead of what the daemon said.
terminalLoginError is now that list, once, next to WithBackOff — the duplicated
copies are what let the two commands disagree in the first place.
Reported by cubic-dev-ai on PR #7398.
* [client] Answer terminalLoginError's nil case on its own terms
A successful Login reaches terminalLoginError with a nil error, and nothing
covered that. It happens to work on grpc v1.80.0 — gstatus.FromError(nil)
answers (nil, true), and Status.Code tolerates a nil receiver by returning
codes.OK, which is not in the terminal set — but that is a chain of internal
details to be relying on for the common path, and none of it was asserted.
Now the nil error is handled where it is obvious, and the table covers it.
Reported by CodeRabbit on PR #7398, which called it a panic; measured on
v1.80.0 it is not one. The gap was the untested reliance, not a crash.
* [client] Treat an unset optional field as its default when diffing a config
Seven Config fields mean "the effective default" when they hold no value:
the five SSH toggles, the SSH JWT cache TTL, and the network monitor. Every
consumer already reads a nil as that default, but apply() diffed them by
presence — `config.X == nil || *input.X != *config.X` — so an input restating
the default counted as a change.
That made the update-settings gate refuse `netbird up` outright. The CLI
sends every flag whose value came from an environment variable
(SetFlagsFromEnvVars goes through pflag's FlagSet.Set, which marks the flag
Changed), and the config a plain login writes leaves all seven unset, so a
container configured with, say, NB_ENABLE_SSH_ROOT=false restated a default
the file held as null on every start and was answered with
FailedPrecondition.
apply() now resolves the seven up front, the way it already did for
ServerSSHAllowed and RemoteJobsAllowed, which also repairs such a profile on
its next write. With the values named, the comparisons below diff values
instead of presence, so their nil branches are gone.
The network monitor keeps its platform default — on for windows and darwin —
and naming it as false elsewhere is what createEngineConfig already read a
nil to be. getJWTCacheTTL reaches the same 0 through its own default, and
Android's GetEnableSSH* getters already answered nil with false.
* [client] Normalize the config before diffing it in WouldChange
apply() reports two different things through one bool: an input that changed
a value, and a field it had to fill in because the config carried none. The
update-settings gate reads that bool as "the caller asked for a change", so
any config still missing a default answered a request that asks for nothing
with a refusal.
Readers already hand out normalized configs — readConfig applies an empty
input for exactly this reason — which is why the gate got away with it. But a
handler that refuses a request must not depend on where its caller obtained
the config, and it must not start reading "this profile predates a field" as
"the caller asked for a change" the day someone adds one with a default.
WouldChange now runs the filling-in as a pass of its own and discards its
verdict, so the pass that answers the caller measures only what the input
did.
* [client] Stop the last config write that skipped normalization
Every path that creates or updates a profile config goes through apply(),
which resolves an optional field to its default — except RenameProfile,
which read the file with a bare json.Unmarshal, set the name, and wrote it
straight back. That copied whatever the file held, so a config written by a
client that stored these fields as null kept them null. It could not
introduce a null, only carry one forward, but renaming a profile is a poor
place to leave a half-resolved config behind. It now reads through
GetExistingConfig, which normalizes what it hands out.
The tests state the invariant the fix completes, over the *bool fields of
Config listed by reflection so a field added later is covered without
touching them: none may come out of apply() unset, and no write may store
one as null. An optional bool that can be nil, true or false forces every
reader to invent the meaning of nil, and makes a diff of the config compare
presence rather than value — which is exactly what refused `netbird up` for
a client restating its own defaults.
SyncMessageVersion stays a genuine three-state field and is not covered: it
is an *int whose absence means the client pins no version, and it travels to
management that way.
* [client] Refuse a serialized config that carries no peer identity
ConfigFromJSON still promised a "fully initialized" config after this PR
moved key generation out of apply() into EnsureIdentity, but identity stopped
being one of the defaults it applies. Its two callers both connect with what
they get back: the iOS SDK's Client.SetConfigFromJSON keeps it as the
preloaded config Run() uses on tvOS, and Auth.SetConfigFromJSON as the config
it authenticates with.
No caller feeds it a document without keys today — every stored document
comes from Auth.GetConfigJSON, whose config is provisioned by
DirectUpdateOrCreateConfig or CreateInMemoryConfig, and the tvOS app only
ever edits fields of a document it already has. This is a safety net for the
next caller, not a live bug.
Provisioning the identity here would be the wrong net. Neither caller can
hand a generated key back to the store the document came from — Client
exports no config at all — so the peer would connect under an identity
nothing persists and register anew on every launch, which is the failure the
EnsureIdentity split exists to prevent. A document with no identity means
nobody has logged in yet, and saying so is the only useful answer.
Both keys are required because both are dead ends when missing: an empty
WireGuard key fails the management login on its size, and an empty SSH key
fails ssh.GeneratePublicKey in ConnectClient before the engine starts.
* [client] Say that the null-on-disk fixture is synthesized, not written
The test comment described the null state in the present tense — "the config
a plain login writes leaves every one of them unset" — which was true before
this branch and is not any more: apply() now resolves those fields, so a
login writes them set. unsetOnDisk puts the null state back deliberately, to
stand in for a profile an older client wrote. Comments only.
* [client] Gather the optional-field defaults into one function
Resolving an unset optional field was spread over five places: the two
values newConfigSkeleton pre-sets, the block this branch added for the SSH
toggles, the network monitor's own if, the `else if` tails of
ServerSSHAllowed and RemoteJobsAllowed, and a trailing if for
DisableNotifications several hundred lines further down. Reading apply() left
no single answer to "what does this field default to, and who decides".
They now live in Config.resolveUnsetDefaults, which apply() calls before it
compares anything — the ordering being the point, since it is what lets
every comparison below diff values instead of presence. The comparisons for
ServerSSHAllowed, RemoteJobsAllowed and DisableNotifications lose their
`config.X == nil ||` clauses accordingly, as the other six already had.
newConfigSkeleton keeps its two, and that is the one asymmetry worth naming:
ServerSSHAllowed defaults to false for a new profile and to true for a
legacy one, and it only works because the skeleton runs first. The doc
comment says so, where before it was implied by the order of two distant
blocks.
Pure refactor. Verified as one: for the four fields whose branches moved,
plus two that did not and the JWT TTL, all 63 combinations of stored value
(nil/false/true) against input value (absent/false/true) produce byte-
identical resolved values and `updated` verdicts before and after.
* [client] Resolve the merge conflicts left in the tree
262ce8c3b landed with the conflict markers still in it, so client/server and
the iOS SDK did not compile. Four regions, resolved as follows.
client/server/mdm.go — main moved the MDM conflict-check machinery into the
mdm package (mdm.ResolveConflicts, mdm.ConflictBool, mdm.ConflictURL, ...).
This branch had edited the local copies, which are now dead: dropped, along
with the profilemanager import that only the local conflictURL needed.
client/server/server.go, Login gate — this branch's value-aware gate stays
(the point of the PR: refuse a real divergence, let a restatement through),
so main's presence-based `loginRequestHasConfigOverrides` block goes; that
helper no longer exists here anyway. Main's other change in the same lines
is real and kept: the MDM policy now comes from the daemon-owned
s.mdmLoader.Load() instead of the package-level loadMDMPolicy, which main
removed. The stale call right below the conflict was the reason the file
would not have compiled even with the markers gone.
client/server/server.go, getConfig — both sides add something and both are
needed. The identity is provisioned and persisted first, then the MDM
overlay is applied, so what reaches disk stays the profile's own config: the
overlay is runtime-only and re-derived on every load.
client/ios/NetBirdSDK/client.go — main reworked SetConfigFromJSON to store
the JSON and re-parse it on each load, which is the shape kept; the parse is
now only a validity check, and this branch's reason for it (a document with
no peer identity is refused, not just an unparseable one) moves into that
comment.
client/server/update_settings_gate_test.go — follows the sentinel constant
to its new home, mdm.PreSharedKeyRedactedSentinel.
* [client] Reuse util's service-URL comparison instead of a second copy
The endpoint-comparison rules this branch introduced now live in util (PR
#7472 moved them there so the MDM conflict check could stop comparing URLs
as strings). Keeping a copy here is what produced that bug in the first
place: two implementations of "is this the same endpoint?" drift, and the
one that drifts starts refusing a URL that addresses the very server it
already points at.
So SameServiceURL delegates the port normalization to util.ServiceURLPort
and drops the local one, and SameServiceURLIncludingPath — endpoint plus
path, for the admin panel URL, which is opened rather than dialed — is
util.SameServiceURL plus the query, fragment and userinfo it adds on top,
so the local path normalization goes too.
What stays here is the distinction util does not make: SameServiceURL is
endpoint-only, because a management URL is dialed and only its host and port
are, while util.SameServiceURL includes the path.
Pure refactor. Verified as one: all 198 pairs of a 14-spelling matrix
(default and zero-padded ports, host case, trailing slash, path, query,
fragment, userinfo, both schemes, nil operands) answer identically for both
functions before and after.
* [client] Give a newly added profile its identity (review item 1)
AddProfile writes the config it builds straight to disk, but built it with
createNewConfig, which stopped generating the peer's keys when identity
generation moved out of apply() into EnsureIdentity. The profile file landed
with an empty PrivateKey and SSHKey.
