Gateway Remote stream mux starts async session.follow after the sync message
listener returns; without patching every ws copy and awaiting identity, ACL
saw an empty ALS and failed history load as gateway/internal.
Co-authored-by: Cursor <cursoragent@cursor.com>
Exclude .dsh-ct-project from the flat-sidebar hide rule and from the auto-expand clicker so admin users can see scheduled tasks again.
Co-authored-by: Cursor <cursoragent@cursor.com>
Lets plugins such as dsh-ops-cron resolve empNo/role, provisioned cwd, and stamp session owners without reading roles.json directly.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.
Co-authored-by: Cursor <cursoragent@cursor.com>
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.
Co-authored-by: Cursor <cursoragent@cursor.com>
workspace.follow no longer emits an empty baseline when ALS identity is missing, and administrator/fallback_admin always pass the workspace allow-list.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for WS identity before emptying workspace.follow, and hard-reload after login so the first subscribe is not stuck with an anonymous empty baseline.
Co-authored-by: Cursor <cursoragent@cursor.com>
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.
Co-authored-by: Cursor <cursoragent@cursor.com>
roles.json missing the hash field (or absent) enables the emergency account; an explicit null keeps it disabled.
Co-authored-by: Cursor <cursoragent@cursor.com>
Clear Secure cookies to match login Set-Cookie attrs, and setUser(null) on logout so the UI does not keep the stale session.
Co-authored-by: Cursor <cursoragent@cursor.com>
Wait for /api/me before clearing sessions, ignore portal cookies for login gate, and stop hiding ConversationRoot when logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>
Capture identity when workspace.follow starts and passthrough for canViewAllSessions so historical pre-plugin workspaces stay visible.
Co-authored-by: Cursor <cursoragent@cursor.com>
The workspace picker opens from data-composer-card with cardWorkspaceTrigger, not the aria-label node; lock that surface for non-creators.
Co-authored-by: Cursor <cursoragent@cursor.com>
Keep data-uds-logged-in at 0, occupy directory-flow immediately, and freeze the choose-workspace control so the native folder dialog cannot open while logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Anonymous and normal users no longer open the OS folder dialog from the empty chat hero; only super_admin can pick/create directories. Host gates directoryPicker.pick/list/createDirectory and the client cancels directoryFlow when canCreateWorkspace is false.
Co-authored-by: Cursor <cursoragent@cursor.com>
Reject anonymous /dsh-ops-cron requests after session validation, hide the 定时任务 chrome when logged out, and block client fetch to the cron HTTP API.
Co-authored-by: Cursor <cursoragent@cursor.com>
Filter session.list/search on the client when cookies are absent, ignore broadcast session-added events, and deepen host listState wrapping so ungrouped rows no longer leak while logged out.
Co-authored-by: Cursor <cursoragent@cursor.com>
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.
Co-authored-by: Cursor <cursoragent@cursor.com>