Repository navigation
中文
本版本新增受 macOS 所有者认证保护的应用密码恢复,并修复系统认证中断后锁屏无法继续输入的严重问题。
- 在主可信显示器的锁屏中新增“忘记应用密码?”入口
- 使用 Touch ID 或 Mac 登录密码完成系统认证后,允许设置新的应用密码
- 重置成功后受保护应用继续保持锁定,必须使用新密码重新解锁
- 区分密码不匹配、Keychain 项目缺失、访问失败和数据损坏;只有真实密码错误才进入限流
- 使用原子 Keychain 更新,写入失败时保留原密码
- 系统认证取消、超时或回调丢失后恢复锁屏输入,不再需要重启电脑
- 阻止旧认证回调覆盖新请求,并避免认证期间焦点恢复抢走系统密码框
- 修复密码框失焦触发提交、提交时读取旧值以及普通按键引发表单刷新的问题
- 增加 Caps Lock 提示、主可信显示器限制,以及中英文界面说明
- 将五组密码、认证和安全状态回归测试加入 GitHub Actions
已验证密码重置、重置后保持锁定、新密码登录、系统认证连续取消后重新操作,以及通用 Release 构建和签名完整性。
English
This release adds app-password recovery protected by macOS owner authentication and fixes a severe lock-screen input failure after interrupted native authentication.
- adds “Forgot App Password?” on the primary trusted lock screen
- requires Touch ID or the Mac login password before setting a new app password
- keeps protected apps locked after reset and requires the new password to unlock
- separates password mismatch, missing Keychain item, access failure, and invalid stored data
- counts only real mismatches toward password throttling
- updates the Keychain item atomically and preserves the old password on failure
- restores lock-screen input after native-authentication cancellation, timeout, or a missing callback
- rejects stale authentication callbacks and prevents focus recovery from stealing the native dialog
- fixes blur-triggered submission, stale secure-field values, and unnecessary per-keystroke view refreshes
- adds Caps Lock guidance, trusted-display recovery restrictions, bilingual copy, and CI regression coverage
The downloadable application remains ad-hoc signed and non-notarized. Verify the matching SHA-256 file before installation.