Commit graph

46 commits

Author SHA1 Message Date
ab926969f6 Restore Add-workspace after granting create permission.
Directory-flow gate was shadowing the native picker; clearing it left an empty hole so Add workspace never rendered. Reload once when permission flips on, and harden canCreateWorkspace detection from role/permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 21:58:19 +08:00
89700ef4f9 Allow admin (and Host plugins) to create workspaces.
super_admin/fallback_admin already could; admin now has canCreateWorkspace, and Host-side creates without browser ALS (IM) are no longer blocked as forbidden.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 21:52:14 +08:00
ad0cc98b38 Make session visibility preference-driven and keep system-channel ACL separate.
Super/fallback can toggle view-all (default on); admin/user stay own-only while still seeing unowned system sessions. Add restore/prune helpers so empty-shell cleanup is explicit and recoverable.
2026-09-14 20:48:15 +08:00
c26dc68f77 Add decrypt-to-unlock local admin via sealed env box.
Replace auto-grant-on-env with AES-GCM box + passphrase unlock, rebuild fallback sessions after restart, and document seal script usage.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 22:16:21 +08:00
922abaa89e Restore uds-auth session on badge mount so login survives reload.
Calling /api/me only when opening the QR panel left users stuck on 未登录 until they clicked the badge.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 21:11:15 +08:00
81ff8eb19f Speed up uds-auth login: paint badge first, lazy /api/me.
Skip startup /api/me until QR load, stop blocking me on workspace provision, and register the footer login entry before heavy ACL gates so login appears immediately.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 12:29:49 +08:00
627e61aa80 Keep emergency login visible when QR fetch fails.
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-10 02:04:42 +08:00
fd0df9b890 Add uds-auth zh/en i18n, UAC-branded settings, and QR expire/fail overlay.
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 22:10:37 +08:00
9a93e9c8ce Do not hide dsh-ops-cron task rows with the session-only projectRow CSS.
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 16:03:42 +08:00
c41991057d Restore workspace partitions for super admins; only force flat after auth-ready.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:17:18 +08:00
e9040224fb Force flat session sidebar for users without workspace create.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:57:23 +08:00
1b397c6733 Unblock composer for normal QR users after login.
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:45:52 +08:00
6b24fd15da Use soft reconnect on logout instead of full page reload.
Hard reload stays only after login so Set-Cookie is committed before WS upgrade.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:36:35 +08:00
97dbfc4940 Reload after login so session history keeps WS identity.
Soft reconnect raced Set-Cookie and left session.page unauthenticated while prompt still worked.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:10:15 +08:00
1053403d88 Prefer soft reconnect after UDS login instead of full reload.
Workspace ACL no longer depends on a hard refresh; keep reload only as fallback.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:45:07 +08:00
e479fe0833 Fix fallback_admin missing workspaces after fresh login.
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:27:05 +08:00
337f6501b0 Enable fallback_admin by default with Admin@123.
Initial deploys often cannot scan UAC QR; seed the emergency account unless roles.json explicitly disabled it.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:09:14 +08:00
6455feed65 Fix fallback_admin logout so badge returns to 未登录.
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:58:47 +08:00
ed562f7c21 Fix anonymous blank UI and stale session restore.
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:51:08 +08:00
d0f77d2d4e Clear restored session when UDS user is anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:41:02 +08:00
3ae13ce13d Hide workspaces when logged out: require token/fallback for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:35:20 +08:00
7d4d228317 Clear UDS_FALLBACK_UI cookie on logout. 2026-09-08 10:29:09 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
42c5dd2c35 Simplify footer auth badge to username and anchor panel above it.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:17:30 +08:00
cf5c9d5060 Reconnect remote.mux after UDS login so session history uses new cookies.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:10:37 +08:00
1f2ff7e00b Block inert composer card clicks unless super_admin.
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:25:43 +08:00
1fc39a3210 Gate open-workspace UI to super_admin only.
Non-super users keep their auto-provisioned workspace; hide Choose workspace and keep the picker locked unless canCreateWorkspace is set.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:22:15 +08:00
52fc39f71e Lock workspace chooser for anonymous users before first click.
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:13:03 +08:00
2072c10338 Block workspace directory picker unless super_admin.
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:30:55 +08:00
2cf253f6aa Gate dsh-ops-cron APIs and UI behind UDS login.
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 08:06:54 +08:00
db907a9489 Hide session list for anonymous UDS users.
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 07:53:35 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
9d16301700 Match UDS login chrome to Settings trigger; sit login near sidebar edge.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:00:29 +08:00
1ac1aec952 Lay Settings and UDS login on one sidebar foot row side by side.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:54:08 +08:00
e052ef4bf4 Pin UDS login to sidebar.footer.action (stable foot next to Settings, right-aligned).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:50:19 +08:00
7e2d8ef5d8 Avoid login badge overlapping Session log: header when in session, overlay only when idle.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:44:12 +08:00
705c6864ef Show UDS login on shell.overlay so it is visible without an active session.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:39:58 +08:00
8f569070a0 Remove broken /settings shortcut from UDS login badge panel.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:34:25 +08:00
b3b5b6997e Fix first-login bootstrap to super_admin; allow admin settings via canAccessSettings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:23:20 +08:00
74a86ff832 Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:37:08 +08:00
b535714000 Move UDS login into header.utilities so it sits left of session log-download.
EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:22:43 +08:00
91a1804f68 Place UDS login beside session log-download in the same header.actions slot. 2026-09-08 02:17:17 +08:00
b4fa832a6b Move UDS login back to top-right overlay, docked left of toggles with matching chrome style. 2026-09-08 02:13:25 +08:00
6caafe9590 Fix uds-auth client.js syntax error that broke the whole plugin bundle. 2026-09-08 02:00:55 +08:00
6360f80349 Move UDS login badge into session header actions to avoid covering Search/toggles. 2026-09-08 01:58:31 +08:00
505f9dea3f Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00