From 1c461285fcf5ecf157acc8e279951840f2054870 Mon Sep 17 00:00:00 2001 From: oliver Date: Thu, 10 Sep 2026 11:23:41 +0800 Subject: [PATCH] Expose udsAuth.getRole for cron elevated-cwd checks. Co-authored-by: Cursor --- uds-auth/lib/index.js | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/uds-auth/lib/index.js b/uds-auth/lib/index.js index cbbbe981..0abe6565 100644 --- a/uds-auth/lib/index.js +++ b/uds-auth/lib/index.js @@ -1057,6 +1057,11 @@ async function initServices(ctx, config) { canViewAllJobs(identity) { return !!identity?.permissions?.canViewAllSessions }, + getRole(empNo) { + const id = String(empNo || '').trim() + if (!id || id.startsWith('__')) return 'user' + return _rolesStore?.getRole?.(id) || 'user' + }, /** * Resolve role + permissions for an empNo (cron tools / fire-time cwd). * Does not touch request cookies — pure lookup from roles store.