Commit graph

24 commits

Author SHA1 Message Date
92a6827aef Clarify session visibility docs after view-all-off tightening.
Some checks failed
ci / test (push) Has been cancelled
ci / test-postgresql (push) Has been cancelled
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 23:52:33 +08:00
ef57e05942 Honor view-all off: only own sessions and personal workspace.
Shared project and channel sessions were still visible via canViewSystemSessions when the toggle was off; tighten ACL and copy so off means own only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 23:52:02 +08:00
91d2515205 Unify admin-class workspace create and restore Add-workspace UI.
Give admin the same permissions as super/fallback, occupy directoryFlow at priority 1 so the button renders without colliding with the native picker, and inject uiWorkspace for pickDirectory.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 22:46:45 +08:00
89700ef4f9 Allow admin (and Host plugins) to create workspaces.
super_admin/fallback_admin already could; admin now has canCreateWorkspace, and Host-side creates without browser ALS (IM) are no longer blocked as forbidden.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 21:52:14 +08:00
ad0cc98b38 Make session visibility preference-driven and keep system-channel ACL separate.
Super/fallback can toggle view-all (default on); admin/user stay own-only while still seeing unowned system sessions. Add restore/prune helpers so empty-shell cleanup is explicit and recoverable.
2026-09-14 20:48:15 +08:00
e2c2e949ed Restrict @ mention and session query ACL so admin/user only see owned or workspace sessions.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 00:30:46 +08:00
fd0df9b890 Add uds-auth zh/en i18n, UAC-branded settings, and QR expire/fail overlay.
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:10:37 +08:00
564d6ac189 Allow in-process IM/cron session APIs when UDS ALS is unset.
Browser HTTP always enters withUserContext(null|identity); WhatsApp harness
calls session.create/prompt with no ALS frame. Treating undefined as
host-internal restores channel turns broken by the UDS session ACL.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:48 +08:00
ba60368f39 Fix session history after UDS login by binding identity on all ws stream upgrades.
Gateway Remote stream mux starts async session.follow after the sync message
listener returns; without patching every ws copy and awaiting identity, ACL
saw an empty ALS and failed history load as gateway/internal.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 19:43:09 +08:00
bad000d5b6 Use workspace membership as session ACL; keep owners for audit.
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:25:52 +08:00
4a477f3513 Stop ACL from wiping local workspace partitions for fallback_admin.
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:33:46 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
3e5c1f846e Fix local fallback_admin workspace list on HTTP.
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:20:10 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
7b893d9b3b Bind UDS identity on WebSocket via Host ws module; hide workspaces when anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:04:33 +08:00
382264f9d6 Resolve UDS ACL identity from cookies when sessionStore is empty.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:58:27 +08:00
a283b5cdc6 Fix workspace visibility: registry inject and WebSocket UDS identity. 2026-09-08 09:51:52 +08:00
ee0a49f381 Repair dsh-acl WebSocket identity patch syntax.
Restore a valid patchWebSocketServerForUdsIdentity implementation after a bad edit.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:49:30 +08:00
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
42618379a5 Fix super_admin workspace list lost on follow ALS gap.
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:36:17 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00