Commit graph

15 commits

Author SHA1 Message Date
bad000d5b6 Use workspace membership as session ACL; keep owners for audit.
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:25:52 +08:00
4a477f3513 Stop ACL from wiping local workspace partitions for fallback_admin.
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:33:46 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
3e5c1f846e Fix local fallback_admin workspace list on HTTP.
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:20:10 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
7b893d9b3b Bind UDS identity on WebSocket via Host ws module; hide workspaces when anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:04:33 +08:00
382264f9d6 Resolve UDS ACL identity from cookies when sessionStore is empty.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:58:27 +08:00
a283b5cdc6 Fix workspace visibility: registry inject and WebSocket UDS identity. 2026-09-08 09:51:52 +08:00
ee0a49f381 Repair dsh-acl WebSocket identity patch syntax.
Restore a valid patchWebSocketServerForUdsIdentity implementation after a bad edit.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:49:30 +08:00
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
42618379a5 Fix super_admin workspace list lost on follow ALS gap.
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:36:17 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00