feat: guided setup — persona re-audit fixes (grade-1 round)
- Regulated path finishes without a terminal: the signed-source state offers 'Add a signed source…' (stores dialog with pin-a-key) plus the per-module install buttons and a plain-language hint why pinning the publisher's key matters — instead of a hint with no affordance. - Apply warnings (e.g. the empty-trusted-publishers caveat) surface selectable in the done state instead of being swallowed. - Truthful preview: new lines state which machine is being set up (server/container targets configure THIS machine), that regulated profiles always get the hash-chained audit log (even with WORM off), and that the curated reading list is stored with the setup record. - Language pass: onboarding checklist in Sie-form + 'System-KI' (was du-form + 'System-AI'), 'Audit-Sperre' jargon replaced, answers file moved to a private per-dialog temp dir. - Screenshot harness: GUIDE_SHOTS_THEME=light for light-parity proof runs. Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
This commit is contained in:
parent
cf4024a4e2
commit
ddac84ce8e
9 changed files with 308 additions and 33 deletions
|
|
@ -72,14 +72,14 @@
|
|||
},
|
||||
"welcomeChecklistHeader": "ERSTE SCHRITTE",
|
||||
"welcomeChecklistBody": "Vier Schritte zu einem funktionierenden Hub. Live-Zustand — nach jeder Änderung aktualisieren.",
|
||||
"welcomeChecklistAi": "System-AI konfigurieren",
|
||||
"welcomeChecklistAiHint": "Einstellungen → System-AI. Wird für die KI-Suche und Fehlererklärungen gebraucht.",
|
||||
"welcomeChecklistAi": "System-KI konfigurieren",
|
||||
"welcomeChecklistAiHint": "Einstellungen → System-KI. Wird für die KI-Suche und Fehlererklärungen gebraucht.",
|
||||
"welcomeChecklistMcp": "Öffentliche Capability-Quelle hinzufügen",
|
||||
"welcomeChecklistMcpHint": "Im Store eine MCP-Quelle hinzufügen oder unter Einstellungen → MCP-Clients konfigurieren.",
|
||||
"welcomeChecklistModule": "Ein Text-Modul installieren",
|
||||
"welcomeChecklistModuleHint": "Im Store ein Modul aus der Kategorie deiner Wahl installieren. Module sind sandboxed Ch∆In-Komponenten.",
|
||||
"welcomeChecklistModuleHint": "Im Store ein Modul aus der Kategorie Ihrer Wahl installieren. Module sind isolierte (sandboxed) Ch∆In-Komponenten.",
|
||||
"welcomeChecklistFlow": "Einen gespeicherten Flow starten",
|
||||
"welcomeChecklistFlowHint": "Flows → einen wählen → Starten. Studio bringt einige Demo-Flows mit; auch ein eigener tut's.",
|
||||
"welcomeChecklistFlowHint": "Flows → einen wählen → Starten. Studio bringt einige Demo-Flows mit; ein eigener funktioniert genauso.",
|
||||
"welcomeChecklistAllDone": "Alle vier Schritte erledigt.",
|
||||
"welcomeChecklistDismiss": "Checkliste ausblenden",
|
||||
"welcomeChecklistRefresh": "Aktualisieren",
|
||||
|
|
@ -886,16 +886,16 @@
|
|||
"maintenanceResetConfirmTitle": "Hub zurücksetzen?",
|
||||
"maintenanceResetConfirmBody": "Stoppt jeden Daemon, verschiebt ~/.chain/ in ein Backup mit Zeitstempel und startet sauber neu. Das Backup ist vollständig wiederherstellbar. Fortfahren?",
|
||||
"maintenanceResetConfirmButton": "Zurücksetzen",
|
||||
"welcomeChecklistAllSetTitle": "Du bist eingerichtet.",
|
||||
"welcomeChecklistAllSetBody": "Drei Stränge, an denen du als nächstes ziehen kannst:",
|
||||
"welcomeChecklistAllSetTitle": "Sie sind eingerichtet.",
|
||||
"welcomeChecklistAllSetBody": "Drei Stränge, an denen Sie als Nächstes ziehen können:",
|
||||
"welcomeChecklistNextAuditTitle": "Audit-Log lesen",
|
||||
"welcomeChecklistNextAuditBody": "Jede Installation, jeder Flow-Lauf, jede Freigabe landet im hash-verketteten Log. Im Protokoll-Tab siehst du, was dein Hub gemacht hat.",
|
||||
"welcomeChecklistNextAuditBody": "Jede Installation, jeder Flow-Lauf, jede Freigabe landet im hash-verketteten Protokoll. Im Protokoll-Tab sehen Sie, was Ihr Hub gemacht hat.",
|
||||
"welcomeChecklistNextAuditButton": "Protokoll öffnen",
|
||||
"welcomeChecklistNextTodayTitle": "Daily-Today-Story einrichten",
|
||||
"welcomeChecklistNextTodayBody": "tools/today/propose.sh per Cron laufen lassen und die Editorial-Karte im Store füllt sich mit operator-kuratierten Stories.",
|
||||
"welcomeChecklistNextTodayButton": "Today-Doku öffnen",
|
||||
"welcomeChecklistNextModuleTitle": "Eigenes Modul bauen",
|
||||
"welcomeChecklistNextModuleBody": "Mit `chain new module <name>` ein Rust+WASM-Scaffold erzeugen. Das module-sdk übernimmt die WIT-Plumbing; du schreibst nur ein typisiertes invoke.",
|
||||
"welcomeChecklistNextModuleBody": "Mit `chain new module <name>` ein Rust+WASM-Gerüst erzeugen. Das module-sdk übernimmt die WIT-Anbindung; Sie schreiben nur ein typisiertes invoke.",
|
||||
"welcomeChecklistNextModuleButton": "Doku lesen",
|
||||
"auditGroupToday": "HEUTE",
|
||||
"auditGroupYesterday": "GESTERN",
|
||||
|
|
@ -1704,7 +1704,7 @@
|
|||
"setupReviewTitle": "Das wird Ch∆In einrichten",
|
||||
"setupChooseFreeText": "Oder beschreiben Sie einfach, was Sie vorhaben",
|
||||
"setupScenTryingOut": "Erst mal ausprobieren",
|
||||
"setupScenTryingOutSub": "Ein unkomplizierter Arbeitsplatz auf diesem Rechner — ohne Signaturen, ohne Audit-Sperre.",
|
||||
"setupScenTryingOutSub": "Ein unkomplizierter Arbeitsplatz auf diesem Rechner — ohne Signaturpflicht, ohne Schreibschutz für das Prüfprotokoll.",
|
||||
"setupScenTeamHub": "Ein Team-Server",
|
||||
"setupScenTeamHubSub": "Ein abgesicherter Hub für mehrere Personen — signierte Module, Ressourcen-Grenzen.",
|
||||
"setupScenRegulated": "Regulierter Produktivbetrieb",
|
||||
|
|
@ -1761,6 +1761,16 @@
|
|||
"setupAllowUnsigned": "Installation aus dem öffentlichen Store erlauben",
|
||||
"setupAllowUnsignedSub": "Lockert die Signaturpflicht bewusst. Gut zum Ausprobieren — für den regulierten Betrieb später wieder aktivieren.",
|
||||
"setupStartCta": "In 3 Fragen loslegen",
|
||||
"setupPlanRunbookLocal": "Eingerichtet wird dieser Rechner; der Hub läuft lokal und wird bei Bedarf gestartet.",
|
||||
"setupPlanRunbookService": "Eingerichtet wird dieser Rechner: Der Hub startet künftig automatisch beim Hochfahren (Hintergrund-Dienst). Für einen anderen Server führen Sie die Einrichtung dort aus.",
|
||||
"setupPlanRunbookAirgap": "Vorgesehen für einen isolierten Server ohne Internet — Module und Updates kommen als Offline-Paket.",
|
||||
"setupPlanRunbookContainer": "Vorgesehen für den Betrieb im Container — ein fertiges Compose-Beispiel wird mitgeliefert.",
|
||||
"setupPlanAuditChain": "Jeder Schritt landet in einem lückenlosen, hash-verketteten Prüfprotokoll — Manipulation wird erkennbar.",
|
||||
"setupPlanDocs": "Eine passende Leseliste ({n} Kapitel) wird mit dem Einrichtungs-Protokoll unter ~/.chain/ gespeichert.",
|
||||
"@setupPlanDocs": {"placeholders": {"n": {"type": "int"}}},
|
||||
"setupTrustedPublishersHint": "Wichtig: Hinterlegen Sie beim Hinzufügen der Quelle den Schlüssel des Herausgebers („Signatur-Schlüssel anheften“) — sonst akzeptiert der Hub jede formal gültige Signatur, egal von wem.",
|
||||
"setupAddSignedSource": "Signierte Quelle hinzufügen…",
|
||||
"setupApplyNotes": "Hinweise aus der Einrichtung",
|
||||
"setupFreeTextHint": "z. B.: Eingehende Anträge vorprüfen und unvollständige markieren",
|
||||
"setupFreeTextSuggest": "Vorschlagen lassen",
|
||||
"setupFreeTextPrivacyLocal": "Ihre Beschreibung wird lokal auf diesem Rechner verarbeitet ({model}).",
|
||||
|
|
|
|||
|
|
@ -1743,7 +1743,7 @@
|
|||
"setupReviewTitle": "This is what Ch∆In will set up",
|
||||
"setupChooseFreeText": "Or just describe what you want to do",
|
||||
"setupScenTryingOut": "Just trying it out",
|
||||
"setupScenTryingOutSub": "A relaxed workspace on this machine — no signing, no audit locking.",
|
||||
"setupScenTryingOutSub": "A straightforward workstation on this machine — no signature requirement, no write-protected audit log.",
|
||||
"setupScenTeamHub": "A shared team hub",
|
||||
"setupScenTeamHubSub": "A secured hub for several people — signed modules, resource limits.",
|
||||
"setupScenRegulated": "Regulated production",
|
||||
|
|
@ -1800,6 +1800,16 @@
|
|||
"setupAllowUnsigned": "Allow installing from the public store",
|
||||
"setupAllowUnsignedSub": "Deliberately relaxes the signature requirement. Fine for trying things out — re-enable it for regulated operation.",
|
||||
"setupStartCta": "Get started in 3 questions",
|
||||
"setupPlanRunbookLocal": "This machine is being set up; the hub runs locally and starts on demand.",
|
||||
"setupPlanRunbookService": "This machine is being set up: the hub will start automatically on boot (background service). For a different server, run the setup there.",
|
||||
"setupPlanRunbookAirgap": "Intended for an isolated server without internet — modules and updates arrive as offline bundles.",
|
||||
"setupPlanRunbookContainer": "Intended for container operation — a ready-made compose example is included.",
|
||||
"setupPlanAuditChain": "Every step lands in a gapless, hash-chained audit log — tampering becomes detectable.",
|
||||
"setupPlanDocs": "A matching reading list ({n} chapters) is stored with the setup record under ~/.chain/.",
|
||||
"@setupPlanDocs": {"placeholders": {"n": {"type": "int"}}},
|
||||
"setupTrustedPublishersHint": "Important: when adding the source, pin the publisher's key (\"pin signing key\") — otherwise the hub accepts any formally valid signature, no matter whose.",
|
||||
"setupAddSignedSource": "Add a signed source…",
|
||||
"setupApplyNotes": "Notes from the setup",
|
||||
"setupFreeTextHint": "e.g.: pre-screen incoming applications and flag incomplete ones",
|
||||
"setupFreeTextSuggest": "Suggest a setup",
|
||||
"setupFreeTextPrivacyLocal": "Your description is processed locally on this machine ({model}).",
|
||||
|
|
|
|||
|
|
@ -5092,7 +5092,7 @@ abstract class AppLocalizations {
|
|||
/// No description provided for @setupScenTryingOutSub.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'A relaxed workspace on this machine — no signing, no audit locking.'**
|
||||
/// **'A straightforward workstation on this machine — no signature requirement, no write-protected audit log.'**
|
||||
String get setupScenTryingOutSub;
|
||||
|
||||
/// No description provided for @setupScenTeamHub.
|
||||
|
|
@ -5395,6 +5395,60 @@ abstract class AppLocalizations {
|
|||
/// **'Get started in 3 questions'**
|
||||
String get setupStartCta;
|
||||
|
||||
/// No description provided for @setupPlanRunbookLocal.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'This machine is being set up; the hub runs locally and starts on demand.'**
|
||||
String get setupPlanRunbookLocal;
|
||||
|
||||
/// No description provided for @setupPlanRunbookService.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'This machine is being set up: the hub will start automatically on boot (background service). For a different server, run the setup there.'**
|
||||
String get setupPlanRunbookService;
|
||||
|
||||
/// No description provided for @setupPlanRunbookAirgap.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Intended for an isolated server without internet — modules and updates arrive as offline bundles.'**
|
||||
String get setupPlanRunbookAirgap;
|
||||
|
||||
/// No description provided for @setupPlanRunbookContainer.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Intended for container operation — a ready-made compose example is included.'**
|
||||
String get setupPlanRunbookContainer;
|
||||
|
||||
/// No description provided for @setupPlanAuditChain.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Every step lands in a gapless, hash-chained audit log — tampering becomes detectable.'**
|
||||
String get setupPlanAuditChain;
|
||||
|
||||
/// No description provided for @setupPlanDocs.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'A matching reading list ({n} chapters) is stored with the setup record under ~/.chain/.'**
|
||||
String setupPlanDocs(int n);
|
||||
|
||||
/// No description provided for @setupTrustedPublishersHint.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Important: when adding the source, pin the publisher\'s key (\"pin signing key\") — otherwise the hub accepts any formally valid signature, no matter whose.'**
|
||||
String get setupTrustedPublishersHint;
|
||||
|
||||
/// No description provided for @setupAddSignedSource.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Add a signed source…'**
|
||||
String get setupAddSignedSource;
|
||||
|
||||
/// No description provided for @setupApplyNotes.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
/// **'Notes from the setup'**
|
||||
String get setupApplyNotes;
|
||||
|
||||
/// No description provided for @setupFreeTextHint.
