Commit graph

334 commits

Author SHA1 Message Date
627e61aa80 Keep emergency login visible when QR fetch fails.
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 02:04:42 +08:00
e2c2e949ed Restrict @ mention and session query ACL so admin/user only see owned or workspace sessions.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 00:30:46 +08:00
e48b8bd082 Fix uds-auth settings save on frozen DSH config objects.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:38:37 +08:00
fd0df9b890 Add uds-auth zh/en i18n, UAC-branded settings, and QR expire/fail overlay.
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:10:37 +08:00
b60c626d41 Bundle uds-skill-auth inside the uds-auth plugin for single-package handoff.
Move the public auth helper skill under uds-auth/skills and update docs to point there instead of the repo-root skills tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:46:11 +08:00
c5c6089f89 Document uds-skill-auth in the plugin for easy handoff to skill authors.
Add a dedicated doc page and link it from the README and auth standard.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:43:29 +08:00
3595f49c86 Ship uds-skill-auth as a distributable skill for field UDS credential helpers.
Business skills depend on this sibling skill instead of the plugin source tree; update the auth standard docs accordingly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:35:28 +08:00
64761c8300 Add parallel skill credential path to uds-auth for agent/cron use.
UI session behavior stays unchanged; login writes a separate skill cache, with optional retain-on-logout and loopback agent-credentials/outbound APIs plus helpers/docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:01:11 +08:00
564d6ac189 Allow in-process IM/cron session APIs when UDS ALS is unset.
Browser HTTP always enters withUserContext(null|identity); WhatsApp harness
calls session.create/prompt with no ALS frame. Treating undefined as
host-internal restores channel turns broken by the UDS session ACL.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:48 +08:00
ba60368f39 Fix session history after UDS login by binding identity on all ws stream upgrades.
Gateway Remote stream mux starts async session.follow after the sync message
listener returns; without patching every ws copy and awaiting identity, ACL
saw an empty ALS and failed history load as gateway/internal.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:09 +08:00
9a93e9c8ce Do not hide dsh-ops-cron task rows with the session-only projectRow CSS.
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 16:03:42 +08:00
bc93392a02 Expose udsAuth Cordis service for request identity and workspace paths.
Lets plugins such as dsh-ops-cron resolve empNo/role, provisioned cwd, and stamp session owners without reading roles.json directly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:49:58 +08:00
c41991057d Restore workspace partitions for super admins; only force flat after auth-ready.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:17:18 +08:00
f98d283118 Wait for workspaceRegistry before provisioning user workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:03:06 +08:00
e9040224fb Force flat session sidebar for users without workspace create.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:57:23 +08:00
1b397c6733 Unblock composer for normal QR users after login.
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:45:52 +08:00
6b24fd15da Use soft reconnect on logout instead of full page reload.
Hard reload stays only after login so Set-Cookie is committed before WS upgrade.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:36:35 +08:00
bad000d5b6 Use workspace membership as session ACL; keep owners for audit.
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:25:52 +08:00
97dbfc4940 Reload after login so session history keeps WS identity.
Soft reconnect raced Set-Cookie and left session.page unauthenticated while prompt still worked.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:10:15 +08:00
1053403d88 Prefer soft reconnect after UDS login instead of full reload.
Workspace ACL no longer depends on a hard refresh; keep reload only as fallback.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:45:07 +08:00
4a477f3513 Stop ACL from wiping local workspace partitions for fallback_admin.
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:33:46 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
3e5c1f846e Fix local fallback_admin workspace list on HTTP.
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:20:10 +08:00
93526e7d45 Seed fallback_admin password Admin@123 on first start.
roles.json missing the hash field (or absent) enables the emergency account; an explicit null keeps it disabled.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:10:36 +08:00
337f6501b0 Enable fallback_admin by default with Admin@123.
Initial deploys often cannot scan UAC QR; seed the emergency account unless roles.json explicitly disabled it.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:09:14 +08:00
6455feed65 Fix fallback_admin logout so badge returns to 未登录.
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:58:47 +08:00
ed562f7c21 Fix anonymous blank UI and stale session restore.
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:51:08 +08:00
d0f77d2d4e Clear restored session when UDS user is anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:41:02 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
17fc093a2d Clear UDS_FALLBACK_UI on server logout. 2026-09-08 10:29:28 +08:00
7d4d228317 Clear UDS_FALLBACK_UI cookie on logout. 2026-09-08 10:29:09 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
42c5dd2c35 Simplify footer auth badge to username and anchor panel above it.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:17:30 +08:00
cf5c9d5060 Reconnect remote.mux after UDS login so session history uses new cookies.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:10:37 +08:00
7b893d9b3b Bind UDS identity on WebSocket via Host ws module; hide workspaces when anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:04:33 +08:00
382264f9d6 Resolve UDS ACL identity from cookies when sessionStore is empty.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:58:27 +08:00
a283b5cdc6 Fix workspace visibility: registry inject and WebSocket UDS identity. 2026-09-08 09:51:52 +08:00
ee0a49f381 Repair dsh-acl WebSocket identity patch syntax.
Restore a valid patchWebSocketServerForUdsIdentity implementation after a bad edit.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:49:30 +08:00
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
42618379a5 Fix super_admin workspace list lost on follow ALS gap.
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:36:17 +08:00
1f2ff7e00b Block inert composer card clicks unless super_admin.
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:25:43 +08:00
1fc39a3210 Gate open-workspace UI to super_admin only.
Non-super users keep their auto-provisioned workspace; hide Choose workspace and keep the picker locked unless canCreateWorkspace is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:22:15 +08:00
52fc39f71e Lock workspace chooser for anonymous users before first click.
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:13:03 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
9d16301700 Match UDS login chrome to Settings trigger; sit login near sidebar edge.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:00:29 +08:00
1ac1aec952 Lay Settings and UDS login on one sidebar foot row side by side.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:54:08 +08:00
e052ef4bf4 Pin UDS login to sidebar.footer.action (stable foot next to Settings, right-aligned).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:50:19 +08:00