mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 00:40:45 +08:00
Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
42c5dd2c35
commit
655655d878
2 changed files with 28 additions and 12 deletions
|
|
@ -99,7 +99,12 @@ window.__ModuleLoader__.load({
|
|||
}
|
||||
|
||||
function getEmpNo() {
|
||||
return getCookie('PORTALSSOUser') || getCookie('ZTEDPGSSOUser') || getCookie('UDS_FALLBACK_USER') || null
|
||||
return getCookie('PORTALSSOUser') || getCookie('ZTEDPGSSOUser') || getCookie('UDS_FALLBACK_USER') || getCookie('UDS_FALLBACK_UI') || null
|
||||
}
|
||||
|
||||
/** Prefer /api/me-driven attr: fallback login cookie is HttpOnly and invisible to document.cookie. */
|
||||
function isLoggedInInUi() {
|
||||
return document.documentElement.getAttribute('data-uds-logged-in') === '1' || !!getEmpNo()
|
||||
}
|
||||
|
||||
/** After UDS login, remote.mux still has pre-login identity — reconnect to re-upgrade with cookies. */
|
||||
|
|
@ -864,7 +869,7 @@ window.__ModuleLoader__.load({
|
|||
const origFetch = window.fetch.bind(window)
|
||||
window.fetch = async function udsAuthFetch(input, init) {
|
||||
const url = typeof input === 'string' ? input : (input && input.url) || ''
|
||||
if (!getEmpNo() && String(url).includes('/dsh-ops-cron') && !String(url).includes('/dsh-ops-cron/health')) {
|
||||
if (!isLoggedInInUi() && String(url).includes('/dsh-ops-cron') && !String(url).includes('/dsh-ops-cron/health')) {
|
||||
return new Response(JSON.stringify({
|
||||
ok: false,
|
||||
error: 'login_required',
|
||||
|
|
@ -883,7 +888,7 @@ window.__ModuleLoader__.load({
|
|||
const origCall = rpc.call.bind(rpc)
|
||||
rpc.call = async function udsAuthRpcCall(channel, endpoint, payload, signal) {
|
||||
const result = await origCall(channel, endpoint, payload, signal)
|
||||
if (!getEmpNo()) {
|
||||
if (!isLoggedInInUi()) {
|
||||
if (channel === '/api') {
|
||||
if (endpoint === 'session/list') return { ok: true, value: { items: [] } }
|
||||
if (endpoint === 'session/search') return { ok: true, value: { items: [], hasMore: false } }
|
||||
|
|
@ -917,14 +922,14 @@ window.__ModuleLoader__.load({
|
|||
const origAdded = sessions.handleSessionAdded && sessions.handleSessionAdded.bind(sessions)
|
||||
if (origAdded) {
|
||||
sessions.handleSessionAdded = (summary) => {
|
||||
if (!getEmpNo()) return
|
||||
if (!isLoggedInInUi()) return
|
||||
return origAdded(summary)
|
||||
}
|
||||
}
|
||||
const origActivity = sessions.handleSessionActivity && sessions.handleSessionActivity.bind(sessions)
|
||||
if (origActivity) {
|
||||
sessions.handleSessionActivity = (sessionId, updatedAt) => {
|
||||
if (!getEmpNo()) return
|
||||
if (!isLoggedInInUi()) return
|
||||
return origActivity(sessionId, updatedAt)
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -449,14 +449,25 @@ async function handleFallbackLogin(req, res) {
|
|||
await ensureUserWorkspace(empNo)
|
||||
|
||||
// 给浏览器设 cookie,让后续请求 auth-middleware 能识别
|
||||
const fbMaxAge = Math.floor(INTERNAL.session.cookieMaxAge / 1000)
|
||||
res.setHeader('Set-Cookie', [
|
||||
'UDS_FALLBACK_USER=administrator',
|
||||
`Max-Age=${Math.floor(INTERNAL.session.cookieMaxAge / 1000)}`,
|
||||
'Path=/',
|
||||
'Secure',
|
||||
'HttpOnly',
|
||||
'SameSite=Lax',
|
||||
].join('; '))
|
||||
[
|
||||
'UDS_FALLBACK_USER=administrator',
|
||||
`Max-Age=${fbMaxAge}`,
|
||||
'Path=/',
|
||||
'Secure',
|
||||
'HttpOnly',
|
||||
'SameSite=Lax',
|
||||
].join('; '),
|
||||
// Readable by document.cookie so client ACL gates see fallback login before /api/me.
|
||||
[
|
||||
'UDS_FALLBACK_UI=administrator',
|
||||
`Max-Age=${fbMaxAge}`,
|
||||
'Path=/',
|
||||
'Secure',
|
||||
'SameSite=Lax',
|
||||
].join('; '),
|
||||
])
|
||||
|
||||
sendJSON(res, 200, {
|
||||
success: true,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue