CluPilotCloud/lang/de
nexxo 903ebdd2b2 Give the operator one line to copy and three steps around it
The console could describe a takeover it had no way to start. This is the
vertical slice that closes that: a one-time code, the archive the rescue system
fetches, and the page that says what to do with both.

The command carries EVERYTHING the script needs before the tunnel exists,
because there is nothing to fetch — that is the whole point of spec §5. Which
means CluPilot generates the WireGuard keypair and admits the peer at the hub
before the machine has ever booted, and hands the private half over in the line.
It is worthless within minutes: task 9 of the script replaces it with one
generated on the machine.

Shown exactly once. The database holds only the code's hash and never the
private key, so leaving the page does not bring it back — it mints a new code,
which invalidates the old one. That is deliberate: a glance at somebody's screen
should be worth nothing an hour later.

Which is also why save() no longer redirects. Sending the operator to the host
detail page sends them away from the only value they need, and an existing test
asserted that redirect — it now asserts the opposite, with the reason written
next to it.

SHA-256 rather than bcrypt for the code, and the reason is not speed. Both
endpoints have to FIND the host by the code; with bcrypt that means trying every
row. The code is 32 characters of CSPRNG output, so it has the entropy that
stretching exists to manufacture.

resolve() and claim() are separate because progress reports arrive BEFORE
registration. If reporting consumed the code, a host could never register after
its first message.

The archive URL is always the public hostname. The console runs under admin.…,
but this line executes on a machine that must not reach the admin area — it is
locked down for exactly that reason — so route() from the console would emit a
hostname that 404s on a server only reachable through the provider's console.

The page warns about missing tunnel settings BEFORE the host is created, not
after. An empty hub key produces a line that looks clean, copies fine, runs, and
ends in a tunnel that never handshakes — discovered on the machine, after
somebody has already paid for it.

The three steps lead with the rescue system, because that is the one nobody
knows by heart, and it says enabling is not the same as booting into it — the
script refuses a running production machine, which is what a half-done switch
looks like from the inside.

