Skip to content

Maclock Secure MacOS 1.5.3

Latest

Choose a tag to compare

@supervking supervking released this 11 Sep 18:55
04c294d

中文

本版本新增受 macOS 所有者认证保护的应用密码恢复,并修复系统认证中断后锁屏无法继续输入的严重问题。

  • 在主可信显示器的锁屏中新增“忘记应用密码?”入口
  • 使用 Touch ID 或 Mac 登录密码完成系统认证后,允许设置新的应用密码
  • 重置成功后受保护应用继续保持锁定,必须使用新密码重新解锁
  • 区分密码不匹配、Keychain 项目缺失、访问失败和数据损坏;只有真实密码错误才进入限流
  • 使用原子 Keychain 更新,写入失败时保留原密码
  • 系统认证取消、超时或回调丢失后恢复锁屏输入,不再需要重启电脑
  • 阻止旧认证回调覆盖新请求,并避免认证期间焦点恢复抢走系统密码框
  • 修复密码框失焦触发提交、提交时读取旧值以及普通按键引发表单刷新的问题
  • 增加 Caps Lock 提示、主可信显示器限制,以及中英文界面说明
  • 将五组密码、认证和安全状态回归测试加入 GitHub Actions

已验证密码重置、重置后保持锁定、新密码登录、系统认证连续取消后重新操作,以及通用 Release 构建和签名完整性。

English

This release adds app-password recovery protected by macOS owner authentication and fixes a severe lock-screen input failure after interrupted native authentication.

  • adds “Forgot App Password?” on the primary trusted lock screen
  • requires Touch ID or the Mac login password before setting a new app password
  • keeps protected apps locked after reset and requires the new password to unlock
  • separates password mismatch, missing Keychain item, access failure, and invalid stored data
  • counts only real mismatches toward password throttling
  • updates the Keychain item atomically and preserves the old password on failure
  • restores lock-screen input after native-authentication cancellation, timeout, or a missing callback
  • rejects stale authentication callbacks and prevents focus recovery from stealing the native dialog
  • fixes blur-triggered submission, stale secure-field values, and unnecessary per-keystroke view refreshes
  • adds Caps Lock guidance, trusted-display recovery restrictions, bilingual copy, and CI regression coverage

The downloadable application remains ad-hoc signed and non-notarized. Verify the matching SHA-256 file before installation.