|
||||
///
|
||||
/// In en, this message translates to:
|
||||
|
|
|
|||
|
|
@ -235,11 +235,11 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
'Vier Schritte zu einem funktionierenden Hub. Live-Zustand — nach jeder Änderung aktualisieren.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistAi => 'System-AI konfigurieren';
|
||||
String get welcomeChecklistAi => 'System-KI konfigurieren';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistAiHint =>
|
||||
'Einstellungen → System-AI. Wird für die KI-Suche und Fehlererklärungen gebraucht.';
|
||||
'Einstellungen → System-KI. Wird für die KI-Suche und Fehlererklärungen gebraucht.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistMcp => 'Öffentliche Capability-Quelle hinzufügen';
|
||||
|
|
@ -253,14 +253,14 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
|
||||
@override
|
||||
String get welcomeChecklistModuleHint =>
|
||||
'Im Store ein Modul aus der Kategorie deiner Wahl installieren. Module sind sandboxed Ch∆In-Komponenten.';
|
||||
'Im Store ein Modul aus der Kategorie Ihrer Wahl installieren. Module sind isolierte (sandboxed) Ch∆In-Komponenten.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistFlow => 'Einen gespeicherten Flow starten';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistFlowHint =>
|
||||
'Flows → einen wählen → Starten. Studio bringt einige Demo-Flows mit; auch ein eigener tut\'s.';
|
||||
'Flows → einen wählen → Starten. Studio bringt einige Demo-Flows mit; ein eigener funktioniert genauso.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistAllDone => 'Alle vier Schritte erledigt.';
|
||||
|
|
@ -1619,18 +1619,18 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
String get maintenanceResetConfirmButton => 'Zurücksetzen';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistAllSetTitle => 'Du bist eingerichtet.';
|
||||
String get welcomeChecklistAllSetTitle => 'Sie sind eingerichtet.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistAllSetBody =>
|
||||
'Drei Stränge, an denen du als nächstes ziehen kannst:';
|
||||
'Drei Stränge, an denen Sie als Nächstes ziehen können:';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistNextAuditTitle => 'Audit-Log lesen';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistNextAuditBody =>
|
||||
'Jede Installation, jeder Flow-Lauf, jede Freigabe landet im hash-verketteten Log. Im Protokoll-Tab siehst du, was dein Hub gemacht hat.';
|
||||
'Jede Installation, jeder Flow-Lauf, jede Freigabe landet im hash-verketteten Protokoll. Im Protokoll-Tab sehen Sie, was Ihr Hub gemacht hat.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistNextAuditButton => 'Protokoll öffnen';
|
||||
|
|
@ -1650,7 +1650,7 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
|
||||
@override
|
||||
String get welcomeChecklistNextModuleBody =>
|
||||
'Mit `chain new module <name>` ein Rust+WASM-Scaffold erzeugen. Das module-sdk übernimmt die WIT-Plumbing; du schreibst nur ein typisiertes invoke.';
|
||||
'Mit `chain new module <name>` ein Rust+WASM-Gerüst erzeugen. Das module-sdk übernimmt die WIT-Anbindung; Sie schreiben nur ein typisiertes invoke.';
|
||||
|
||||
@override
|
||||
String get welcomeChecklistNextModuleButton => 'Doku lesen';
|
||||
|
|
@ -2991,7 +2991,7 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
|
||||
@override
|
||||
String get setupScenTryingOutSub =>
|
||||
'Ein unkomplizierter Arbeitsplatz auf diesem Rechner — ohne Signaturen, ohne Audit-Sperre.';
|
||||
'Ein unkomplizierter Arbeitsplatz auf diesem Rechner — ohne Signaturpflicht, ohne Schreibschutz für das Prüfprotokoll.';
|
||||
|
||||
@override
|
||||
String get setupScenTeamHub => 'Ein Team-Server';
|
||||
|
|
@ -3182,6 +3182,41 @@ class AppLocalizationsDe extends AppLocalizations {
|
|||
@override
|
||||
String get setupStartCta => 'In 3 Fragen loslegen';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookLocal =>
