'Account', 'role_admin' => 'Administrator', // Section nav tabs 'tab_profile' => 'Profile', 'tab_security' => 'Security', 'tab_users' => 'Users', 'tab_sessions' => 'Sessions', 'tab_email' => 'Email', // Profile panel 'profile_title' => 'Profile', 'profile_subtitle' => 'Name and email', 'name' => 'Name', 'email' => 'Email', // Password panel 'password_title' => 'Password', 'password_subtitle' => 'At least 10 characters', 'current_password' => 'Current password', 'new_password' => 'New password', 'repeat_password' => 'Repeat', 'change_password' => 'Change password', // Two-factor panel 'twofa_title' => 'Two-factor authentication', 'twofa_subtitle' => 'TOTP (authenticator app)', 'twofa_status_on' => '2FA is active', 'twofa_status_off' => '2FA is not set up', 'twofa_hint_on' => 'Login requires a TOTP code.', 'twofa_hint_off' => 'Recommended — protects login with a second factor.', 'twofa_setup' => 'Set up', 'twofa_recommended' => '2FA is optional but recommended — secure your account with an authenticator or a security key.', 'twofa_remove_totp' => 'Remove authenticator', // Account recovery (last-resort) note — admin-only, post-login 'recovery_note' => 'Account recovery (last resort): sign in to the host over SSH and run `clusev reset-admin`.', // Notifications 'profile_saved' => 'Profile saved.', 'password_changed' => 'Password changed.', // Disable-2FA confirmation modal 'disable_2fa_heading' => 'Remove authenticator', 'disable_2fa_body' => 'Remove the authenticator (TOTP) as a factor? Security keys are kept.', 'disable_2fa_notify' => 'Authenticator removed.', // Stub tabs (filled in 0.9.0) // Page title 'title' => 'Settings — Clusev', // IP/CIDR whitelist validation 'lp_whitelist_invalid' => ':value is not a valid IP/CIDR.', // Login protection tab 'tab_login_protection' => 'Login protection', 'lp_title' => 'Login protection', 'lp_subtitle' => 'Blocks IP addresses after too many failed sign-in attempts.', 'lp_enabled' => 'Enabled', 'lp_maxretry' => 'Max. attempts', 'lp_findtime' => 'Time window (min.)', 'lp_bantime' => 'Ban duration (min.)', 'lp_whitelist' => 'Whitelist (IP/CIDR, one per line)', 'lp_whitelist_hint' => 'These addresses are never counted or blocked. Loopback is always exempt.', 'lp_current_ip' => 'Your current IP', 'lp_current_ip_exempt' => 'exempt', 'lp_whitelist_my_ip' => 'Add my IP to the whitelist', 'lp_save' => 'Save', 'lp_saved' => 'Login protection saved.', 'lp_bans_title' => 'Active blocks', 'lp_ban_reason' => 'Reason', 'lp_ban_attempts' => 'Attempts', 'lp_ban_until' => 'blocked until :time', 'lp_no_bans' => 'No active blocks.', 'lp_unban' => 'Unblock', 'lp_unban_heading' => 'Unblock IP?', 'lp_unban_body' => ':ip will be allowed again.', 'lp_unban_notify' => 'IP unblocked.', 'lp_unban_all' => 'Unblock all', 'lp_unban_all_heading' => 'Clear all blocks?', 'lp_unban_all_body' => 'All currently blocked IP addresses will be allowed again.', 'lp_unban_all_notify' => 'All blocks cleared.', 'lp_lockout_note' => 'Logged-in operators are never blocked and can unblock their own IP here. Emergency: clusev unban on the host shell.', // Threat-detection status indicator (env-driven, no toggle). Deliberately neutral naming // (no "honeypot"/"decoy"/"deception", env-var name omitted) — the deception layer must not // reveal itself in the UI. 'hp_title' => 'Threat detection', 'hp_subtitle' => 'Automatic ban of scanning attackers', 'hp_note' => 'Automatically bans scanning IP addresses on sight. Controlled via an environment variable. Hits appear under Threats.', 'hp_on' => 'Enabled', 'hp_off' => 'Disabled', ];