Commit graph

345 commits

Author SHA1 Message Date
91d2515205 Unify admin-class workspace create and restore Add-workspace UI.
Give admin the same permissions as super/fallback, occupy directoryFlow at priority 1 so the button renders without colliding with the native picker, and inject uiWorkspace for pickDirectory.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 22:46:45 +08:00
060500360d Stop infinite page refresh from auth remount gates.
Remove directory-flow reload, only shadow the picker while anonymous, and stop clearing login attrs on AuthBadge unmount so flat↔workspace observers cannot loop.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 22:01:22 +08:00
ab926969f6 Restore Add-workspace after granting create permission.
Directory-flow gate was shadowing the native picker; clearing it left an empty hole so Add workspace never rendered. Reload once when permission flips on, and harden canCreateWorkspace detection from role/permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 21:58:19 +08:00
89700ef4f9 Allow admin (and Host plugins) to create workspaces.
super_admin/fallback_admin already could; admin now has canCreateWorkspace, and Host-side creates without browser ALS (IM) are no longer blocked as forbidden.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 21:52:14 +08:00
050b99426f Remove unused NetX alarm WebSocket bridge.
Alarm delivery moved to NetX DSH hub; drop /ws/netx-bridge and its tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-15 23:10:32 +08:00
ad0cc98b38 Make session visibility preference-driven and keep system-channel ACL separate.
Super/fallback can toggle view-all (default on); admin/user stay own-only while still seeing unowned system sessions. Add restore/prune helpers so empty-shell cleanup is explicit and recoverable.
2026-09-14 20:48:15 +08:00
c26dc68f77 Add decrypt-to-unlock local admin via sealed env box.
Replace auto-grant-on-env with AES-GCM box + passphrase unlock, rebuild fallback sessions after restart, and document seal script usage.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 22:16:21 +08:00
922abaa89e Restore uds-auth session on badge mount so login survives reload.
Calling /api/me only when opening the QR panel left users stuck on 未登录 until they clicked the badge.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 21:11:15 +08:00
81ff8eb19f Speed up uds-auth login: paint badge first, lazy /api/me.
Skip startup /api/me until QR load, stop blocking me on workspace provision, and register the footer login entry before heavy ACL gates so login appears immediately.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 12:29:49 +08:00
1c461285fc Expose udsAuth.getRole for cron elevated-cwd checks.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 11:23:41 +08:00
cc32a6c6ea Expose resolveIdentityForEmpNo on udsAuth for role-aware cron cwd.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 10:00:59 +08:00
627e61aa80 Keep emergency login visible when QR fetch fails.
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 02:04:42 +08:00
e2c2e949ed Restrict @ mention and session query ACL so admin/user only see owned or workspace sessions.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 00:30:46 +08:00
e48b8bd082 Fix uds-auth settings save on frozen DSH config objects.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:38:37 +08:00
fd0df9b890 Add uds-auth zh/en i18n, UAC-branded settings, and QR expire/fail overlay.
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:10:37 +08:00
b60c626d41 Bundle uds-skill-auth inside the uds-auth plugin for single-package handoff.
Move the public auth helper skill under uds-auth/skills and update docs to point there instead of the repo-root skills tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:46:11 +08:00
c5c6089f89 Document uds-skill-auth in the plugin for easy handoff to skill authors.
Add a dedicated doc page and link it from the README and auth standard.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:43:29 +08:00
3595f49c86 Ship uds-skill-auth as a distributable skill for field UDS credential helpers.
Business skills depend on this sibling skill instead of the plugin source tree; update the auth standard docs accordingly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:35:28 +08:00
64761c8300 Add parallel skill credential path to uds-auth for agent/cron use.
UI session behavior stays unchanged; login writes a separate skill cache, with optional retain-on-logout and loopback agent-credentials/outbound APIs plus helpers/docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 23:01:11 +08:00
564d6ac189 Allow in-process IM/cron session APIs when UDS ALS is unset.
Browser HTTP always enters withUserContext(null|identity); WhatsApp harness
calls session.create/prompt with no ALS frame. Treating undefined as
host-internal restores channel turns broken by the UDS session ACL.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:48 +08:00
ba60368f39 Fix session history after UDS login by binding identity on all ws stream upgrades.
Gateway Remote stream mux starts async session.follow after the sync message
listener returns; without patching every ws copy and awaiting identity, ACL
saw an empty ALS and failed history load as gateway/internal.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:09 +08:00
9a93e9c8ce Do not hide dsh-ops-cron task rows with the session-only projectRow CSS.
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 16:03:42 +08:00
bc93392a02 Expose udsAuth Cordis service for request identity and workspace paths.
Lets plugins such as dsh-ops-cron resolve empNo/role, provisioned cwd, and stamp session owners without reading roles.json directly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:49:58 +08:00
c41991057d Restore workspace partitions for super admins; only force flat after auth-ready.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:17:18 +08:00
f98d283118 Wait for workspaceRegistry before provisioning user workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:03:06 +08:00
e9040224fb Force flat session sidebar for users without workspace create.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:57:23 +08:00
1b397c6733 Unblock composer for normal QR users after login.
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:45:52 +08:00
6b24fd15da Use soft reconnect on logout instead of full page reload.
Hard reload stays only after login so Set-Cookie is committed before WS upgrade.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:36:35 +08:00
bad000d5b6 Use workspace membership as session ACL; keep owners for audit.
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:25:52 +08:00
97dbfc4940 Reload after login so session history keeps WS identity.
Soft reconnect raced Set-Cookie and left session.page unauthenticated while prompt still worked.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:10:15 +08:00
1053403d88 Prefer soft reconnect after UDS login instead of full reload.
Workspace ACL no longer depends on a hard refresh; keep reload only as fallback.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:45:07 +08:00
4a477f3513 Stop ACL from wiping local workspace partitions for fallback_admin.
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:33:46 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
3e5c1f846e Fix local fallback_admin workspace list on HTTP.
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:20:10 +08:00
93526e7d45 Seed fallback_admin password Admin@123 on first start.
roles.json missing the hash field (or absent) enables the emergency account; an explicit null keeps it disabled.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:10:36 +08:00
337f6501b0 Enable fallback_admin by default with Admin@123.
Initial deploys often cannot scan UAC QR; seed the emergency account unless roles.json explicitly disabled it.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:09:14 +08:00
6455feed65 Fix fallback_admin logout so badge returns to 未登录.
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:58:47 +08:00
ed562f7c21 Fix anonymous blank UI and stale session restore.
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:51:08 +08:00
d0f77d2d4e Clear restored session when UDS user is anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:41:02 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
17fc093a2d Clear UDS_FALLBACK_UI on server logout. 2026-09-08 10:29:28 +08:00
7d4d228317 Clear UDS_FALLBACK_UI cookie on logout. 2026-09-08 10:29:09 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
42c5dd2c35 Simplify footer auth badge to username and anchor panel above it.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:17:30 +08:00
cf5c9d5060 Reconnect remote.mux after UDS login so session history uses new cookies.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:10:37 +08:00
7b893d9b3b Bind UDS identity on WebSocket via Host ws module; hide workspaces when anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:04:33 +08:00
382264f9d6 Resolve UDS ACL identity from cookies when sessionStore is empty.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:58:27 +08:00
a283b5cdc6 Fix workspace visibility: registry inject and WebSocket UDS identity. 2026-09-08 09:51:52 +08:00
ee0a49f381 Repair dsh-acl WebSocket identity patch syntax.
Restore a valid patchWebSocketServerForUdsIdentity implementation after a bad edit.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:49:30 +08:00
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00