|
||||
'Eingerichtet wird dieser Rechner; der Hub läuft lokal und wird bei Bedarf gestartet.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookService =>
|
||||
'Eingerichtet wird dieser Rechner: Der Hub startet künftig automatisch beim Hochfahren (Hintergrund-Dienst). Für einen anderen Server führen Sie die Einrichtung dort aus.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookAirgap =>
|
||||
'Vorgesehen für einen isolierten Server ohne Internet — Module und Updates kommen als Offline-Paket.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookContainer =>
|
||||
'Vorgesehen für den Betrieb im Container — ein fertiges Compose-Beispiel wird mitgeliefert.';
|
||||
|
||||
@override
|
||||
String get setupPlanAuditChain =>
|
||||
'Jeder Schritt landet in einem lückenlosen, hash-verketteten Prüfprotokoll — Manipulation wird erkennbar.';
|
||||
|
||||
@override
|
||||
String setupPlanDocs(int n) {
|
||||
return 'Eine passende Leseliste ($n Kapitel) wird mit dem Einrichtungs-Protokoll unter ~/.chain/ gespeichert.';
|
||||
}
|
||||
|
||||
@override
|
||||
String get setupTrustedPublishersHint =>
|
||||
'Wichtig: Hinterlegen Sie beim Hinzufügen der Quelle den Schlüssel des Herausgebers („Signatur-Schlüssel anheften“) — sonst akzeptiert der Hub jede formal gültige Signatur, egal von wem.';
|
||||
|
||||
@override
|
||||
String get setupAddSignedSource => 'Signierte Quelle hinzufügen…';
|
||||
|
||||
@override
|
||||
String get setupApplyNotes => 'Hinweise aus der Einrichtung';
|
||||
|
||||
@override
|
||||
String get setupFreeTextHint =>
|
||||
'z. B.: Eingehende Anträge vorprüfen und unvollständige markieren';
|
||||
|
|
|
|||
|
|
@ -2993,7 +2993,7 @@ class AppLocalizationsEn extends AppLocalizations {
|
|||
|
||||
@override
|
||||
String get setupScenTryingOutSub =>
|
||||
'A relaxed workspace on this machine — no signing, no audit locking.';
|
||||
'A straightforward workstation on this machine — no signature requirement, no write-protected audit log.';
|
||||
|
||||
@override
|
||||
String get setupScenTeamHub => 'A shared team hub';
|
||||
|
|
@ -3179,6 +3179,41 @@ class AppLocalizationsEn extends AppLocalizations {
|
|||
@override
|
||||
String get setupStartCta => 'Get started in 3 questions';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookLocal =>
|
||||
'This machine is being set up; the hub runs locally and starts on demand.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookService =>
|
||||
'This machine is being set up: the hub will start automatically on boot (background service). For a different server, run the setup there.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookAirgap =>
|
||||
'Intended for an isolated server without internet — modules and updates arrive as offline bundles.';
|
||||
|
||||
@override
|
||||
String get setupPlanRunbookContainer =>
|
||||
'Intended for container operation — a ready-made compose example is included.';
|
||||
|
||||
@override
|
||||
String get setupPlanAuditChain =>
|
||||
'Every step lands in a gapless, hash-chained audit log — tampering becomes detectable.';
|
||||
|
||||
@override
|
||||
String setupPlanDocs(int n) {
|
||||
return 'A matching reading list ($n chapters) is stored with the setup record under ~/.chain/.';
|
||||
}
|
||||
|
||||
@override
|
||||
String get setupTrustedPublishersHint =>
|
||||
'Important: when adding the source, pin the publisher\'s key (\"pin signing key\") — otherwise the hub accepts any formally valid signature, no matter whose.';
|
||||
|
||||
@override
|
||||
String get setupAddSignedSource => 'Add a signed source…';
|
||||
|
||||
@override
|
||||
String get setupApplyNotes => 'Notes from the setup';
|
||||
|
||||
@override
|
||||
String get setupFreeTextHint =>
|
||||
'e.g.: pre-screen incoming applications and flag incomplete ones';
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue