Commit graph

6 commits

Author SHA1 Message Date
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
42618379a5 Fix super_admin workspace list lost on follow ALS gap.
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:36:17 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00