Isolate scheduled tasks by empNo, aligned with uds-auth workspaces.

Super/fallback admins see all jobs grouped by user folder; admin/user only see their own. Stamp ownership on create, filter HTTP/tools, and prefer the owner's provisioned cwd on fire.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-08 15:49:54 +08:00
parent 0ffc48b43a
commit 7d27179e51
12 changed files with 785 additions and 141 deletions

View file

@ -48,6 +48,15 @@ export {
} from './isolation.js'
export { wrapScheduledPrompt } from './prompt.js'
export { normalizeJobModel } from './store.js'
export {
assertCanAccessJob,
canViewAllJobs,
filterJobsForIdentity,
jobVisibleToIdentity,
migrateJobOwners,
UNASSIGNED_OWNER,
viewerPayload,
} from './ownership.js'
export { claimOccurrence, executeClaimedRun, extractAssistantText, TITLE_PREFIX } from './fire.js'
export {
deliverRunToIm,
@ -140,10 +149,12 @@ export function apply(ctx, config = {}) {
const getDshIm = () => tryGet(ctx, 'dshIm')
const getAgents = () => tryGet(ctx, 'agents')
const getAgentPresets = () => tryGet(ctx, 'agentPresets')
const getUdsAuth = () => tryGet(ctx, 'udsAuth')
const service = createHostService({
sessionPort: makeLiveSessionPort(ctx),
getDshIm,
getAgents,
getUdsAuth,
logger: ctx.logger,
})