feat(workspace): sealed-area names are confidential by default
Some checks failed
Security / Security check (push) Failing after 2s
Some checks failed
Security / Security check (push) Failing after 2s
The switcher listed sealed areas by name ('lbs', 'stromnetz') on
any glance or screenshot — but the names themselves often carry
client/mandate identity (usertest security finding). The sealed
section now renders one aggregated row ('2 sealed areas') with a
deliberate 'Show names' reveal per menu opening; selection still
pops the regular s:<slug> value. Settings -> Security gains 'list
sealed areas with their names right away' (WorkspacePrefs,
SidebarPrefs pattern, default off).
The aggregate row wraps to two lines — popup menus cap their
width and action texts must never be truncated (the first cut
showed '1 abgeschotte…' in the proof shot). Guard: switcher tests
cover aggregated-until-reveal and the Settings toggle; the old
direct-listing test now asserts the reveal contract. DE+EN.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
parent
ed680c507a
commit
588f437395
11 changed files with 370 additions and 41 deletions
|
|
@ -5545,6 +5545,30 @@ abstract class AppLocalizations {
|
|||
/// **'SEALED AREAS'**
|
||||
String get workspaceSealedHeader;
|
||||
|
||||
/// No description provided for @workspaceSealedAggregate.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'{n, plural, =1{1 sealed area} other{{n} sealed areas}}'**
|
||||
String workspaceSealedAggregate(int n);
|
||||
|
||||
/// No description provided for @workspaceSealedRevealAction.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Show names'**
|
||||
String get workspaceSealedRevealAction;
|
||||
|
||||
/// No description provided for @settingsSealedNamesTitle.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'List sealed areas with their names right away'**
|
||||
String get settingsSealedNamesTitle;
|
||||
|
||||
/// No description provided for @settingsSealedNamesBody.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Area names can be sensitive (client/mandate identity). By default the workspace switcher shows them aggregated; the names appear only after a click.'**
|
||||
String get settingsSealedNamesBody;
|
||||
|
||||
/// No description provided for @workspaceSealedRunning.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue