Commit graph

16 commits

Author SHA1 Message Date
f98d283118 Wait for workspaceRegistry before provisioning user workspaces.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:03:06 +08:00
1b397c6733 Unblock composer for normal QR users after login.
Stop leaving pointer-events locks on the inert workspace card, and auto-bind the provisioned personal workspace from /api/me.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:45:52 +08:00
bad000d5b6 Use workspace membership as session ACL; keep owners for audit.
Session RPC access checks visible workspaces (and cwd), wraps prompt and related methods with address.sessionId extraction, and gates create paths for non-admins.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 14:25:52 +08:00
3e5c1f846e Fix local fallback_admin workspace list on HTTP.
Drop Secure cookies when not HTTPS so WS upgrades keep UDS_FALLBACK_*, and accept UDS_FALLBACK_UI for ACL identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 11:20:10 +08:00
655655d878 Fix fallback_admin session list when HttpOnly cookie hides empNo from JS.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:28:45 +08:00
7b893d9b3b Bind UDS identity on WebSocket via Host ws module; hide workspaces when anonymous.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 10:04:33 +08:00
a5ba9d52cc Fix workspaceRegistry inject and restore WS UDS identity.
Stop Cordis throws on ctx.workspaceRegistry, inject the registry handle for provisioning, and bind login identity onto remote.mux WebSocket listeners so super_admin keeps all workspaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 09:48:44 +08:00
92ee170b2e Enforce multi-user ACL for sessions, settings, and workspaces.
Bridge UDS identity into DSH RPC via ALS, stamp/filter sessions, auto-provision per-empNo workspaces, and hide Settings/Add-workspace for roles that lack those permissions.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 04:29:48 +08:00
b3b5b6997e Fix first-login bootstrap to super_admin; allow admin settings via canAccessSettings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 03:23:20 +08:00
9ff9635624 Query user profile via intranet direct HTTP; upgrade/clear trust sessions without department.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:50:34 +08:00
74a86ff832 Fix QR login: pass userSearchUrl into auth middleware for token+empNo verify.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 02:37:08 +08:00
74ea52667d Fix duplicate /uds-auth route: drop rpc.handle, register webServer prefix once. 2026-09-08 02:04:57 +08:00
c9ca785155 Register /uds-auth/qr-start and fix crypto imports for QR login. 2026-09-08 01:54:42 +08:00
3aca99ca93 Fix uds-auth qr-start 404 by registering route and top-level crypto import. 2026-09-08 01:54:02 +08:00
505f9dea3f Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00
8ca42dd973 change log in 2026-09-08 00:28:58 +08:00