fix(i18n): ForwardProxy ACL-Labels + Diagnostics-Output vollständig übersetzt
- ForwardProxy: ACL_TYPE_KEYS-Array + t('fwd.aclTypes.*') statt
hartkodierter gemischter DE/EN-Labels; action-Select und
value-Placeholder ebenso via t()
- Diagnostics: '(kein Output)' → t('diag.noOutput') — war einzige
sichtbare deutsche Konstante außerhalb t()
- en/de common.json: fwd.aclTypes.*, fwd.actions.*, fwd.valuePlaceholder,
diag.noOutput hinzugefügt
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -881,6 +881,7 @@
|
||||
"aclType": "Typ",
|
||||
"aclTypeExtra": "Was Squid prüft (Quelle, Domain, Port, …).",
|
||||
"value": "Wert",
|
||||
"valuePlaceholder": ".example.com oder 10.10.20.0/24 oder 443",
|
||||
"valueExtra": "Format hängt vom Typ ab — IPs/CIDRs für src/dst, Domain mit führendem . für dstdomain (.example.com matcht auch sub.example.com), Regex für *_regex-Typen.",
|
||||
"action": "Aktion",
|
||||
"priority": "Priority",
|
||||
@@ -890,7 +891,26 @@
|
||||
"edit": "ACL bearbeiten",
|
||||
"deleteConfirm": "ACL {{name}} wirklich löschen?",
|
||||
"emptyTitle": "Noch keine Forward-Proxy-ACLs.",
|
||||
"emptyDesc": "Default ohne ACLs: nur localnet (10/8, 172.16/12, 192.168/16) darf raus. Lege eine ACL an, um spezifische Domains/IPs/Ports gezielt zu erlauben oder zu blocken."
|
||||
"emptyDesc": "Default ohne ACLs: nur localnet (10/8, 172.16/12, 192.168/16) darf raus. Lege eine ACL an, um spezifische Domains/IPs/Ports gezielt zu erlauben oder zu blocken.",
|
||||
"actions": {
|
||||
"allow": "allow — Zugriff erlauben",
|
||||
"deny": "deny — Zugriff blockieren"
|
||||
},
|
||||
"aclTypes": {
|
||||
"src": "src — Quell-IP/CIDR",
|
||||
"dst": "dst — Ziel-IP/CIDR",
|
||||
"dstdomain": "dstdomain — Ziel-Domain (exact)",
|
||||
"srcdomain": "srcdomain — Quell-Domain (rDNS)",
|
||||
"port": "port — Ziel-Port",
|
||||
"proto": "proto — http/https/ftp/...",
|
||||
"method": "method — GET/POST/CONNECT/...",
|
||||
"time": "time — Wochentag/Zeit",
|
||||
"url_regex": "url_regex — kompletter URL-Match",
|
||||
"urlpath_regex": "urlpath_regex — Path-Teil",
|
||||
"dstdom_regex": "dstdom_regex — Domain-Regex",
|
||||
"srcdom_regex": "srcdom_regex — Quell-Domain-Regex",
|
||||
"browser": "browser — User-Agent-Regex"
|
||||
}
|
||||
},
|
||||
"common": {
|
||||
"yes": "Ja",
|
||||
@@ -1055,7 +1075,8 @@
|
||||
"curl": { "intro": "HTTPS-Probe mit -IsSv: TLS-Handshake-Details + Header. Folgt KEINE Redirects." },
|
||||
"tcp": { "intro": "Pure TCP-Connect ohne I/O. Ideal um zu prüfen ob ein Backend-Port erreichbar ist." },
|
||||
"securityTitle": "Sicherheits-Hinweis",
|
||||
"securityDesc": "Endpoints sind hinter Admin-Auth. Targets werden gegen eine strikte Allow-Liste validiert (keine Shell-Metazeichen). curl ist auf http(s) beschränkt — kein file:// / smb:// / data://."