Nothing lost the keys permanently — the daemon's own getConfig provisions and
persists them on first use — but every reader that does not write got a
config that cannot connect in the meantime, which is exactly the set this
branch grew: the update-settings gate deciding whether to refuse a request,
and the mobile SDKs loading a stored profile.
createProvisionedConfig exists for callers that persist or connect, and this
is one; before the split, createNewConfig produced the keys here too.
* [client] Let a logged-out profile deserialize again (review item 2)
ConfigFromJSON refused a document with no WireGuard or SSH key. A config
legitimately has none between a logout and the next login: mobile
LogoutProfile clears both in place and writes the profile back, so the peer
re-registers on the next login instead of returning as itself.
So the refusal broke the mobile flows it was meant to protect. On iOS and
tvOS the stored JSON of a logged-out profile stopped loading through
Client.SetConfigFromJSON and Auth.SetConfigFromJSON, and copyConfig — which
round-trips a Config through JSON to take an in-memory copy before applying
the MDM overlay — failed on the same document. Where the old code silently
minted a key, this returned an error, which is worse for logout and profile
switching alike: neither is asking to connect.
The deserializer now stays out of the identity question in both directions:
it does not generate one (a read cannot hand back keys nothing will write
down) and does not refuse one that is absent. Whoever goes on to connect is
where an absent identity has to be answered — and it already is, by the
login path that provisions and persists.
ErrConfigWithoutIdentity goes with it; nothing else used it.
* [client] Fold the scheme case here too, like util does (review item 6)
profilemanager.SameServiceURL compared the scheme with ==, util.SameServiceURL
with EqualFold. No observable difference — net/url lowercases the scheme when
it parses, and both functions take parsed URLs — but two functions of the same
name with two different rules is a trap for whoever reads one and assumes the
other.
* [client] Classify the daemon's refusals in the GUI (review item 3)
FailedPrecondition reached the classifier unmatched, so a refusal showed as
"Operation failed". It is the code both of the daemon's deliberate refusals
carry: the update-settings kill switch, and a field an MDM policy manages.
Both are now named — settings_locked and settings_managed_by_mdm, matched on
the message the daemon composes — and FailedPrecondition itself falls back to
change_refused, so a refusal the daemon grows later still reads as a refusal
rather than a failure.
Only the English strings are added. Bundle.Translate falls back to the
default language for a missing key, so other locales show English until the
usual translation pass, rather than the bare "error.<code>" the classifier
would otherwise surface.
Note: the package needs GTK4/WebKit to build, which this machine has not, so
the test is type-checked (go vet, GOOS=windows) but was not executed locally;
CI's Linux job runs it.
* [client] Cover the mobile profile round trip: create, logout, reload
Both mobile regressions this branch's review turned up lived on the same
path, and neither was visible from the desktop client: a profile created
without an identity, and a logged-out profile that would no longer
deserialize. The desktop never meets the second one — it is mobile logout
that clears the peer's keys in place, so the next login registers a new peer
instead of bringing the old one back.
The test walks a profile through the round its user puts it through —
created, logged out, loaded again, switched away from and back — and loads it
at each step the way the SDKs do: read the stored config, serialize it, load
it back. That is Client.SetConfigFromJSON storing the document for tvOS,
Auth.SetConfigFromJSON authenticating with it, and copyConfig taking an
in-memory copy before the MDM overlay.
Verified to fail on each regression separately: restoring the bare
constructor in AddProfile fails it with "a new profile was written with no
identity", and restoring the identity check in ConfigFromJSON fails it at
"load the profile back".
client/mobile already had the coverage for the first one in
TestLogoutProfile_DisableProfiles — which arrived from main with the MDM
work, and which I had not been running.
* [client] Name only the refusals, not every FailedPrecondition
The classifier gained a blanket FailedPrecondition -> change_refused fallback
so a refusal would stop reading as "Operation failed". It reaches too far:
the daemon returns that code for two dozen states that are not settings
refusals — "not logged in", "client is not running", "another capture is
already running", "session can no longer be extended, log in again to
reconnect" — and errorClassifier is shared with the session and connection
services, not just the settings save.
So the user was told the service had refused their change while what they
actually had to do was log in again. The two refusals the daemon composes
stay named by their message; everything else goes back to the generic
message, which says nothing rather than something wrong.
Reported by cubic on the PR.
* [client] Say what each assertion was checking in the mobile test
AGENTS.md asks for a context message on comparison and boolean assertions,
and four of the ones added with this test had none, so a failure would have
read as a bare Empty/Equal with no hint of which step of the round trip broke.
Reported by cubic on the PR.
* [client] Translate the two new error strings into every locale
The GUI classifier gained error.settings_locked and
error.settings_managed_by_mdm, and only the English strings were added: the
bundle falls back to the default language for a missing key, so nothing would
have shown a bare "error.<code>" to a user.
CI disagrees, and it is right to: check-translations.mjs requires every
locale to carry the full English key set, so English-only fails the gate
rather than degrading quietly.
The ten locales now carry both strings. These are my translations, not a
localization pass — worth a second pass by whoever owns the language, in
particular for the phrasing of "an administrator has locked them".
The uk file also loses two lines of stray 8-space indentation, normalized by
rewriting the file; no key or value changed with it.
* [client] Persist the profile before overlaying MDM on it (review item)
`netbird login` read the config, applied the MDM policy on top, and only then
provisioned the identity and wrote the result out. On a profile with no
identity yet — a first login — that write persisted the enforced values into
the user's own config file: an MDM-managed management URL or pre-shared key
became indistinguishable from one the user set, and stayed behind once the
policy was withdrawn.
Provisioning and its write now come first, and the overlay is applied to the
in-memory config afterwards, where it belongs: it is re-derived on every load
and never meant to reach disk from here. Server.getConfig already orders the
two this way; the two paths now agree.
Reported by cubic on the PR.
* [client] Assert against the stored config, not a resolved default (review item)
The login-gate test read the profile back with ReadOrGenerateConfig, which
resolves a default config in memory when the file is missing — and that
default's management URL is the very value the assertion checks. An erased or
mislocated profile would have passed the test instead of failing it.
The file is written by the test itself, so GetExistingConfig is the right
reader: it errors when the file is gone.
Reported by cubic on the PR.
* [client] Keep the mTLS pair off the gate's dry run (review item)
WouldChange runs the real apply() against a throwaway copy, and apply() loads
the client mTLS certificate and key from disk whenever the config names them.
So every gated SetConfig and Login read the pair — twice per request, once for
the normalization pass and once for the verdict — including requests that were
about to be refused or that changed nothing, and logged an error per request
when the files were missing. The gate used to be presence-based and never
called apply(), so this was new work on a request path.
The loaded pair feeds the connection and never the comparison: nothing in
apply() reads it back, and it does not move the `updated` verdict. A config
built only to be compared against now says so, and apply() skips the load for
it.
Reported by cubic on the PR.
* Makes it explicit that RenameProfile does write on disk
* [client] Provision the peer identity under the config lock (review item)
Login took the authoritative update-settings and privilege decisions under
guardedConfigMu, then released it and called getConfig, which mints the peer's
identity and writes the config out. Between that read and that write, a
SetConfig holding the same lock could land a change and answer its caller —
and then be overwritten by the config the login had already read.
The window is narrow: getConfig only writes when the profile has no identity
or no file, so in practice a first login racing a settings change on the same
profile. It is also narrower than before this branch, where the write happened
inside the reader on every read that filled in a default.
Provisioning now runs where the decision it belongs to runs: at the end of
authorizeAndPrepareLogin, with the lock already held, next to
persistLoginOverrides, which writes there too. No lock is taken that was not
held before, so the documented guardedConfigMu-then-mutex order is untouched.
getConfig keeps its behaviour by calling the same extracted helper; on the
login path it now finds the identity already there and writes nothing. The
other callers are unchanged, and still provision outside any lock — a
concurrent SetConfig is not part of their flow.
Reported by cubic on the PR.
* [client] Declare the probe marker to the debug-bundle field check
TestAddConfig_AllFieldsCovered walks Config by reflection and fails until every
field is either rendered in the debug bundle or listed as excluded with a
reason. The probe marker added for the gate's dry run was neither, so the
client unit suite went red on every platform.
It is excluded: it marks a throwaway copy built to be compared against and
discarded, so it is never set on a config anyone runs with, and rendering it
would only ever print false.
* [client] Provision the peer identity on the iOS login path
Key generation used to happen inside apply(), so a config loaded from JSON with
no keys got them in memory on the way in, the login worked, and the app stored
the result. This branch moved generation into EnsureIdentity, and nothing in
the iOS SDK called it.
The consequence lands on the flow the mobile logout sets up: logout clears both
keys in place so the next login registers a new peer. The app then hands that
keyless JSON to Auth.SetConfigFromJSON, and the login calls auth.NewAuth with
an empty WireGuard key, which fails on key size before the SSO flow starts —
the user cannot sign back in.
Auth.setBaseConfig now provisions, which covers both entry points (NewAuth and
SetConfigFromJSON). It mints on the base config, the one GetConfigJSON returns
for the caller to persist, and writes it to disk itself when the profile has a
file — non-atomically, like NewAuth's own write, since the tvOS App Group
sandbox blocks temp-file-and-rename.
Not covered by a test: the package builds only under GOOS=ios, which the test
jobs do not run. Verified by building and vetting for GOOS=ios/arm64.
Reported by pappz in review.
* [client] Name the resolving reader for what it does, not what it makes
ReadOrGenerateConfig reads the profile config and falls back to the defaults in
memory when there is no file. "Generate" reads as "produces and stores", which
is the opposite of the property the rename it came from was meant to advertise:
the read is pure, writes nothing and mints no identity.
ReadConfigOrDefault says the same without the side effect, and pairs with
GetExistingConfig, which fails where this one falls back. Its doc comment now
states the absence of a write rather than only the fallback.
Pure rename; the two remaining mentions of the pre-branch name ReadConfig in
the tests go with it.
Reported by pappz in review.
* [client] Read an emptied NAT list as the absent one it matches
apply() compared NATExternalIPs with reflect.DeepEqual, which calls a nil
slice and an empty slice different. Both mean the same thing — no NAT
mappings — and the two meet on a perfectly ordinary start: a profile stores
the absent list as JSON null and reads it back nil, while `netbird up` sends
CleanNATExternalIPs, an empty list, whenever NB_EXTERNAL_IP_MAP is set to
nothing, which a deployment template does by default.
So the gate saw a change where nothing changed and refused the request with
FailedPrecondition. That is the same deadlock this branch exists to remove,
reached through another field: a container with the kill switch on could not
come up, and `netbird up` reported "the daemon refused the settings update".
The DNS label list next to it already used slices.Equal, which treats nil and
empty as the same list. The NAT list now does too, and the last use of
reflect in the package goes with it.
Reported by pappz in review.
1400 lines
50 KiB
JSON
1400 lines
50 KiB
JSON
{
|
||
"tray.tooltip": {
|
||
"message": "NetBird"
|
||
},
|
||
"tray.status.disconnected": {
|
||
"message": "未接続"
|
||
},
|
||
"tray.status.daemonUnavailable": {
|
||
"message": "実行されていません"
|
||
},
|
||
"tray.status.error": {
|
||
"message": "エラー"
|
||
},
|
||
"tray.status.connected": {
|
||
"message": "接続済み"
|
||
},
|
||
"tray.status.connecting": {
|
||
"message": "接続中"
|
||
},
|
||
"tray.status.needsLogin": {
|
||
"message": "ログインが必要"
|
||
},
|
||
"tray.status.loginFailed": {
|
||
"message": "ログインに失敗しました"
|
||
},
|
||
"tray.status.sessionExpired": {
|
||
"message": "セッションが期限切れ"
|
||
},
|
||
"tray.session.expiresIn": {
|
||
"message": "セッションはあと{remaining}で期限切れ"
|
||
},
|
||
"tray.session.unit.lessThanMinute": {
|
||
"message": "1分未満"
|
||
},
|
||
"tray.session.unit.minute": {
|
||
"message": "1分"
|
||
},
|
||
"tray.session.unit.minutes": {
|
||
"message": "{count}分"
|
||
},
|
||
"tray.session.unit.hour": {
|
||
"message": "1時間"
|
||
},
|
||
"tray.session.unit.hours": {
|
||
"message": "{count}時間"
|
||
},
|
||
"tray.session.unit.day": {
|
||
"message": "1日"
|
||
},
|
||
"tray.session.unit.days": {
|
||
"message": "{count}日"
|
||
},
|
||
"tray.menu.open": {
|
||
"message": "NetBird を開く"
|
||
},
|
||
"tray.menu.connect": {
|
||
"message": "接続"
|
||
},
|
||
"tray.menu.disconnect": {
|
||
"message": "切断"
|
||
},
|
||
"tray.menu.exitNode": {
|
||
"message": "出口ノード"
|
||
},
|
||
"tray.menu.networks": {
|
||
"message": "リソース"
|
||
},
|
||
"tray.menu.profiles": {
|
||
"message": "プロファイル"
|
||
},
|
||
"tray.menu.manageProfiles": {
|
||
"message": "プロファイルの管理"
|
||
},
|
||
"tray.menu.settings": {
|
||
"message": "設定..."
|
||
},
|
||
"tray.menu.debugBundle": {
|
||
"message": "デバッグバンドルを作成"
|
||
},
|
||
"tray.menu.about": {
|
||
"message": "ヘルプとサポート"
|
||
},
|
||
"tray.menu.github": {
|
||
"message": "GitHub"
|
||
},
|
||
"tray.menu.documentation": {
|
||
"message": "ドキュメント"
|
||
},
|
||
"tray.menu.troubleshoot": {
|
||
"message": "トラブルシューティング"
|
||
},
|
||
"tray.menu.downloadLatest": {
|
||
"message": "最新バージョンをダウンロード"
|
||
},
|
||
"tray.menu.installVersion": {
|
||
"message": "バージョン {version} をインストール"
|
||
},
|
||
"tray.menu.guiVersion": {
|
||
"message": "GUI: {version}"
|
||
},
|
||
"tray.menu.daemonVersion": {
|
||
"message": "デーモン: {version}"
|
||
},
|
||
"tray.menu.versionUnknown": {
|
||
"message": "—"
|
||
},
|
||
"tray.menu.quit": {
|
||
"message": "NetBird を終了"
|
||
},
|
||
"notify.daemonOutdated.title": {
|
||
"message": "NetBird サービスが古くなっています"
|
||
},
|
||
"notify.daemonOutdated.body": {
|
||
"message": "このアプリを使用するには NetBird サービスを更新してください。"
|
||
},
|
||
"notify.update.title": {
|
||
"message": "NetBird の更新が利用可能"
|
||
},
|
||
"notify.update.body": {
|
||
"message": "NetBird {version} が利用可能です。"
|
||
},
|
||
"notify.update.enforcedSuffix": {
|
||
"message": "管理者がこの更新を必須にしています。"
|
||
},
|
||
"notify.error.title": {
|
||
"message": "エラー"
|
||
},
|
||
"notify.error.connect": {
|
||
"message": "接続に失敗しました"
|
||
},
|
||
"notify.error.disconnect": {
|
||
"message": "切断に失敗しました"
|
||
},
|
||
"notify.error.switchProfile": {
|
||
"message": "{profile} への切り替えに失敗しました"
|
||
},
|
||
"notify.error.exitNode": {
|
||
"message": "出口ノード {name} の更新に失敗しました"
|
||
},
|
||
"notify.sessionExpired.title": {
|
||
"message": "NetBird セッションが期限切れ"
|
||
},
|
||
"notify.sessionExpired.body": {
|
||
"message": "NetBird セッションの有効期限が切れました。もう一度ログインしてください。"
|
||
},
|
||
"notify.sessionWarning.title": {
|
||
"message": "まもなくセッションが期限切れ"
|
||
},
|
||
"notify.sessionWarning.body": {
|
||
"message": "NetBird セッションはあと{remaining}で期限切れになります。更新するには「今すぐ延長」をクリックしてください。"
|
||
},
|
||
"notify.sessionWarning.bodyGeneric": {
|
||
"message": "NetBird セッションはまもなく期限切れになります。更新するには「今すぐ延長」をクリックしてください。"
|
||
},
|
||
"notify.sessionWarning.extend": {
|
||
"message": "今すぐ延長"
|
||
},
|
||
"notify.sessionWarning.dismiss": {
|
||
"message": "閉じる"
|
||
},
|
||
"notify.sessionWarning.failed": {
|
||
"message": "NetBird セッションの延長に失敗しました"
|
||
},
|
||
"notify.sessionWarning.successTitle": {
|
||
"message": "NetBird セッションを延長しました"
|
||
},
|
||
"notify.sessionWarning.successBody": {
|
||
"message": "セッションが更新されました。"
|
||
},
|
||
"notify.sessionDeadlineRejected.title": {
|
||
"message": "セッション期限が拒否されました"
|
||
},
|
||
"notify.sessionDeadlineRejected.body": {
|
||
"message": "サーバーが無効なセッション期限を送信しました。もう一度サインインしてください。"
|
||
},
|
||
"notify.mdm.policyApplied.title": {
|
||
"message": "NetBird 設定が更新されました"
|
||
},
|
||
"notify.mdm.policyApplied.body": {
|
||
"message": "NetBird の構成が IT ポリシーによって更新されました。"
|
||
},
|
||
"common.cancel": {
|
||
"message": "キャンセル"
|
||
},
|
||
"common.save": {
|
||
"message": "保存"
|
||
},
|
||
"common.saveChanges": {
|
||
"message": "変更を保存"
|
||
},
|
||
"common.saving": {
|
||
"message": "保存中…"
|
||
},
|
||
"common.close": {
|
||
"message": "閉じる"
|
||
},
|
||
"common.copy": {
|
||
"message": "コピー"
|
||
},
|
||
"common.togglePasswordVisibility": {
|
||
"message": "パスワードの表示を切り替え"
|
||
},
|
||
"common.increase": {
|
||
"message": "増やす"
|
||
},
|
||
"common.decrease": {
|
||
"message": "減らす"
|
||
},
|
||
"common.delete": {
|
||
"message": "削除"
|
||
},
|
||
"common.create": {
|
||
"message": "作成"
|
||
},
|
||
"common.add": {
|
||
"message": "追加"
|
||
},
|
||
"common.remove": {
|
||
"message": "削除"
|
||
},
|
||
"common.refresh": {
|
||
"message": "更新"
|
||
},
|
||
"common.loading": {
|
||
"message": "読み込み中…"
|
||
},
|
||
"common.netbird": {
|
||
"message": "NetBird"
|
||
},
|
||
"common.noResults.title": {
|
||
"message": "結果が見つかりませんでした"
|
||
},
|
||
"common.noResults.description": {
|
||
"message": "結果が見つかりませんでした。別の検索語を試すか、フィルターを変更してください。"
|
||
},
|
||
"notConnected.title": {
|
||
"message": "未接続"
|
||
},
|
||
"notConnected.description": {
|
||
"message": "ピア、ネットワークリソース、出口ノードの詳細情報を表示するには、まず NetBird に接続してください。"
|
||
},
|
||
"connect.status.disconnected": {
|
||
"message": "未接続"
|
||
},
|
||
"connect.status.connecting": {
|
||
"message": "接続中..."
|
||
},
|
||
"connect.status.connected": {
|
||
"message": "接続済み"
|
||
},
|
||
"connect.status.disconnecting": {
|
||
"message": "切断中..."
|
||
},
|
||
"connect.status.daemonUnavailable": {
|
||
"message": "デーモンが利用できません"
|
||
},
|
||
"connect.status.loginRequired": {
|
||
"message": "ログインが必要"
|
||
},
|
||
"connect.error.loginTitle": {
|
||
"message": "ログインに失敗しました"
|
||
},
|
||
"connect.error.connectTitle": {
|
||
"message": "接続に失敗しました"
|
||
},
|
||
"connect.error.disconnectTitle": {
|
||
"message": "切断に失敗しました"
|
||
},
|
||
"nav.peers.title": {
|
||
"message": "ピア"
|
||
},
|
||
"nav.peers.description": {
|
||
"message": "{total}台中{connected}台接続中"
|
||
},
|
||
"nav.resources.title": {
|
||
"message": "リソース"
|
||
},
|
||
"nav.resources.description": {
|
||
"message": "{total}件中{active}件有効"
|
||
},
|
||
"nav.exitNode.title": {
|
||
"message": "出口ノード"
|
||
},
|
||
"nav.exitNode.none": {
|
||
"message": "未使用"
|
||
},
|
||
"nav.exitNode.using": {
|
||
"message": "{name} 経由"
|
||
},
|
||
"header.openSettings": {
|
||
"message": "設定を開く"
|
||
},
|
||
"header.togglePanel": {
|
||
"message": "サイドパネルを切り替え"
|
||
},
|
||
"profile.selector.loading": {
|
||
"message": "読み込み中..."
|
||
},
|
||
"profile.selector.noProfile": {
|
||
"message": "プロファイルなし"
|
||
},
|
||
"profile.selector.searchPlaceholder": {
|
||
"message": "名前でプロファイルを検索..."
|
||
},
|
||
"profile.selector.emptyTitle": {
|
||
"message": "プロファイルが見つかりません"
|
||
},
|
||
"profile.selector.emptyDescription": {
|
||
"message": "別の検索語を試すか、新しいプロファイルを作成してください。"
|
||
},
|
||
"profile.selector.newProfile": {
|
||
"message": "新しいプロファイル"
|
||
},
|
||
"profile.selector.moreOptions": {
|
||
"message": "その他のオプション"
|
||
},
|
||
"profile.selector.deregister": {
|
||
"message": "登録解除"
|
||
},
|
||
"profile.selector.delete": {
|
||
"message": "削除"
|
||
},
|
||
"profile.selector.switchTo": {
|
||
"message": "このプロファイルに切り替え"
|
||
},
|
||
"profile.selector.edit": {
|
||
"message": "編集"
|
||
},
|
||
"profile.edit.title": {
|
||
"message": "プロファイルを編集"
|
||
},
|
||
"profile.edit.submit": {
|
||
"message": "変更を保存"
|
||
},
|
||
"profile.dialog.title": {
|
||
"message": "プロファイル名を入力"
|
||
},
|
||
"profile.dialog.nameLabel": {
|
||
"message": "プロファイル名"
|
||
},
|
||
"profile.dialog.description": {
|
||
"message": "分かりやすいプロファイル名を設定してください。"
|
||
},
|
||
"profile.dialog.placeholder": {
|
||
"message": "例: 仕事"
|
||
},
|
||
"profile.dialog.submit": {
|
||
"message": "プロファイルを追加"
|
||
},
|
||
"profile.dialog.required": {
|
||
"message": "プロファイル名を入力してください(例: 仕事、自宅)"
|
||
},
|
||
"profile.dialog.managementHelp": {
|
||
"message": "NetBird Cloud または独自のサーバーを使用します。"
|
||
},
|
||
"profile.dialog.urlUnreachable": {
|
||
"message": "このサーバーに到達できませんでした。URLを確認するか、正しいことが確実な場合はそのままプロファイルを追加してください。"
|
||
},
|
||
"header.menu.settings": {
|
||
"message": "設定..."
|
||
},
|
||
"header.menu.defaultView": {
|
||
"message": "デフォルト表示"
|
||
},
|
||
"header.menu.advancedView": {
|
||
"message": "詳細表示"
|
||
},
|
||
"header.menu.updateAvailable": {
|
||
"message": "更新が利用可能"
|
||
},
|
||
"header.menu.open": {
|
||
"message": "メニューを開く"
|
||
},
|
||
"header.profile.switch": {
|
||
"message": "プロファイルを切り替え"
|
||
},
|
||
"connect.toggle.label": {
|
||
"message": "NetBird 接続を切り替え"
|
||
},
|
||
"connect.localIp.label": {
|
||
"message": "ローカル IP アドレス"
|
||
},
|
||
"common.search": {
|
||
"message": "検索"
|
||
},
|
||
"common.filter": {
|
||
"message": "フィルター"
|
||
},
|
||
"exitNodes.dropdown.trigger": {
|
||
"message": "出口ノードを選択"
|
||
},
|
||
"peers.row.label": {
|
||
"message": "{name} の詳細を開く、{status}"
|
||
},
|
||
"peers.dialog.title": {
|
||
"message": "ピアの詳細"
|
||
},
|
||
"networks.row.toggle": {
|
||
"message": "{name} を切り替え"
|
||
},
|
||
"networks.bulk.label": {
|
||
"message": "表示中のすべてのリソースを切り替え"
|
||
},
|
||
"profile.switch.title": {
|
||
"message": "プロファイルを「{name}」に切り替えますか?"
|
||
},
|
||
"profile.switch.message": {
|
||
"message": "プロファイルを切り替えてもよろしいですか?\n現在のプロファイルは切断されます。"
|
||
},
|
||
"profile.switch.confirm": {
|
||
"message": "確認"
|
||
},
|
||
"profile.deregister.title": {
|
||
"message": "プロファイル「{name}」の登録を解除しますか?"
|
||
},
|
||
"profile.deregister.message": {
|
||
"message": "このプロファイルの登録を解除してもよろしいですか?\n再度使用するにはログインが必要になります。"
|
||
},
|
||
"profile.deregister.confirm": {
|
||
"message": "登録解除"
|
||
},
|
||
"profile.delete.title": {
|
||
"message": "プロファイル「{name}」を削除しますか?"
|
||
},
|
||
"profile.delete.message": {
|
||
"message": "このプロファイルを削除してもよろしいですか?\nこの操作は取り消せません。"
|
||
},
|
||
"profile.delete.disabledActive": {
|
||
"message": "使用中のプロファイルは削除できません。削除する前に別のプロファイルに切り替えてください。"
|
||
},
|
||
"profile.delete.disabledDefault": {
|
||
"message": "デフォルトのプロファイルは削除できません。"
|
||
},
|
||
"profile.error.switchTitle": {
|
||
"message": "プロファイルの切り替えに失敗しました"
|
||
},
|
||
"profile.error.deregisterTitle": {
|
||
"message": "プロファイルの登録解除に失敗しました"
|
||
},
|
||
"profile.error.deleteTitle": {
|
||
"message": "プロファイルの削除に失敗しました"
|
||
},
|
||
"profile.error.createTitle": {
|
||
"message": "プロファイルの作成に失敗しました"
|
||
},
|
||
"profile.error.editTitle": {
|
||
"message": "プロファイルの編集に失敗しました"
|
||
},
|
||
"profile.error.loadTitle": {
|
||
"message": "プロファイルの読み込みに失敗しました"
|
||
},
|
||
"profile.dropdown.activeProfile": {
|
||
"message": "使用中のプロファイル"
|
||
},
|
||
"profile.dropdown.switchProfile": {
|
||
"message": "プロファイルを切り替え"
|
||
},
|
||
"profile.dropdown.noEmail": {
|
||
"message": "その他"
|
||
},
|
||
"profile.dropdown.addProfile": {
|
||
"message": "プロファイルを追加"
|
||
},
|
||
"profile.dropdown.manageProfiles": {
|
||
"message": "プロファイルの管理"
|
||
},
|
||
"profile.dropdown.settings": {
|
||
"message": "設定"
|
||
},
|
||
"settings.profiles.section.profiles": {
|
||
"message": "プロファイル"
|
||
},
|
||
"settings.profiles.intro": {
|
||
"message": "仕事用と個人用のアカウント、あるいは異なる管理サーバーなど、複数の NetBird ID を並行して管理できます。以下でプロファイルの追加、登録解除、削除ができます。"
|
||
},
|
||
"settings.profiles.addProfile": {
|
||
"message": "プロファイルを追加"
|
||
},
|
||
"settings.profiles.active": {
|
||
"message": "使用中"
|
||
},
|
||
"settings.profiles.emptyTitle": {
|
||
"message": "プロファイルがありません"
|
||
},
|
||
"settings.profiles.emptyDescription": {
|
||
"message": "NetBird 管理サーバーに接続するプロファイルを作成してください。"
|
||
},
|
||
"settings.error.loadTitle": {
|
||
"message": "設定の読み込みに失敗しました"
|
||
},
|
||
"settings.error.saveTitle": {
|
||
"message": "設定の保存に失敗しました"
|
||
},
|
||
"settings.error.debugBundleTitle": {
|
||
"message": "デバッグバンドルの作成に失敗しました"
|
||
},
|
||
"settings.nav.label": {
|
||
"message": "設定セクション"
|
||
},
|
||
"settings.tabs.general": {
|
||
"message": "一般"
|
||
},
|
||
"settings.tabs.network": {
|
||
"message": "ネットワーク"
|
||
},
|
||
"settings.tabs.security": {
|
||
"message": "セキュリティ"
|
||
},
|
||
"settings.tabs.profiles": {
|
||
"message": "プロファイル"
|
||
},
|
||
"settings.tabs.ssh": {
|
||
"message": "SSH"
|
||
},
|
||
"settings.tabs.advanced": {
|
||
"message": "詳細設定"
|
||
},
|
||
"settings.tabs.troubleshooting": {
|
||
"message": "トラブルシューティング"
|
||
},
|
||
"settings.tabs.about": {
|
||
"message": "情報"
|
||
},
|
||
"settings.tabs.updateAvailable": {
|
||
"message": "更新が利用可能"
|
||
},
|
||
"settings.general.section.general": {
|
||
"message": "一般"
|
||
},
|
||
"settings.general.section.connection": {
|
||
"message": "接続"
|
||
},
|
||
"settings.general.connectOnStartup.label": {
|
||
"message": "起動時に接続"
|
||
},
|
||
"settings.general.connectOnStartup.help": {
|
||
"message": "サービスの起動時に自動的に接続を確立します。"
|
||
},
|
||
"settings.general.notifications.label": {
|
||
"message": "デスクトップ通知"
|
||
},
|
||
"settings.general.notifications.help": {
|
||
"message": "新しい更新や接続イベントに関するデスクトップ通知を表示します。"
|
||
},
|
||
"settings.general.autostart.label": {
|
||
"message": "ログイン時に NetBird UI を起動"
|
||
},
|
||
"settings.general.autostart.help": {
|
||
"message": "ログイン時に NetBird インターフェースを自動的に起動します。これはグラフィカルインターフェースにのみ影響し、バックグラウンドサービスには影響しません。"
|
||
},
|
||
"settings.general.autostart.errorTitle": {
|
||
"message": "自動起動の変更に失敗しました"
|
||
},
|
||
"settings.general.keepConnectedOnQuit.label": {
|
||
"message": "終了後も接続を維持",
|
||
"description": "Toggle label: keep the VPN connection up after quitting the UI."
|
||
},
|
||
"settings.general.keepConnectedOnQuit.help": {
|
||
"message": "NetBird を閉じたあとも接続はバックグラウンドで維持されます。自分で切断したときにだけ停止します。",
|
||
"description": "Helper text for the stay-connected-after-quitting toggle."
|
||
},
|
||
"settings.general.language.label": {
|
||
"message": "表示言語"
|
||
},
|
||
"settings.general.language.help": {
|
||
"message": "NetBird インターフェースの言語を選択します。"
|
||
},
|
||
"settings.general.language.search": {
|
||
"message": "言語を検索…"
|
||
},
|
||
"settings.general.language.empty": {
|
||
"message": "一致する言語がありません。"
|
||
},
|
||
"settings.general.theme.label": {
|
||
"message": "テーマ"
|
||
},
|
||
"settings.general.theme.help": {
|
||
"message": "ライト、ダーク、またはシステムの外観に従います。"
|
||
},
|
||
"settings.general.theme.system": {
|
||
"message": "システム"
|
||
},
|
||
"settings.general.theme.light": {
|
||
"message": "ライト"
|
||
},
|
||
"settings.general.theme.dark": {
|
||
"message": "ダーク"
|
||
},
|
||
"settings.general.management.label": {
|
||
"message": "管理サーバー"
|
||
},
|
||
"settings.general.management.help": {
|
||
"message": "NetBird Cloud または自身のセルフホスト管理サーバーに接続します。変更するとクライアントが再接続します。"
|
||
},
|
||
"settings.general.management.cloud": {
|
||
"message": "クラウド"
|
||
},
|
||
"settings.general.management.selfHosted": {
|
||
"message": "セルフホスト"
|
||
},
|
||
"settings.general.management.urlPlaceholder": {
|
||
"message": "https://netbird.selfhosted.com:443"
|
||
},
|
||
"settings.general.management.urlError": {
|
||
"message": "有効なURLを入力してください(例: https://netbird.selfhosted.com:443)"
|
||
},
|
||
"settings.general.management.urlUnreachable": {
|
||
"message": "このサーバーに到達できませんでした。URLを確認するか、正しいことが確実な場合はそのまま保存してください。"
|
||
},
|
||
"settings.general.management.switchCloudTitle": {
|
||
"message": "NetBird Cloud に切り替えますか?"
|
||
},
|
||
"settings.general.management.switchCloudMessage": {
|
||
"message": "セルフホストサーバーが切断されます。\n再度ログインが必要になる場合があります。"
|
||
},
|
||
"settings.general.management.switchCloudConfirm": {
|
||
"message": "クラウドに切り替え"
|
||
},
|
||
"settings.network.section.connectivity": {
|
||
"message": "ネットワーク接続"
|
||
},
|
||
"settings.network.section.routingDns": {
|
||
"message": "ルーティングとDNS"
|
||
},
|
||
"settings.network.monitor.label": {
|
||
"message": "ネットワーク変更時に再接続"
|
||
},
|
||
"settings.network.monitor.help": {
|
||
"message": "ネットワークを監視し、Wi-Fiの切り替え、イーサネットの変更、スリープからの復帰などの変化時に自動的に再接続します。"
|
||
},
|
||
"settings.network.dns.label": {
|
||
"message": "DNSを有効にする"
|
||
},
|
||
"settings.network.dns.help": {
|
||
"message": "NetBird が管理する DNS 設定をホストのリゾルバに適用します。"
|
||
},
|
||
"settings.network.clientRoutes.label": {
|
||
"message": "クライアントルートを有効にする"
|
||
},
|
||
"settings.network.clientRoutes.help": {
|
||
"message": "他のピアからルートを受け入れ、そのネットワークに到達できるようにします。"
|
||
},
|
||
"settings.network.serverRoutes.label": {
|
||
"message": "サーバールートを有効にする"
|
||
},
|
||
"settings.network.serverRoutes.help": {
|
||
"message": "このホストのローカルルートを他のピアにアドバタイズします。"
|
||
},
|
||
"settings.network.ipv6.label": {
|
||
"message": "IPv6を有効にする"
|
||
},
|
||
"settings.network.ipv6.help": {
|
||
"message": "NetBird オーバーレイネットワークで IPv6 アドレッシングを使用します。"
|
||
},
|
||
"settings.security.section.firewall": {
|
||
"message": "ファイアウォール"
|
||
},
|
||
"settings.security.section.encryption": {
|
||
"message": "暗号化"
|
||
},
|
||
"settings.security.blockInbound.label": {
|
||
"message": "受信トラフィックをブロック"
|
||
},
|
||
"settings.security.blockInbound.help": {
|
||
"message": "このデバイスおよびこのデバイスがルーティングするネットワークへの、ピアからの要求されていない接続を拒否します。送信トラフィックには影響しません。"
|
||
},
|
||
"settings.security.blockLan.label": {
|
||
"message": "LANアクセスをブロック"
|
||
},
|
||
"settings.security.blockLan.help": {
|
||
"message": "このデバイスがピアのトラフィックをルーティングする際に、ピアがローカルネットワークやそのデバイスに到達できないようにします。"
|
||
},
|
||
