From 655655d878f6107649db5858259bafe7782cb1fb Mon Sep 17 00:00:00 2001 From: oliver Date: Tue, 8 Sep 2026 10:28:45 +0800 Subject: [PATCH] Fix fallback_admin session list when HttpOnly cookie hides empNo from JS. Co-authored-by: Cursor --- uds-auth/lib/client.js | 15 ++++++++++----- uds-auth/lib/index.js | 25 ++++++++++++++++++------- 2 files changed, 28 insertions(+), 12 deletions(-) diff --git a/uds-auth/lib/client.js b/uds-auth/lib/client.js index 4db183a9..f17c65ae 100644 --- a/uds-auth/lib/client.js +++ b/uds-auth/lib/client.js @@ -99,7 +99,12 @@ window.__ModuleLoader__.load({ } function getEmpNo() { - return getCookie('PORTALSSOUser') || getCookie('ZTEDPGSSOUser') || getCookie('UDS_FALLBACK_USER') || null + return getCookie('PORTALSSOUser') || getCookie('ZTEDPGSSOUser') || getCookie('UDS_FALLBACK_USER') || getCookie('UDS_FALLBACK_UI') || null + } + + /** Prefer /api/me-driven attr: fallback login cookie is HttpOnly and invisible to document.cookie. */ + function isLoggedInInUi() { + return document.documentElement.getAttribute('data-uds-logged-in') === '1' || !!getEmpNo() } /** After UDS login, remote.mux still has pre-login identity — reconnect to re-upgrade with cookies. */ @@ -864,7 +869,7 @@ window.__ModuleLoader__.load({ const origFetch = window.fetch.bind(window) window.fetch = async function udsAuthFetch(input, init) { const url = typeof input === 'string' ? input : (input && input.url) || '' - if (!getEmpNo() && String(url).includes('/dsh-ops-cron') && !String(url).includes('/dsh-ops-cron/health')) { + if (!isLoggedInInUi() && String(url).includes('/dsh-ops-cron') && !String(url).includes('/dsh-ops-cron/health')) { return new Response(JSON.stringify({ ok: false, error: 'login_required', @@ -883,7 +888,7 @@ window.__ModuleLoader__.load({ const origCall = rpc.call.bind(rpc) rpc.call = async function udsAuthRpcCall(channel, endpoint, payload, signal) { const result = await origCall(channel, endpoint, payload, signal) - if (!getEmpNo()) { + if (!isLoggedInInUi()) { if (channel === '/api') { if (endpoint === 'session/list') return { ok: true, value: { items: [] } } if (endpoint === 'session/search') return { ok: true, value: { items: [], hasMore: false } } @@ -917,14 +922,14 @@ window.__ModuleLoader__.load({ const origAdded = sessions.handleSessionAdded && sessions.handleSessionAdded.bind(sessions) if (origAdded) { sessions.handleSessionAdded = (summary) => { - if (!getEmpNo()) return + if (!isLoggedInInUi()) return return origAdded(summary) } } const origActivity = sessions.handleSessionActivity && sessions.handleSessionActivity.bind(sessions) if (origActivity) { sessions.handleSessionActivity = (sessionId, updatedAt) => { - if (!getEmpNo()) return + if (!isLoggedInInUi()) return return origActivity(sessionId, updatedAt) } } diff --git a/uds-auth/lib/index.js b/uds-auth/lib/index.js index d812cdbf..4ecc1364 100644 --- a/uds-auth/lib/index.js +++ b/uds-auth/lib/index.js @@ -449,14 +449,25 @@ async function handleFallbackLogin(req, res) { await ensureUserWorkspace(empNo) // 给浏览器设 cookie,让后续请求 auth-middleware 能识别 + const fbMaxAge = Math.floor(INTERNAL.session.cookieMaxAge / 1000) res.setHeader('Set-Cookie', [ - 'UDS_FALLBACK_USER=administrator', - `Max-Age=${Math.floor(INTERNAL.session.cookieMaxAge / 1000)}`, - 'Path=/', - 'Secure', - 'HttpOnly', - 'SameSite=Lax', - ].join('; ')) + [ + 'UDS_FALLBACK_USER=administrator', + `Max-Age=${fbMaxAge}`, + 'Path=/', + 'Secure', + 'HttpOnly', + 'SameSite=Lax', + ].join('; '), + // Readable by document.cookie so client ACL gates see fallback login before /api/me. + [ + 'UDS_FALLBACK_UI=administrator', + `Max-Age=${fbMaxAge}`, + 'Path=/', + 'Secure', + 'SameSite=Lax', + ].join('; '), + ]) sendJSON(res, 200, { success: true,