Directory-flow gate was shadowing the native picker; clearing it left an empty hole so Add workspace never rendered. Reload once when permission flips on, and harden canCreateWorkspace detection from role/permissions.
Co-authored-by: Cursor <cursoragent@cursor.com>
super_admin/fallback_admin already could; admin now has canCreateWorkspace, and Host-side creates without browser ALS (IM) are no longer blocked as forbidden.
Co-authored-by: Cursor <cursoragent@cursor.com>
Super/fallback can toggle view-all (default on); admin/user stay own-only while still seeing unowned system sessions. Add restore/prune helpers so empty-shell cleanup is explicit and recoverable.
Skip startup /api/me until QR load, stop blocking me on workspace provision, and register the footer login entry before heavy ACL gates so login appears immediately.
Co-authored-by: Cursor <cursoragent@cursor.com>
Status probes often fail with the QR request, so default fallback on and always show the link on QR error/expiry.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wire client locale to the DSH host, return stable API error codes with localized messages, and replace bottom refresh with an in-frame retry for expired or offline QR.
Co-authored-by: Cursor <cursoragent@cursor.com>
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.
Co-authored-by: Cursor <cursoragent@cursor.com>
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.
Co-authored-by: Cursor <cursoragent@cursor.com>
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.
Co-authored-by: Cursor <cursoragent@cursor.com>
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.
Co-authored-by: Cursor <cursoragent@cursor.com>
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.
Co-authored-by: Cursor <cursoragent@cursor.com>