|
||||
"securityDesc": "Endpoints sind hinter Admin-Auth. Targets werden gegen eine strikte Allow-Liste validiert (keine Shell-Metazeichen). curl ist auf http(s) beschränkt — kein file:// / smb:// / data://.",
|
||||
"noOutput": "(kein Output)"
|
||||
},
|
||||
"backups": {
|
||||
"title": "Backups",
|
||||
|
||||
@@ -881,6 +881,7 @@
|
||||
"aclType": "Type",
|
||||
"aclTypeExtra": "What Squid matches (source, domain, port, …).",
|
||||
"value": "Value",
|
||||
"valuePlaceholder": ".example.com or 10.10.20.0/24 or 443",
|
||||
"valueExtra": "Format depends on type — IPs/CIDRs for src/dst, domain with leading dot for dstdomain (.example.com also matches sub.example.com), regex for *_regex types.",
|
||||
"action": "Action",
|
||||
"priority": "Priority",
|
||||
@@ -890,7 +891,26 @@
|
||||
"edit": "Edit ACL",
|
||||
"deleteConfirm": "Really delete ACL {{name}}?",
|
||||
"emptyTitle": "No forward-proxy ACLs yet.",
|
||||
"emptyDesc": "Default with no ACLs: only localnet (10/8, 172.16/12, 192.168/16) is allowed out. Add an ACL to selectively allow or block specific domains/IPs/ports."
|
||||
"emptyDesc": "Default with no ACLs: only localnet (10/8, 172.16/12, 192.168/16) is allowed out. Add an ACL to selectively allow or block specific domains/IPs/ports.",
|
||||
"actions": {
|
||||
"allow": "allow — permit access",
|
||||
"deny": "deny — block access"
|
||||
},
|
||||
"aclTypes": {
|
||||
"src": "src — source IP/CIDR",
|
||||
"dst": "dst — destination IP/CIDR",
|
||||
"dstdomain": "dstdomain — destination domain (exact)",
|
||||
"srcdomain": "srcdomain — source domain (rDNS)",
|
||||
"port": "port — destination port",
|
||||
"proto": "proto — http/https/ftp/...",
|
||||
"method": "method — GET/POST/CONNECT/...",
|
||||
"time": "time — weekday/time range",
|
||||
"url_regex": "url_regex — full URL regex",
|
||||
"urlpath_regex": "urlpath_regex — URL path regex",
|
||||
"dstdom_regex": "dstdom_regex — destination domain regex",
|
||||
"srcdom_regex": "srcdom_regex — source domain regex",
|
||||
"browser": "browser — User-Agent regex"
|
||||
}
|
||||
},
|
||||
"common": {
|
||||
"yes": "Yes",
|
||||
@@ -1055,7 +1075,8 @@
|
||||
"curl": { "intro": "HTTPS probe with -IsSv: TLS handshake details + headers. Does NOT follow redirects." },
|
||||
"tcp": { "intro": "Pure TCP connect (no I/O). Ideal to verify a backend port is reachable." },
|
||||
"securityTitle": "Security note",
|
||||
"securityDesc": "Endpoints are behind admin auth. Targets are validated against a strict allow-list (no shell metachars). curl is restricted to http(s) — no file:// / smb:// / data://."
|
||||
"securityDesc": "Endpoints are behind admin auth. Targets are validated against a strict allow-list (no shell metachars). curl is restricted to http(s) — no file:// / smb:// / data://.",
|
||||
"noOutput": "(no output)"
|
||||
},
|
||||
"backups": {
|
||||
"title": "Backups",
|
||||
|
||||
@@ -74,7 +74,7 @@ function ToolCard({ icon, title, intro, children, result, loading, run }: {
|
||||
borderRadius: 6, overflow: 'auto', maxHeight: 320,
|
||||
whiteSpace: 'pre-wrap', wordBreak: 'break-all',
|
||||
}}>
|
||||
{result.output || result.error || '(kein Output)'}
|
||||
{result.output || result.error || t('diag.noOutput')}
|
||||
</pre>
|
||||
</div>
|
||||
)}
|
||||
|
||||
@@ -40,24 +40,10 @@ interface FormValues {
|
||||
comment?: string
|
||||
}
|
||||
|
||||
// ACL-Typen aus Squid's Vokabular — dieselbe Whitelist wie der
|
||||
// Backend-Validator. Mehr Typen kann Squid (browser, time-of-day,
|
||||
// arp, ...) — die spielen wir später dazu.
