Commit graph

28 commits

Author SHA1 Message Date
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
42618379a5 Fix super_admin workspace list lost on follow ALS gap.
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:36:17 +08:00
1f2ff7e00b Block inert composer card clicks unless super_admin.
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:25:43 +08:00
1fc39a3210 Gate open-workspace UI to super_admin only.
Non-super users keep their auto-provisioned workspace; hide Choose workspace and keep the picker locked unless canCreateWorkspace is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:22:15 +08:00
52fc39f71e Lock workspace chooser for anonymous users before first click.
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:13:03 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
9d16301700 Match UDS login chrome to Settings trigger; sit login near sidebar edge.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:00:29 +08:00
1ac1aec952 Lay Settings and UDS login on one sidebar foot row side by side.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:54:08 +08:00
e052ef4bf4 Pin UDS login to sidebar.footer.action (stable foot next to Settings, right-aligned).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:50:19 +08:00
7e2d8ef5d8 Avoid login badge overlapping Session log: header when in session, overlay only when idle.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:44:12 +08:00
705c6864ef Show UDS login on shell.overlay so it is visible without an active session.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:39:58 +08:00
8f569070a0 Remove broken /settings shortcut from UDS login badge panel.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:34:25 +08:00
b3b5b6997e Fix first-login bootstrap to super_admin; allow admin settings via canAccessSettings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:23:20 +08:00
9ff9635624 Query user profile via intranet direct HTTP; upgrade/clear trust sessions without department.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:50:34 +08:00
74a86ff832 Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:37:08 +08:00
b535714000 Move UDS login into header.utilities so it sits left of session log-download.
EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:22:43 +08:00
91a1804f68 Place UDS login beside session log-download in the same header.actions slot. 2026-09-08 02:17:17 +08:00
b4fa832a6b Move UDS login back to top-right overlay, docked left of toggles with matching chrome style. 2026-09-08 02:13:25 +08:00
74ea52667d Fix duplicate /uds-auth route: drop rpc.handle, register webServer prefix once. 2026-09-08 02:04:57 +08:00
6caafe9590 Fix uds-auth client.js syntax error that broke the whole plugin bundle. 2026-09-08 02:00:55 +08:00
6360f80349 Move UDS login badge into session header actions to avoid covering Search/toggles. 2026-09-08 01:58:31 +08:00
c9ca785155 Register /uds-auth/qr-start and fix crypto imports for QR login. 2026-09-08 01:54:42 +08:00
3aca99ca93 Fix uds-auth qr-start 404 by registering route and top-level crypto import. 2026-09-08 01:54:02 +08:00
505f9dea3f Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00
8ca42dd973 change log in 2026-09-08 00:28:58 +08:00