Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.
Co-authored-by: Cursor <cursoragent@cursor.com>
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.
Co-authored-by: Cursor <cursoragent@cursor.com>