|
||||
const ACL_TYPES = [
|
||||
{ value: 'src', label: 'src — Quell-IP/CIDR' },
|
||||
{ value: 'dst', label: 'dst — Ziel-IP/CIDR' },
|
||||
{ value: 'dstdomain', label: 'dstdomain — Ziel-Domain (exact)' },
|
||||
{ value: 'srcdomain', label: 'srcdomain — Quell-Domain (rDNS)' },
|
||||
{ value: 'port', label: 'port — Ziel-Port' },
|
||||
{ value: 'proto', label: 'proto — http/https/ftp/...' },
|
||||
{ value: 'method', label: 'method — GET/POST/CONNECT/...' },
|
||||
{ value: 'time', label: 'time — Wochentag/Zeit' },
|
||||
{ value: 'url_regex', label: 'url_regex — kompletter URL-Match' },
|
||||
{ value: 'urlpath_regex', label: 'urlpath_regex — Path-Teil' },
|
||||
{ value: 'dstdom_regex', label: 'dstdom_regex — Domain-Regex' },
|
||||
{ value: 'srcdom_regex', label: 'srcdom_regex — Quell-Domain-Regex' },
|
||||
{ value: 'browser', label: 'browser — User-Agent-Regex' },
|
||||
]
|
||||
const ACL_TYPE_KEYS = [
|
||||
'src', 'dst', 'dstdomain', 'srcdomain', 'port', 'proto', 'method',
|
||||
'time', 'url_regex', 'urlpath_regex', 'dstdom_regex', 'srcdom_regex', 'browser',
|
||||
] as const
|
||||
|
||||
async function listACLs(): Promise<ACL[]> {
|
||||
const r = await apiClient.get('/forward-proxy/acls')
|
||||
@@ -222,17 +208,21 @@ export default function ForwardProxyPage() {
|
||||
</Form.Item>
|
||||
<Form.Item label={t('fwd.action')} name="action" rules={[{ required: true }]}>
|
||||
<Select options={[
|
||||
{ value: 'allow', label: 'allow — Zugriff erlauben' },
|
||||
{ value: 'deny', label: 'deny — Zugriff blockieren' },
|
||||
{ value: 'allow', label: t('fwd.actions.allow') },
|
||||
{ value: 'deny', label: t('fwd.actions.deny') },
|
||||
]} />
|
||||
</Form.Item>
|
||||
<Form.Item label={t('fwd.aclType')} name="acl_type" rules={[{ required: true }]}
|
||||
extra={t('fwd.aclTypeExtra')}>
|
||||
<Select options={ACL_TYPES} showSearch optionFilterProp="value" />
|
||||
<Select
|
||||
options={ACL_TYPE_KEYS.map(k => ({ value: k, label: t(`fwd.aclTypes.${k}`) }))}
|
||||
showSearch
|
||||
optionFilterProp="value"
|
||||
/>
|
||||
</Form.Item>
|
||||
<Form.Item label={t('fwd.value')} name="value" rules={[{ required: true }]}
|
||||
extra={t('fwd.valueExtra')}>
|
||||
<Input.TextArea rows={2} placeholder=".example.com oder 10.10.20.0/24 oder 443" />
|
||||
<Input.TextArea rows={2} placeholder={t('fwd.valuePlaceholder')} />
|
||||
</Form.Item>
|
||||
<Form.Item label={t('fwd.priority')} name="priority" rules={[{ required: true }]}
|
||||
extra={t('fwd.priorityExtra')}>
|
||||
|
||||
Reference in New Issue
Block a user