"settings.security.rosenpass.label": {
|
||
"message": "量子耐性を有効にする"
|
||
},
|
||
"settings.security.rosenpass.help": {
|
||
"message": "WireGuard® に加えて Rosenpass によるポスト量子鍵交換を追加します。"
|
||
},
|
||
"settings.security.rosenpassPermissive.label": {
|
||
"message": "寛容モードを有効にする"
|
||
},
|
||
"settings.security.rosenpassPermissive.help": {
|
||
"message": "量子耐性に対応していないピアへの接続を許可します。"
|
||
},
|
||
"settings.ssh.section.server": {
|
||
"message": "サーバー"
|
||
},
|
||
"settings.ssh.section.capabilities": {
|
||
"message": "機能"
|
||
},
|
||
"settings.ssh.section.authentication": {
|
||
"message": "認証"
|
||
},
|
||
"settings.ssh.server.label": {
|
||
"message": "SSHサーバーを有効にする"
|
||
},
|
||
"settings.ssh.server.help": {
|
||
"message": "このホストで NetBird SSH サーバーを実行し、他のピアが接続できるようにします。"
|
||
},
|
||
"settings.ssh.root.label": {
|
||
"message": "rootログインを許可"
|
||
},
|
||
"settings.ssh.root.help": {
|
||
"message": "ピアが root ユーザーとしてサインインできるようにします。無効にすると非特権アカウントが必要になります。"
|
||
},
|
||
"settings.ssh.sftp.label": {
|
||
"message": "SFTPを許可"
|
||
},
|
||
"settings.ssh.sftp.help": {
|
||
"message": "ネイティブの SFTP または SCP クライアントを使用してファイルを安全に転送します。"
|
||
},
|
||
"settings.ssh.localForward.label": {
|
||
"message": "ローカルポート転送"
|
||
},
|
||
"settings.ssh.localForward.help": {
|
||
"message": "接続するピアが、このホストから到達可能なサービスへローカルポートをトンネリングできるようにします。"
|
||
},
|
||
"settings.ssh.remoteForward.label": {
|
||
"message": "リモートポート転送"
|
||
},
|
||
"settings.ssh.remoteForward.help": {
|
||
"message": "接続するピアが、このホスト上のポートを自身のマシンに公開できるようにします。"
|
||
},
|
||
"settings.ssh.jwt.label": {
|
||
"message": "JWT認証を有効にする"
|
||
},
|
||
"settings.ssh.jwt.help": {
|
||
"message": "各 SSH セッションを IdP に対して検証し、ユーザー ID と監査を行います。無効にするとネットワークの ACL ポリシーのみに依存します。IdP が利用できない場合に便利です。"
|
||
},
|
||
"settings.ssh.jwtTtl.label": {
|
||
"message": "JWTキャッシュTTL"
|
||
},
|
||
"settings.ssh.jwtTtl.help": {
|
||
"message": "発信 SSH 接続で再度認証を求めるまでに、このクライアントが JWT をキャッシュする期間です。0 に設定するとキャッシュを無効にし、接続ごとに認証します。"
|
||
},
|
||
"settings.ssh.jwtTtl.suffix": {
|
||
"message": "秒"
|
||
},
|
||
"settings.advanced.section.interface": {
|
||
"message": "インターフェース"
|
||
},
|
||
"settings.advanced.section.security": {
|
||
"message": "セキュリティ"
|
||
},
|
||
"settings.advanced.interfaceName.label": {
|
||
"message": "名前"
|
||
},
|
||
"settings.advanced.interfaceName.error": {
|
||
"message": "1〜15文字の英字、数字、ドット、ハイフン、アンダースコアを使用してください。"
|
||
},
|
||
"settings.advanced.interfaceName.errorMac": {
|
||
"message": "「utun」に続けて数字で始まる必要があります(例: utun100)。"
|
||
},
|
||
"settings.advanced.port.label": {
|
||
"message": "ポート"
|
||
},
|
||
"settings.advanced.port.error": {
|
||
"message": "{min}〜{max}の範囲でポートを入力してください。"
|
||
},
|
||
"settings.advanced.port.help": {
|
||
"message": "0 に設定すると、ランダムな空きポートが使用されます。"
|
||
},
|
||
"settings.advanced.mtu.label": {
|
||
"message": "MTU"
|
||
},
|
||
"settings.advanced.mtu.error": {
|
||
"message": "{min}〜{max}の範囲で MTU 値を入力してください。"
|
||
},
|
||
"settings.advanced.psk.label": {
|
||
"message": "事前共有鍵"
|
||
},
|
||
"settings.advanced.psk.help": {
|
||
"message": "追加の対称暗号化のためのオプションの WireGuard PSK です。NetBird セットアップキーとは異なります。同じ事前共有鍵を使用するピアとのみ通信できます。"
|
||
},
|
||
"settings.troubleshooting.section.title": {
|
||
"message": "デバッグバンドル"
|
||
},
|
||
"settings.troubleshooting.anonymize.label": {
|
||
"message": "機密情報を匿名化"
|
||
},
|
||
"settings.troubleshooting.anonymize.help": {
|
||
"message": "IP アドレス、ドメイン、その他の機密性の高い値を隠します。"
|
||
},
|
||
"settings.troubleshooting.anonymize.info": {
|
||
"message": "「デフォルト」では、サポートのために内部 IPv4 アドレスとピア名は読める状態のまま残ります。「厳格」では、さらにプライベート (RFC 1918)、CGNAT、リンクローカルの IP アドレス、ピア名、WireGuard 公開鍵も匿名化されます。繰り返し現れる値は同じプレースホルダーに置き換えられるため、ピアは区別できます。デバッグバンドルを組織外に共有する場合は「厳格」を使用してください。"
|
||
},
|
||
"settings.troubleshooting.anonymize.none": {
|
||
"message": "なし"
|
||
},
|
||
"settings.troubleshooting.anonymize.default": {
|
||
"message": "デフォルト"
|
||
},
|
||
"settings.troubleshooting.anonymize.strict": {
|
||
"message": "厳格"
|
||
},
|
||
"settings.troubleshooting.systemInfo.label": {
|
||
"message": "システム情報を含める"
|
||
},
|
||
"settings.troubleshooting.systemInfo.help": {
|
||
"message": "OS、カーネル、ネットワークインターフェース、ルーティングテーブルを含めます。"
|
||
},
|
||
"settings.troubleshooting.upload.label": {
|
||
"message": "バンドルを NetBird サーバーにアップロード"
|
||
},
|
||
"settings.troubleshooting.upload.help": {
|
||
"message": "NetBird サポートと共有するためのアップロードキーを返します。"
|
||
},
|
||
"settings.troubleshooting.trace.label": {
|
||
"message": "トレースログを有効にする"
|
||
},
|
||
"settings.troubleshooting.trace.help": {
|
||
"message": "ログレベルを TRACE に引き上げ、その後元に戻します。"
|
||
},
|
||
"settings.troubleshooting.capture.label": {
|
||
"message": "キャプチャセッション"
|
||
},
|
||
"settings.troubleshooting.capture.help": {
|
||
"message": "再接続して待機し、問題を再現できるようにします。"
|
||
},
|
||
"settings.troubleshooting.packets.label": {
|
||
"message": "ネットワークパケットをキャプチャ"
|
||
},
|
||
"settings.troubleshooting.packets.help": {
|
||
"message": "キャプチャ期間中のネットワークトラフィックを .pcap として保存します。"
|
||
},
|
||
"settings.troubleshooting.duration.label": {
|
||
"message": "キャプチャ時間"
|
||
},
|
||
"settings.troubleshooting.duration.help": {
|
||
"message": "キャプチャセッションを実行する時間です。"
|
||
},
|
||
"settings.troubleshooting.duration.suffix": {
|
||
"message": "分"
|
||
},
|
||
"settings.troubleshooting.create": {
|
||
"message": "バンドルを作成"
|
||
},
|
||
"settings.troubleshooting.progress.description": {
|
||
"message": "ログ、システムの詳細、接続状態を収集しています。通常はしばらくで完了します。完了するまで NetBird を使い続けても、設定を閉じても構いません。"
|
||
},
|
||
"settings.troubleshooting.cancelling": {
|
||
"message": "キャンセル中…"
|
||
},
|
||
"settings.troubleshooting.done.uploadedTitle": {
|
||
"message": "デバッグバンドルのアップロードに成功しました!"
|
||
},
|
||
"settings.troubleshooting.done.savedTitle": {
|
||
"message": "バンドルを保存しました"
|
||
},
|
||
"settings.troubleshooting.done.uploadedDescription": {
|
||
"message": "下記のアップロードキーを <docs>NetBird サポート</docs> と共有してください。ローカルコピーもお使いのデバイスに保存されました。"
|
||
},
|
||
"settings.troubleshooting.done.savedDescription": {
|
||
"message": "デバッグバンドルはローカルに保存されました。"
|
||
},
|
||
"settings.troubleshooting.done.copyKey": {
|
||
"message": "キーをコピー"
|
||
},
|
||
"settings.troubleshooting.done.openFolder": {
|
||
"message": "フォルダを開く"
|
||
},
|
||
"settings.troubleshooting.done.openFileLocation": {
|
||
"message": "ファイルの場所を開く"
|
||
},
|
||
"settings.troubleshooting.uploadFailedWithReason": {
|
||
"message": "アップロードに失敗しました: {reason} バンドルはローカルに保存されています。"
|
||
},
|
||
"settings.troubleshooting.uploadFailed": {
|
||
"message": "アップロードに失敗しました。バンドルはローカルに保存されています。"
|
||
},
|
||
"settings.troubleshooting.stage.reconnecting": {
|
||
"message": "NetBird を再接続しています…"
|
||
},
|
||
"settings.troubleshooting.stage.capturing": {
|
||
"message": "デバッグログをキャプチャしています"
|
||
},
|
||
"settings.troubleshooting.stage.bundling": {
|
||
"message": "デバッグバンドルを生成しています…"
|
||
},
|
||
"settings.troubleshooting.stage.uploading": {
|
||
"message": "NetBird にアップロードしています…"
|
||
},
|
||
"settings.troubleshooting.stage.cancelling": {
|
||
"message": "キャンセル中…"
|
||
},
|
||
"settings.about.client": {
|
||
"message": "NetBird Client v{version}"
|
||
},
|
||
"settings.about.clientName": {
|
||
"message": "NetBird Client"
|
||
},
|
||
"settings.about.development": {
|
||
"message": "[開発版]"
|
||
},
|
||
"settings.about.gui": {
|
||
"message": "GUI v{version}"
|
||
},
|
||
"settings.about.guiName": {
|
||
"message": "GUI"
|
||
},
|
||
"settings.about.copyright": {
|
||
"message": "© {year} NetBird. All Rights Reserved."
