Give admin the same permissions as super/fallback, occupy directoryFlow at priority 1 so the button renders without colliding with the native picker, and inject uiWorkspace for pickDirectory.
Co-authored-by: Cursor <cursoragent@cursor.com>
Remove directory-flow reload, only shadow the picker while anonymous, and stop clearing login attrs on AuthBadge unmount so flat↔workspace observers cannot loop.
Co-authored-by: Cursor <cursoragent@cursor.com>
Directory-flow gate was shadowing the native picker; clearing it left an empty hole so Add workspace never rendered. Reload once when permission flips on, and harden canCreateWorkspace detection from role/permissions.
Co-authored-by: Cursor <cursoragent@cursor.com>
super_admin/fallback_admin already could; admin now has canCreateWorkspace, and Host-side creates without browser ALS (IM) are no longer blocked as forbidden.
Co-authored-by: Cursor <cursoragent@cursor.com>
Super/fallback can toggle view-all (default on); admin/user stay own-only while still seeing unowned system sessions. Add restore/prune helpers so empty-shell cleanup is explicit and recoverable.
Skip startup /api/me until QR load, stop blocking me on workspace provision, and register the footer login entry before heavy ACL gates so login appears immediately.
Co-authored-by: Cursor <cursoragent@cursor.com>
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.
Co-authored-by: Cursor <cursoragent@cursor.com>
Move the public auth helper skill under uds-auth/skills and update docs to point there instead of the repo-root skills tree.
Co-authored-by: Cursor <cursoragent@cursor.com>
Business skills depend on this sibling skill instead of the plugin source tree; update the auth standard docs accordingly.
Co-authored-by: Cursor <cursoragent@cursor.com>
UI session behavior stays unchanged; login writes a separate skill cache, with optional retain-on-logout and loopback agent-credentials/outbound APIs plus helpers/docs.
Co-authored-by: Cursor <cursoragent@cursor.com>
Browser HTTP always enters withUserContext(null|identity); WhatsApp harness
calls session.create/prompt with no ALS frame. Treating undefined as
host-internal restores channel turns broken by the UDS session ACL.
Co-authored-by: Cursor <cursoragent@cursor.com>
Gateway Remote stream mux starts async session.follow after the sync message
listener returns; without patching every ws copy and awaiting identity, ACL
saw an empty ALS and failed history load as gateway/internal.
Co-authored-by: Cursor <cursoragent@cursor.com>
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.
Co-authored-by: Cursor <cursoragent@cursor.com>
Lets plugins such as dsh-ops-cron resolve empNo/role, provisioned cwd, and stamp session owners without reading roles.json directly.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.
Co-authored-by: Cursor <cursoragent@cursor.com>
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.
Co-authored-by: Cursor <cursoragent@cursor.com>
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
roles.json missing the hash field (or absent) enables the emergency account; an explicit null keeps it disabled.
Co-authored-by: Cursor <cursoragent@cursor.com>
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>