Add Roles to Administration, with Stalwart's permissions in every language
A role is a named set of permissions given to accounts, groups and tenants. It gets its own section under a new Access heading: every role listed with the permissions it grants once its bases are followed, and a panel to create, edit and delete one. A role builds on others and has everything they grant; a denial anywhere in the tree wins, which is how Stalwart resolves it (permissions.rs unions enabled and disabled across the tree, then subtracts). The picker is Stalwart's own list of permissions, under its headings, searchable and filterable to what is granted or set here. Each permission is not set, allowed or denied, and one that is inherited says which role it comes from. Only permissions the viewer holds can be allowed, because Stalwart refuses the rest, and a role carrying anything the viewer lacks opens read-only with no delete, because Stalwart checks a grant but not a delete. Saving sends a pointer for each permission and base role that changed. The roles Stalwart hands out by default, read from x:Authentication, say so before they are changed and cannot be deleted here; a role still in use is kept by the server, and the refusal names what uses it. The permission list is Stalwart's schema. A new route, GET /api/admin/permissions, fetches /api/schema as the signed-in account and returns only names and labels, behind the same two gates as the registry methods and held in memory for an hour. Its labels are English only, so every one of the 661 has a translation in each of the eight other languages, in its own file keyed by permission name and loaded only when Roles opens. A permission a later Stalwart adds shows its English label. A test holds every language to the 0.16.22 snapshot: nothing missing, nothing stale. The mock answers x:Role/set with the grant check, loops and in-use refusals, reads the defaults from x:Authentication, and serves the schema gzipped as the real one is. Fifty-two new strings and two plurals in all nine catalogues, and 661 permission labels with 59 headings in each of the eight translations.
This commit is contained in:
@@ -204,6 +204,58 @@ export const catalog: Catalog = {
|
||||
"Your organisation has reached the number of mailing lists it is allowed.": "Votre organisation a atteint le nombre de listes de diffusion autorisé.",
|
||||
"This mailing list no longer exists. Someone may have deleted it.": "Cette liste de diffusion n’existe plus. Quelqu’un l’a peut-être supprimée.",
|
||||
"The server did not say whether the list was created.": "Le serveur n’a pas indiqué si la liste a été créée.",
|
||||
"Roles": "Rôles",
|
||||
"users": "utilisateurs",
|
||||
"groups": "groupes",
|
||||
"tenant administrators": "administrateurs de locataire",
|
||||
"administrators": "administrateurs",
|
||||
"A role needs a name.": "Un rôle a besoin d’un nom.",
|
||||
"Created {name}": "{name} créé",
|
||||
"New role": "Nouveau rôle",
|
||||
"This role carries permissions yours doesn't, so you can view it but not change it.": "Ce rôle comporte des autorisations que le vôtre n’a pas : vous pouvez le consulter, mais pas le modifier.",
|
||||
"Your role lets you view roles but not change them.": "Votre rôle vous permet de consulter les rôles, mais pas de les modifier.",
|
||||
"Stalwart gives this role by default to {kinds}. A change here reaches everyone who has it that way.": "Stalwart attribue ce rôle par défaut aux {kinds}. Une modification ici touche tous ceux qui l’ont de cette façon.",
|
||||
"Builds on": "S’appuie sur",
|
||||
"Permissions": "Autorisations",
|
||||
"Stalwart gives this role by default, so it can't be deleted. Change the defaults in Stalwart's own administration first.": "Stalwart attribue ce rôle par défaut, il ne peut donc pas être supprimé. Modifiez d’abord les valeurs par défaut dans l’administration de Stalwart.",
|
||||
"This role carries permissions yours doesn't.": "Ce rôle comporte des autorisations que le vôtre n’a pas.",
|
||||
"Create role": "Créer le rôle",
|
||||
"builds on this one": "s’appuie sur celui-ci",
|
||||
"has permissions yours doesn't": "a des autorisations que le vôtre n’a pas",
|
||||
