Commit graph

30 commits

Author SHA1 Message Date
337f6501b0 Enable fallback_admin by default with Admin@123.
Initial deploys often cannot scan UAC QR; seed the emergency account unless roles.json explicitly disabled it.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:09:14 +08:00
6455feed65 Fix fallback_admin logout so badge returns to 未登录.
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:58:47 +08:00
ed562f7c21 Fix anonymous blank UI and stale session restore.
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:51:08 +08:00
d0f77d2d4e Clear restored session when UDS user is anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:41:02 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
7d4d228317 Clear UDS_FALLBACK_UI cookie on logout. 2026-09-08 10:29:09 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
42c5dd2c35 Simplify footer auth badge to username and anchor panel above it.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:17:30 +08:00
cf5c9d5060 Reconnect remote.mux after UDS login so session history uses new cookies.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:10:37 +08:00
1f2ff7e00b Block inert composer card clicks unless super_admin.
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:25:43 +08:00
1fc39a3210 Gate open-workspace UI to super_admin only.
Non-super users keep their auto-provisioned workspace; hide Choose workspace and keep the picker locked unless canCreateWorkspace is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:22:15 +08:00
52fc39f71e Lock workspace chooser for anonymous users before first click.
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:13:03 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
9d16301700 Match UDS login chrome to Settings trigger; sit login near sidebar edge.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:00:29 +08:00
1ac1aec952 Lay Settings and UDS login on one sidebar foot row side by side.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:54:08 +08:00
e052ef4bf4 Pin UDS login to sidebar.footer.action (stable foot next to Settings, right-aligned).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:50:19 +08:00
7e2d8ef5d8 Avoid login badge overlapping Session log: header when in session, overlay only when idle.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:44:12 +08:00
705c6864ef Show UDS login on shell.overlay so it is visible without an active session.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:39:58 +08:00
8f569070a0 Remove broken /settings shortcut from UDS login badge panel.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:34:25 +08:00
b3b5b6997e Fix first-login bootstrap to super_admin; allow admin settings via canAccessSettings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:23:20 +08:00
74a86ff832 Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:37:08 +08:00
b535714000 Move UDS login into header.utilities so it sits left of session log-download.
EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:22:43 +08:00
91a1804f68 Place UDS login beside session log-download in the same header.actions slot. 2026-09-08 02:17:17 +08:00
b4fa832a6b Move UDS login back to top-right overlay, docked left of toggles with matching chrome style. 2026-09-08 02:13:25 +08:00
6caafe9590 Fix uds-auth client.js syntax error that broke the whole plugin bundle. 2026-09-08 02:00:55 +08:00
6360f80349 Move UDS login badge into session header actions to avoid covering Search/toggles. 2026-09-08 01:58:31 +08:00
505f9dea3f Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00