|
||
},
|
||
"settings.about.links.imprint": {
|
||
"message": "運営者情報"
|
||
},
|
||
"settings.about.links.privacy": {
|
||
"message": "プライバシー"
|
||
},
|
||
"settings.about.links.cla": {
|
||
"message": "CLA"
|
||
},
|
||
"settings.about.links.terms": {
|
||
"message": "利用規約"
|
||
},
|
||
"settings.about.community.github": {
|
||
"message": "GitHub"
|
||
},
|
||
"settings.about.community.slack": {
|
||
"message": "Slack"
|
||
},
|
||
"settings.about.community.forum": {
|
||
"message": "フォーラム"
|
||
},
|
||
"settings.about.community.documentation": {
|
||
"message": "ドキュメント"
|
||
},
|
||
"settings.about.community.feedback": {
|
||
"message": "フィードバック"
|
||
},
|
||
"update.banner.message": {
|
||
"message": "NetBird {version} をインストールする準備ができました。"
|
||
},
|
||
"update.banner.later": {
|
||
"message": "後で"
|
||
},
|
||
"update.banner.installNow": {
|
||
"message": "今すぐインストール"
|
||
},
|
||
"update.card.versionAvailableDownload": {
|
||
"message": "バージョン {version} がダウンロード可能です。"
|
||
},
|
||
"update.card.versionAvailableInstall": {
|
||
"message": "バージョン {version} がインストール可能です。"
|
||
},
|
||
"update.card.whatsNew": {
|
||
"message": "新機能は?"
|
||
},
|
||
"update.card.installNow": {
|
||
"message": "今すぐインストール"
|
||
},
|
||
"update.card.getInstaller": {
|
||
"message": "ダウンロード"
|
||
},
|
||
"update.card.autoCheckInterval": {
|
||
"message": "NetBird はバックグラウンドで更新を確認します。"
|
||
},
|
||
"update.card.changelog": {
|
||
"message": "変更履歴"
|
||
},
|
||
"update.card.onLatestVersion": {
|
||
"message": "最新バージョンを使用しています"
|
||
},
|
||
"update.header.tooltip": {
|
||
"message": "更新が利用可能"
|
||
},
|
||
"update.overlay.updatingVersion": {
|
||
"message": "NetBird を v{version} に更新しています"
|
||
},
|
||
"update.overlay.updating": {
|
||
"message": "NetBird を更新しています"
|
||
},
|
||
"update.overlay.description": {
|
||
"message": "新しいバージョンが利用可能で、インストール中です。更新が完了すると NetBird は自動的に再起動します。"
|
||
},
|
||
"update.overlay.error.timeoutTitle": {
|
||
"message": "更新に時間がかかっています"
|
||
},
|
||
"update.overlay.error.timeoutDescription": {
|
||
"message": "{target} のインストールに時間がかかりすぎ、完了しませんでした。"
|
||
},
|
||
"update.overlay.error.canceledTitle": {
|
||
"message": "更新が停止されました"
|
||
},
|
||
"update.overlay.error.canceledDescription": {
|
||
"message": "{target} への更新は完了前にキャンセルされました。"
|
||
},
|
||
"update.overlay.error.failTitle": {
|
||
"message": "更新をインストールできませんでした"
|
||
},
|
||
"update.overlay.error.failDescription": {
|
||
"message": "{target} をインストールできませんでした。"
|
||
},
|
||
"update.overlay.error.unknownMessage": {
|
||
"message": "不明なエラー"
|
||
},
|
||
"update.overlay.error.targetVersion": {
|
||
"message": "v{version}"
|
||
},
|
||
"update.overlay.error.targetFallback": {
|
||
"message": "新しいバージョン"
|
||
},
|
||
"update.error.loadStateTitle": {
|
||
"message": "更新状態の読み込みに失敗しました"
|
||
},
|
||
"update.error.triggerTitle": {
|
||
"message": "更新の開始に失敗しました"
|
||
},
|
||
"update.page.versionLine": {
|
||
"message": "クライアントを次のバージョンに更新しています: {version}。"
|
||
},
|
||
"update.page.versionLineGeneric": {
|
||
"message": "クライアントを更新しています。"
|
||
},
|
||
"update.page.outdated": {
|
||
"message": "クライアントのバージョンが、管理サーバーで設定された自動更新バージョンより古くなっています。"
|
||
},
|
||
"update.page.status.running": {
|
||
"message": "更新中"
|
||
},
|
||
"update.page.status.timeout": {
|
||
"message": "更新がタイムアウトしました。もう一度お試しください。"
|
||
},
|
||
"update.page.status.canceled": {
|
||
"message": "更新がキャンセルされました。"
|
||
},
|
||
"update.page.status.failed": {
|
||
"message": "更新に失敗しました: {message}"
|
||
},
|
||
"update.page.status.unknownError": {
|
||
"message": "不明な更新エラー"
|
||
},
|
||
"update.page.failedTitle": {
|
||
"message": "更新に失敗しました"
|
||
},
|
||
"update.page.timeoutMessage": {
|
||
"message": "更新がタイムアウトしました。"
|
||
},
|
||
"update.page.dontClose": {
|
||
"message": "このウィンドウを閉じないでください。"
|
||
},
|
||
"update.page.updating": {
|
||
"message": "更新中…"
|
||
},
|
||
"update.page.complete": {
|
||
"message": "更新が完了しました"
|
||
},
|
||
"update.page.failed": {
|
||
"message": "更新に失敗しました"
|
||
},
|
||
"window.title.settings": {
|
||
"message": "設定"
|
||
},
|
||
"window.title.signIn": {
|
||
"message": "サインイン"
|
||
},
|
||
"window.title.sessionExpiration": {
|
||
"message": "セッションの期限切れ"
|
||
},
|
||
"window.title.updating": {
|
||
"message": "更新中"
|
||
},
|
||
"window.title.welcome": {
|
||
"message": "NetBird へようこそ"
|
||
},
|
||
"window.title.error": {
|
||
"message": "エラー"
|
||
},
|
||
"welcome.title": {
|
||
"message": "トレイの NetBird を確認してください"
|
||
},
|
||
"welcome.titleMac": {
|
||
"message": "メニューバーの NetBird を確認してください"
|
||
},
|
||
"welcome.description": {
|
||
"message": "NetBird はトレイに常駐します。アイコンをクリックして、接続、プロファイルの切り替え、設定を開くことができます。"
|
||
},
|
||
"welcome.descriptionMac": {
|
||
"message": "NetBird はメニューバーに常駐します。アイコンをクリックして、接続、プロファイルの切り替え、設定を開くことができます。"
|
||
},
|
||
"welcome.continue": {
|
||
"message": "続ける"
|
||
},
|
||
"welcome.back": {
|
||
"message": "戻る"
|
||
},
|
||
"welcome.management.title": {
|
||
"message": "NetBird をセットアップ"
|
||
},
|
||
"welcome.management.description": {
|
||
"message": "「続ける」をクリックして開始するか、独自の NetBird サーバーをお持ちの場合は「セルフホスト」を選択してください。"
|
||
},
|
||
"welcome.management.cloud.title": {
|
||
"message": "NetBird Cloud"
|
||
},
|
||
"welcome.management.cloud.description": {
|
||
"message": "当社のホスト型サービスを使用します。セットアップは不要です。"
|
||
},
|
||
"welcome.management.selfHosted.title": {
|
||
"message": "セルフホスト"
|
||
},
|
||
"welcome.management.selfHosted.description": {
|
||
"message": "独自の管理サーバーに接続します。"
|
||
},
|
||
"welcome.management.urlLabel": {
|
||
"message": "管理サーバーのURL"
|
||
},
|
||
"welcome.management.urlPlaceholder": {
|
||
"message": "https://netbird.selfhosted.com:443"
|
||
},
|
||
"welcome.management.urlInvalid": {
|
||
"message": "有効なURLを入力してください(例: https://netbird.selfhosted.com:443)"
|
||
},
|
||
"welcome.management.urlUnreachable": {
|
||
"message": "このサーバーに到達できませんでした。URLまたはネットワークを確認し、正しいことが確実な場合は続行してください。"
|
||
},
|
||
"welcome.management.checking": {
|
||
"message": "確認中…"
|
||
},
|
||
"browserLogin.title": {
|
||
"message": "ブラウザでログインを完了してください"
|
||
},
|
||
"browserLogin.notSeeing": {
|
||
"message": "サインインを完了できるようブラウザのタブを開きました。表示されませんか?"
|
||
},
|
||
"browserLogin.tryAgain": {
|
||
"message": "再試行"
|
||
},
|
||
"browserLogin.openFailedTitle": {
|
||
"message": "ブラウザの起動に失敗しました"
|
||
},
|
||
"sessionExpiration.title": {
|
||
"message": "まもなくセッションが期限切れになります"
|
||
},
|
||
"sessionExpiration.titleLater": {
|
||
"message": "セッションが期限切れになります"
|
||
},
|
||
"sessionExpiration.description": {
|
||
"message": "このデバイスはまもなく切断されます。ブラウザでのサインインで更新してください。"
|
||
},
|
||
"sessionExpiration.descriptionLater": {
|
||
"message": "ブラウザでサインインすると、このデバイスがネットワークに接続されたままになります。"
|
||
},
|
||
"sessionExpiration.stay": {
|
||
"message": "セッションを更新"
|
||
},
|
||
"sessionExpiration.authenticate": {
|
||
"message": "認証"
|
||
},
|
||
"sessionExpiration.logout": {
|
||
"message": "ログアウト"
|
||
},
|
||
"sessionExpiration.expired": {
|
||
"message": "セッションが期限切れになりました"
|
||
},
|
||
"sessionExpiration.expiredDescription": {
|
||
"message": "デバイスが切断されました。再接続するにはブラウザでサインインして認証してください。"
|
||
},
|
||
"sessionExpiration.close": {
|
||
"message": "閉じる"
|
||
},
|
||
"sessionExpiration.extendFailedTitle": {
|
||
"message": "セッションの延長に失敗しました"
|
||
},
|
||
"sessionExpiration.logoutFailedTitle": {
|
||
"message": "ログアウトに失敗しました"
|
||
},
|
||
"peers.search.placeholder": {
|
||
"message": "名前または IP で検索"
|
||
},
|
||
"peers.filter.all": {
|
||
"message": "すべて"
|
||
},
|
||
"peers.filter.online": {
|
||
"message": "オンライン"
|
||
},
|
||
"peers.filter.offline": {
|
||
"message": "オフライン"
|
||
},
|
||
"peers.empty.title": {
|
||
"message": "利用可能なピアがありません"
|
||
},
|
||
"peers.empty.description": {
|
||
"message": "利用可能なピアがないか、いずれのピアにもアクセス権がありません。"
|
||
},
|
||
"peers.details.domain": {
|
||
"message": "ドメイン"
|
||
},
|
||
"peers.details.netbirdIp": {
|
||
"message": "NetBird IP"
|
||
},
|
||
"peers.details.netbirdIpv6": {
|
||
"message": "NetBird IPv6"
|
||
},
|
||
"peers.details.publicKey": {
|
||
"message": "公開鍵"
|
||
},
|
||
"peers.details.connection": {
|
||
"message": "接続"
|
||
},
|
||
"peers.details.latency": {
|
||
"message": "レイテンシ"
|
||
},
|
||
"peers.details.lastHandshake": {
|
||
"message": "最終ハンドシェイク"
|
||
},
|
||
"peers.details.statusSince": {
|
||
"message": "最終接続更新"
|
||
},
|
||
"peers.details.bytes": {
|
||
"message": "バイト"
|
||
},
|
||
"peers.details.bytesSent": {
|
||
"message": "送信"
|
||
},
|
||
"peers.details.bytesReceived": {
|
||
"message": "受信"
|
||
},
|
||
"peers.details.localIce": {
|
||
"message": "ローカル ICE"
|
||
},
|
||
"peers.details.remoteIce": {
|
||
"message": "リモート ICE"
|
||
},
|
||
"peers.details.never": {
|
||
"message": "なし"
|
||
},
|
||
"peers.details.justNow": {
|
||
"message": "たった今"
|
||
},
|
||
"peers.details.refresh": {
|
||
"message": "更新"
|
||
},
|
||
"peers.status.connected": {
|
||
"message": "接続済み"
|
||
},
|
||
"peers.status.connecting": {
|
||
"message": "接続中"
|
||
},
|
||
"peers.status.disconnected": {
|
||
"message": "未接続"
|
||
},
|
||
"peers.details.relayAddress": {
|
||
"message": "リレー"
|
||
},
|
||
"peers.details.networks": {
|
||
"message": "リソース"
|
||
},
|
||
"peers.details.relayed": {
|
||
"message": "リレー経由"
|
||
},
|
||
"peers.details.p2p": {
|
||
"message": "P2P"
|
||
},
|
||
"peers.details.rosenpass": {
|
||
"message": "Rosenpass 有効"
|
||
},
|
||
"networks.search.placeholder": {
|
||
"message": "ネットワークまたはドメインで検索"
|
||
},
|
||
"networks.filter.all": {
|
||
"message": "すべて"
|
||
},
|
||
"networks.filter.active": {
|
||
"message": "有効"
|
||
},
|
||
"networks.filter.overlapping": {
|
||
"message": "重複"
|
||
},
|
||
"networks.empty.title": {
|
||
"message": "利用可能なリソースがありません"
|
||
},
|
||
"networks.empty.description": {
|
||
"message": "利用可能なネットワークリソースがないか、いずれのリソースにもアクセス権がありません。"
|
||
},
|
||
"networks.selected": {
|
||
"message": "選択中"
|
||
},
|
||
"networks.unselected": {
|
||
"message": "未選択"
|
||
},
|
||
"networks.ips.heading": {
|
||
"message": "解決された IP"
|
||
},
|
||
"networks.bulk.selectionCount": {
|
||
"message": "{total}件中{selected}件有効"
|
||
},
|
||
"networks.bulk.enableAll": {
|
||
"message": "すべて有効化"
|
||
},
|
||
"networks.bulk.disableAll": {
|
||
"message": "すべて無効化"
|
||
},
|
||
"exitNodes.search.placeholder": {
|
||
"message": "出口ノードを検索"
|
||
},
|
||
"exitNodes.none": {
|
||
"message": "なし"
|
||
},
|
||
"exitNodes.empty.title": {
|
||
"message": "利用可能な出口ノードがありません"
|
||
},
|
||
"exitNodes.empty.description": {
|
||
"message": "このピアと共有されている出口ノードはありません。"
|
||
},
|
||
"exitNodes.card.title": {
|
||
"message": "出口ノード"
|
||
},
|
||
"exitNodes.card.statusActive": {
|
||
"message": "有効"
|
||
},
|
||
"exitNodes.card.statusInactive": {
|
||
"message": "無効"
|
||
},
|
||
"exitNodes.dropdown.noneTitle": {
|
||
"message": "なし"
|
||
},
|
||
"exitNodes.dropdown.noneDescription": {
|
||
"message": "出口ノードを使用しない直接接続"
|
||
},
|
||
"quickActions.connect": {
|
||
"message": "接続"
|
||
},
|
||
"quickActions.disconnect": {
|
||
"message": "切断"
|
||
},
|
||
"daemon.unavailable.title": {
|
||
"message": "NetBird サービスが実行されていません"
|
||
},
|
||
"daemon.unavailable.description": {
|
||
"message": "サービスが実行されると、アプリは自動的に再接続します。"
|
||
},
|
||
"daemon.unavailable.docsLink": {
|
||
"message": "ドキュメント"
|
||
},
|
||
"daemon.outdated.title": {
|
||
"message": "NetBird サービスが古くなっています"
|
||
},
|
||
"daemon.outdated.description": {
|
||
"message": "このアプリを使用するには NetBird サービスを更新してください。"
|
||
},
|
||
"daemon.outdated.download": {
|
||
"message": "最新版をダウンロード"
|
||
},
|
||
"error.jwt_clock_skew": {
|
||
"message": "サインインに失敗しました: このデバイスの時計がサーバーと同期していません。システムの時計を同期してからもう一度お試しください。"
|
||
},
|
||
"error.jwt_expired": {
|
||
"message": "サインイントークンの有効期限が切れました。もう一度サインインしてください。"
|
||
},
|
||
"error.jwt_signature_invalid": {
|
||
"message": "サインインに失敗しました: トークンの署名が無効です。管理者にお問い合わせください。"
|
||
},
|
||
"error.session_expired": {
|
||
"message": "セッションの有効期限が切れました。もう一度サインインしてください。"
|
||
},
|
||
"error.invalid_setup_key": {
|
||
"message": "セットアップキーがないか、無効です。"
|
||
},
|
||
"error.permission_denied": {
|
||
"message": "サインインがサーバーによって拒否されました。"
|
||
},
|
||
"error.daemon_unreachable": {
|
||
"message": "NetBird デーモンが応答していません。サービスが実行されているか確認してください。"
|
||
},
|
||
"error.settings_locked": {
|
||
"message": "この端末では設定を変更できません。管理者によってロックされています。"
|
||
},
|
||
"error.settings_managed_by_mdm": {
|
||
"message": "この設定は組織によって管理されているため、変更できません。"
|
||
},
|
||
"error.unknown": {
|
||
"message": "操作に失敗しました。"
|
||
},
|
||
"error.elevation_unavailable": {
|
||
"message": "NetBird はこのシステムに必要な権限を要求できませんでした。代わりに次のコマンドを実行してください:"
|
||
},
|
||
"error.elevation_failed": {
|
||
"message": "昇格した権限でも変更を適用できませんでした。代わりに次のコマンドを実行してください:"
|
||
},
|
||
"settings.ssh.privilege.actorRoot": {
|
||
"message": "root 権限"
|
||
},
|
||
"settings.ssh.privilege.actorAdministrator": {
|
||
"message": "管理者権限"
|
||
},
|
||
"settings.ssh.privilege.hint": {
|
||
"message": "{actor}が必要です。代わりに次のコマンドを実行してください:"
|
||
},
|
||
"settings.ssh.privilege.oneWay": {
|
||
"message": "無効にはできますが、再度有効にするには{actor}が必要です。"
|
||
},
|
||
"settings.ssh.privilege.oneWayInverted": {
|
||
"message": "有効にはできますが、再度無効にするには{actor}が必要です。"
|
||
},
|
||
"settings.ssh.privilege.authorizePending": {
|
||
"message": "承認を待っています…"
|
||
}
|
||
}
|