oclaw/uds-auth
oliver 92a6827aef
Some checks failed
ci / test (push) Has been cancelled
ci / test-postgresql (push) Has been cancelled
Clarify session visibility docs after view-all-off tightening.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 23:52:33 +08:00
..
docs Bundle uds-skill-auth inside the uds-auth plugin for single-package handoff. 2026-09-08 23:46:11 +08:00
lib Clarify session visibility docs after view-all-off tightening. 2026-09-16 23:52:33 +08:00
scripts Make session visibility preference-driven and keep system-channel ACL separate. 2026-09-14 20:48:15 +08:00
skill-helpers Bundle uds-skill-auth inside the uds-auth plugin for single-package handoff. 2026-09-08 23:46:11 +08:00
skills/uds-skill-auth Bundle uds-skill-auth inside the uds-auth plugin for single-package handoff. 2026-09-08 23:46:11 +08:00
test Honor view-all off: only own sessions and personal workspace. 2026-09-16 23:52:02 +08:00
.gitignore Unify admin-class workspace create and restore Add-workspace UI. 2026-09-16 22:46:45 +08:00
config.default.yaml Add parallel skill credential path to uds-auth for agent/cron use. 2026-09-08 23:01:11 +08:00
cordis.patch.yml Enforce multi-user ACL for sessions, settings, and workspaces. 2026-09-08 04:29:48 +08:00
package-lock.json Restore uds-auth in oclaw: DSH plugin with token+profile auth, settings UI, and pagination. 2026-09-08 01:46:17 +08:00
package.json Honor view-all off: only own sessions and personal workspace. 2026-09-16 23:52:02 +08:00
pnpm-lock.yaml change log in 2026-09-08 00:28:58 +08:00
README.md Add decrypt-to-unlock local admin via sealed env box. 2026-09-12 22:16:21 +08:00
README.zh.md Make session visibility preference-driven and keep system-channel ACL separate. 2026-09-14 20:48:15 +08:00

uds-auth

UDS authentication plugin for DeepSeek Harness: fixed sidebar login badge + host session/role APIs.

Install

dsh plugin --profile web add -w "D:/project/chatgpt/oclaw/uds-auth"

Restart Harness after install. The badge mounts on sidebar.footer.action (root scope).

Config

uacBaseUrl: https://uac.zte.com.cn
userSearchUrl: https://icenterapi.zte.com.cn/zte-km-icenter-addresearch/user/plain/docs/search
loginSystemCode: '100000455558'
originSystemCode: ''
retainSkillCredentialsOnLogout: true
skillCredentialTtlSeconds: 604800
outboundAllowedHosts: icenterapi.zte.com.cn,icentermsg.dt.zte.com.cn

Skill auth standard (Chinese): docs/skill-auth-standard.zh.md.

Bundled skill: skills/uds-skill-auth. Handoff notes: docs/uds-skill-auth.zh.md.

Loopback agent APIs: GET|POST /uds-auth/agent-credentials, POST /uds-auth/outbound.

Local admin unlock (optional, decrypt-to-login)

  1. node scripts/seal-local-admin.mjs "your-passphrase"
  2. Set printed UDS_AUTH_LOCAL_ADMIN_BOX=... on the Harness process (ciphertext only)
  3. Login panel → “Unlock with local key” → enter passphrase

Env alone does not grant admin. Legacy UDS_AUTH_LOCAL_ADMIN_KEY is ignored.

Layout

Piece Path Role
Host lib/index.js Cordis apply: settings, RPC, /uds-auth/*
Client lib/client.js ModuleLoader + React footer login card
Bundle cordis.patch.yml layer insert only
Meta package.json dsh.client ./client + slots inject

The login panel uses position: fixed with a measured trigger anchor (same pattern as CordisPanel) so the sidebar overflow clip cannot hide it.

License

MIT