1986 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 20:40:19 +02:00
..
admin.php Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
admin_incidents.php Let an incident be deleted, and start measuring whether the hosts answer 2026-07-29 15:16:48 +02:00
admin_settings.php Quote what a person pays, and tab the settings page 2026-07-29 19:18:10 +02:00
auth.php Ask whether they are a consumer, and let one change their mind 2026-07-29 21:06:06 +02:00
backups.php feat(portal): full sidebar — Cloud, Users, Backups, Invoices, Support 2026-07-25 08:08:33 +02:00
billing.php Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
capacity.php Take the order, park it, and say when it will be delivered 2026-07-29 18:50:46 +02:00
checkout.php Give the order a checkout page, and stop hiding what a year costs 2026-07-30 16:00:08 +02:00
cloud.php Restart a machine, enforce the quota that was sold, end a route that ended 2026-07-29 18:28:28 +02:00
coming_soon.php Say EU, and stop promising to fix somebody else's deleted folder 2026-07-29 14:17:30 +02:00
common.php Recover silently from an expired session, and show a connection banner when offline 2026-07-28 21:36:21 +02:00
customer_detail.php Let an operator correct a customer's details 2026-07-29 23:18:46 +02:00
customer_message.php Show the customer, and write the answers once 2026-07-29 22:37:30 +02:00
dashboard.php Let the customer buy it themselves, and tab the integrations page 2026-07-29 19:42:28 +02:00
datacenters.php Let a datacenter code be corrected while nothing depends on it, and say which building 2026-07-28 22:25:21 +02:00
delivery.php Quote what a person pays, and tab the settings page 2026-07-29 19:18:10 +02:00
devices.php Recognise the devices an account signs in from, and warn about a new one 2026-07-28 23:28:34 +02:00
domain.php Serve the custom domain, not just announce it 2026-07-29 16:44:52 +02:00
dormant_mail.php Accept terms instead of a start date, and fix the sender no server accepts 2026-07-30 15:22:35 +02:00
dpa.php Stop asking for a signature the law does not want, and lay out the tab 2026-07-30 17:30:55 +02:00
dpa_admin.php Stop asking for a signature the law does not want, and lay out the tab 2026-07-30 17:30:55 +02:00
edit_customer.php Let an operator correct a customer's details 2026-07-29 23:18:46 +02:00
errors.php Refuse a portal login for an address that already belongs to an operator 2026-07-28 14:42:16 +02:00
finance.php Quote what a person pays, and tab the settings page 2026-07-29 19:18:10 +02:00
hosts.php Give the operator one line to copy and three steps around it 2026-07-30 20:40:19 +02:00
impersonate.php feat(admin): impersonate customer portal — session login + return banner 2026-07-25 13:46:48 +02:00
inbox.php Read the mailbox password where it actually is, and let the console test it 2026-07-30 13:12:29 +02:00
instances.php Pin the sidebar header and footer so only the nav list scrolls, and shorten two action labels that wrapped 2026-07-28 20:52:12 +02:00
integrations.php Merge main into the operating-mode branch 2026-07-30 17:53:20 +02:00
invoice.php Say the same thing to the customer, the register and the bank 2026-07-30 01:30:24 +02:00
invoice_mail.php Send the invoice with the invoice attached 2026-07-29 02:13:41 +02:00
invoices.php Say the same thing to the customer, the register and the bank 2026-07-30 01:30:24 +02:00
invoices_admin.php Write an invoice for work that came off no price list 2026-07-29 20:12:26 +02:00
mail.php Put customer instances on their own domain, and say which domains are ours 2026-07-29 16:03:13 +02:00
mail_log.php Keep a register of what was sent, and answer the customer from here 2026-07-29 21:02:36 +02:00
mail_preview.php Make mails readable on a phone, and let an operator look at one 2026-07-30 14:50:37 +02:00
mail_settings.php Bound the mail test-send and real send to a timeout instead of hanging 2026-07-28 16:36:14 +02:00
maintenance.php Put every mail in one design, and confirm an order when the money arrives 2026-07-29 00:14:04 +02:00
new_invoice.php Write an invoice for work that came off no price list 2026-07-29 20:12:26 +02:00
order.php Fix the checkout link, and stop the switch moving under the cursor 2026-07-30 16:05:56 +02:00
orders.php Keep the shop window off the portal's front door 2026-07-29 00:26:22 +02:00
plans.php Sell the year as well as the month, and say what it saves 2026-07-30 15:44:35 +02:00
provisioning.php Deliver the storage a customer actually buys 2026-07-29 19:13:10 +02:00
readiness.php Never tell anyone to delete a catalogue their contracts bill on 2026-07-30 17:30:56 +02:00
reset_password.php Give people a way back in, and put the URL in English 2026-07-29 16:50:29 +02:00
secrets.php Say which slot the value in force is really coming from 2026-07-30 17:01:33 +02:00
security.php Put customer instances on their own domain, and say which domains are ours 2026-07-29 16:03:13 +02:00
sessions.php Show where an account is signed in, and let it sign the other places out 2026-07-28 23:38:17 +02:00
settings.php Rebuild the settings page out of panels and rows 2026-07-30 17:38:57 +02:00
status.php Let an incident be deleted, and start measuring whether the hosts answer 2026-07-29 15:16:48 +02:00
support.php Editing in modals, an update button that is not gated on a stale reading, and a support page that is real 2026-07-27 17:55:49 +02:00
templates.php Show the customer, and write the answers once 2026-07-29 22:37:30 +02:00
two_factor_setup.php Let a half-finished two-factor enrolment be cancelled, and rework the setup page 2026-07-28 22:25:27 +02:00
updating.php Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
users.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
verify_email.php Accept terms instead of a start date, and fix the sender no server accepts 2026-07-30 15:22:35 +02:00
vpn.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
withdrawal.php Take the address by field, fix the customer type, ask why they leave 2026-07-30 16:41:32 +02:00