"No other roles": "Aucun autre rôle",
|
||||
"A role has every permission of the roles it builds on, apart from any it or they deny.": "Un rôle a toutes les autorisations des rôles sur lesquels il s’appuie, sauf celles que lui ou eux refusent.",
|
||||
"Search permissions": "Rechercher des autorisations",
|
||||
"All permissions": "Toutes les autorisations",
|
||||
"Granted": "Accordées",
|
||||
"Set on this role": "Définies sur ce rôle",
|
||||
"No permissions match": "Aucune autorisation ne correspond",
|
||||
"{granted} of {total}": "{granted} sur {total}",
|
||||
"Denied by {role}": "Refusée par {role}",
|
||||
"Granted by {role}": "Accordée par {role}",
|
||||
"Inherit": "Hériter",
|
||||
"Not set": "Non défini",
|
||||
"Allow": "Autoriser",
|
||||
"Deny": "Refuser",
|
||||
"A denial wins over anything allowed, here or on a role this one builds on. You can only allow permissions you hold yourself.": "Un refus l’emporte sur toute autorisation, ici ou sur un rôle sur lequel celui-ci s’appuie. Vous ne pouvez autoriser que les autorisations que vous détenez vous-même.",
|
||||
"Accounts, groups and other roles that use it must be moved off it first.": "Les comptes, groupes et autres rôles qui l’utilisent doivent d’abord en être détachés.",
|
||||
"Delete role…": "Supprimer le rôle…",
|
||||
"Deleted {name}": "{name} supprimé",
|
||||
"Still used by {things}. Move them to another role first.": "Encore utilisé par {things}. Attribuez-leur d’abord un autre rôle.",
|
||||
"Delete role": "Supprimer le rôle",
|
||||
"It can't be undone.": "C’est irréversible.",
|
||||
"Type {name} to confirm": "Saisissez {name} pour confirmer",
|
||||
"Stalwart's list of permissions could not be loaded, so permissions can't be changed here. ({reason})": "La liste des autorisations de Stalwart n’a pas pu être chargée : les autorisations ne peuvent donc pas être modifiées ici. ({reason})",
|
||||
"Named sets of permissions, given to accounts, groups and tenants.": "Des ensembles nommés d’autorisations, attribués aux comptes, groupes et locataires.",
|
||||
"Search roles": "Rechercher des rôles",
|
||||
"No roles match": "Aucun rôle ne correspond",
|
||||
"No roles yet": "Aucun rôle pour l’instant",
|
||||
"Open {name}": "Ouvrir {name}",
|
||||
"Default for {kinds}": "Par défaut pour les {kinds}",
|
||||
"You can't give a role permissions your own role doesn't have.": "Vous ne pouvez pas donner à un rôle des autorisations que votre propre rôle n’a pas.",
|
||||
"Your organisation has reached the number of roles it is allowed.": "Votre organisation a atteint le nombre de rôles autorisé.",
|
||||
"This role no longer exists. Someone may have deleted it.": "Ce rôle n’existe plus. Quelqu’un l’a peut-être supprimé.",
|
||||
"the default roles": "les rôles par défaut",
|
||||
"The server did not say whether the role was created.": "Le serveur n’a pas indiqué si le rôle a été créé.",
|
||||
"User": "Utilisateur",
|
||||
"Administrator": "Administrateur",
|
||||
"Custom role": "Rôle personnalisé",
|
||||
@@ -1600,6 +1652,8 @@ export const catalog: Catalog = {
|
||||
"Its {n} members are taken out of the group first, and lose what was shared with it. The group's own mail is removed in the background, and it can't be undone.": { one: "Son {n} membre est d’abord retiré du groupe et perd ce qui était partagé avec lui. Les messages du groupe sont supprimés en arrière-plan, et c’est irréversible.", other: "Ses {n} membres sont d’abord retirés du groupe et perdent ce qui était partagé avec lui. Les messages du groupe sont supprimés en arrière-plan, et c’est irréversible." },
|
||||
"{n} mailing lists": { one: "{n} liste de diffusion", other: "{n} listes de diffusion" },
|
||||
"{n} recipients": { one: "{n} destinataire", other: "{n} destinataires" },
|
||||
"Grants {n} permissions": { one: "Accorde {n} autorisation", other: "Accorde {n} autorisations" },
|
||||
"{n} roles": { one: "{n} rôle", other: "{n} rôles" },
|
||||
"{n} DKIM keys": { one: "{n} clé DKIM", other: "{n} clés DKIM" },
|
||||
"{n} other items": { one: "{n} autre élément", other: "{n} autres éléments" },
|
||||
// ── Administration ────────────────────────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user