CluPilotCloud/app/Models
nexxo 7edd88b71c Ein Zugang zur Konsole, dessen Passwort niemand kennt
Bisher erzeugte Settings::inviteStaff() beim Einladen eines
Betreiber-Mitarbeiters ein Passwort und zeigte es dem Inhaber einmal auf dem
Bildschirm, damit er es "sicher weitergibt" -- fuer einen Zugang zur Konsole,
die die ganze Flotte verwaltet. Der Kommentar dort nannte sich selbst eine
Attrappe.

Jetzt geht eine Einladung ohne Passwort hinaus: der Eingeladene bekommt eine
Mail mit einem Link und vergibt sein Passwort selbst, ueber
App\Livewire\Auth\OperatorSetPassword. Niemand -- auch der Inhaber nicht --
kennt je ein fremdes Passwort.

Dafuer brauchte es einen eigenen Weg, den es fuer Betreiber noch nicht gab
(R21: Konsole und Portal teilen keine Identitaet). Ein eigener Broker mit
eigener Tabelle (operator_password_reset_tokens, config/auth.php), eine
eigene Route in der Gast-Gruppe der Konsole (admin.invitation), und
Operator::sendPasswordResetNotification() wirft jetzt, statt Laravels
Vorgabe zu nutzen, die auf die Portalseite verlinkt haette.

Der Einladungslink gilt 72 Stunden -- lang genug fuer ein Wochenende, kurz
genug, dass ein altes Postfach nicht auf Dauer einen Schluessel zur Konsole
haelt. Zwei-Faktor bleibt unberuehrt: die neue Seite meldet niemanden
automatisch an, der Eingeladene durchlaeuft danach die normale Anmeldung
samt ihrer bestehenden Zwei-Faktor-Pruefung. Die Route liegt hinter denselben
Netz- und Hostwaechtern wie der Rest der Konsole (RestrictAdminHost,
RestrictConsoleNetwork), ohne Sonderfall.

OperatorInvitationMail reiht sich in den Versandtakt ein (MailLane::LOCKED,
wie ResetPasswordMail und VerifyEmailMail -- ein Mensch wartet gerade) und
ist damit in der Vorschau- und Versandtakt-Uebersicht der Konsole sichtbar,
statt lautlos in die gedrosselte Spur zu fallen.

Zwei Mutationsproben gegen die tragende Zusicherung durchgefuehrt (Bericht:
.superpowers/sdd/betreiber-einladung-report.md): die erste (durch die
Vorgaengersitzung) hielt fest, dass drei Zusicherungen fallen wuerden, waere
das Konto sofort anmeldbar; die zweite -- das Passwort testweise wieder auf
die Seite gebracht -- faellt exakt an der dafuer gebauten reflektierenden
Pruefung ueber alle oeffentlichen Eigenschaften der Seite.

Suite: 2771 passed (9683 assertions).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-04 01:50:42 +02:00
..
Builders feat(billing): a proof register, and modules frozen at their booked price 2026-07-26 13:07:34 +02:00
Concerns feat(engine): core provisioning data model + hosts 2026-07-25 09:49:43 +02:00
Backup.php feat(engine-b): customer domain models + migrations 2026-07-25 11:38:01 +02:00
Customer.php Take the address by field, fix the customer type, ask why they leave 2026-07-30 16:41:32 +02:00
Datacenter.php Hostnamen vergibt CluPilot: ein Name statt zweier, und der Zaehler ueberlebt das Loeschen 2026-08-01 13:45:43 +02:00
DnsRecord.php feat(engine-b): customer domain models + migrations 2026-07-25 11:38:01 +02:00
DpaAcceptance.php Deliver the processing agreement, and hold the proof it was accepted 2026-07-30 16:56:57 +02:00
DpaVersion.php Deliver the processing agreement, and hold the proof it was accepted 2026-07-30 16:56:57 +02:00
DunningCase.php Fix-Runde: Reichweite der Sperre, keine doppelte Gebuehr, verlorene Nachricht 2026-07-31 22:57:56 +02:00
ExportTarget.php Let a destination say how it is laid out and how long anything stays 2026-07-29 03:08:27 +02:00
FailedCheckout.php Zahlungsprobleme: geplatzte Kaeufe aufzeichnen, beide Arten an einer Stelle 2026-07-31 21:58:52 +02:00
Host.php Gesperrte Adressen: Datensatz, Verdopplung und die Liste, die nie gesperrt wird 2026-08-03 13:16:11 +02:00
InboundMail.php Read the support mailbox into the console 2026-07-29 21:41:29 +02:00
Incident.php Rebuild the status page as a status page 2026-07-29 12:45:18 +02:00
IncidentUpdate.php Rebuild the status page as a status page 2026-07-29 12:45:18 +02:00
Instance.php Gesperrte Adressen: Datensatz, Verdopplung und die Liste, die nie gesperrt wird 2026-08-03 13:16:11 +02:00
InstanceMetric.php Measure availability, and let a customer move down again 2026-07-27 16:41:15 +02:00
InstanceTraffic.php feat(traffic): meter the monthly allowance, show it, throttle instead of blocking 2026-07-25 23:33:47 +02:00
Invoice.php Invoice every renewal, and tell Stripe when the package changes 2026-07-29 19:35:15 +02:00
InvoiceExport.php Let the export have as many destinations as somebody wants 2026-07-29 02:43:15 +02:00
InvoiceSeries.php Lay the foundation for self-issued invoices: series, numbers, frozen documents 2026-07-29 00:57:06 +02:00
LoginSession.php Recognise the devices an account signs in from, and warn about a new one 2026-07-28 23:28:34 +02:00
MailTemplate.php Show the customer, and write the answers once 2026-07-29 22:37:30 +02:00
Mailbox.php Clear every mailbox's verification when the shared server config changes 2026-07-28 06:36:06 +02:00
MaintenanceNotification.php fix(admin): in-flight claim (claimed_at) for exactly-once maintenance send; scope permission rollback 2026-07-25 16:38:44 +02:00
MaintenanceWindow.php fix(portal): scope the per-instance maintenance badge to that instance's host 2026-07-25 19:12:33 +02:00
MonitoringTarget.php Move the console off /admin, give the status page its own address, and measure monitoring 2026-07-27 06:05:40 +02:00
OnboardingTask.php feat(engine-b): customer domain models + migrations 2026-07-25 11:38:01 +02:00
Operator.php Ein Zugang zur Konsole, dessen Passwort niemand kennt 2026-08-04 01:50:42 +02:00
Order.php Stop charging VAT to the customers who owe us none 2026-07-30 02:15:41 +02:00
PlanFamily.php Interne Pakete verschwinden aus dem Laden und bleiben in der Konsole 2026-08-01 15:31:46 +02:00
PlanPrice.php feat(billing): the plan catalogue becomes three tables, and config stops selling 2026-07-26 12:05:56 +02:00
PlanVersion.php Release v1.3.88 — die Vorlage baut sich selbst 2026-08-01 05:01:44 +02:00
ProvisioningRun.php Fix nine defects in the provisioning pipelines 2026-07-30 01:34:55 +02:00
ProvisioningStepEvent.php feat(engine): core provisioning data model + hosts 2026-07-25 09:49:43 +02:00
ProxyHost.php Fill the hostname page from the installation, not from a blank form 2026-07-31 00:53:12 +02:00
RunResource.php feat(engine): core provisioning data model + hosts 2026-07-25 09:49:43 +02:00
Seat.php Wanderung friert das Nachziehen selbst ein, statt die Modellmethode zu rufen 2026-08-03 20:59:45 +02:00
SecurityBlock.php fix(security): Aufheben einer Sperre sagt die Wahrheit und wird nachgeholt 2026-08-03 17:28:28 +02:00
SentMail.php Keep a register of what was sent, and answer the customer from here 2026-07-29 21:02:36 +02:00
StatusDay.php Rebuild the status page as a status page 2026-07-29 12:45:18 +02:00
StripeAddonPrice.php Stop charging VAT to the customers who owe us none 2026-07-30 02:15:41 +02:00
StripePendingEvent.php feat(billing): Stripe owns the billing cycle, we own capability 2026-07-26 13:36:28 +02:00
StripePlanPrice.php Stop charging VAT to the customers who owe us none 2026-07-30 02:15:41 +02:00
Subscription.php Take the address by field, fix the customer type, ask why they leave 2026-07-30 16:41:32 +02:00
SubscriptionAddon.php Die Packungsgroesse steht auf der Buchung, nicht in der Konfiguration 2026-08-01 12:25:30 +02:00
SubscriptionRecord.php Ask whether they are a consumer, and let one change their mind 2026-07-29 21:06:06 +02:00
SupportRequest.php Editing in modals, an update button that is not gated on a stale reading, and a support page that is real 2026-07-27 17:55:49 +02:00
User.php Jede Mail faehrt wieder ueber ihren eigenen Mailer 2026-08-03 20:36:20 +02:00
UserDevice.php Repair two comment blocks the admin-hosts edit ran together 2026-07-28 23:20:43 +02:00
VpnPeer.php Move the console's identity out of the customer table 2026-07-28 10:31:43 +02:00