mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-08 22:20:54 +08:00
Move the public auth helper skill under uds-auth/skills and update docs to point there instead of the repo-root skills tree. Co-authored-by: Cursor <cursoragent@cursor.com>
2.5 KiB
2.5 KiB
uds-auth
DeepSeek Harness 的 UDS 统一认证插件:右上角登录徽章 + 设置页用户管理。
安装
dsh plugin --profile web add -w "D:/project/chatgpt/oclaw/uds-auth"
安装后重启 Harness。登录徽章在 shell.overlay(右上角);用户管理/部署配置在 设置 → UDS 认证(settings.section)。
配置
在 设置 → UDS 认证 或 cordis.patch.yml 中修改:
uacBaseUrl: https://uac.zte.com.cn
userSearchUrl: https://icenterapi.zte.com.cn/zte-km-icenter-addresearch/user/plain/docs/search
loginSystemCode: '100000455558'
originSystemCode: ''
标准 DSH 插件结构
| 部分 | 路径 | 说明 |
|---|---|---|
| Host | lib/index.js |
Cordis apply:HTTP /uds-auth/*、可选 schema 设置 |
| Client | lib/client.js |
右上角登录 + 设置页用户管理 |
| Bundle | cordis.patch.yml |
insert 插件层(不含 client.entry) |
| Meta | package.json → dsh.client |
exports["./client"] + slots inject |
API
POST /uds-auth/qr-start— 服务端生成扫码挑战GET /uds-auth/qr?data=— 二维码 SVGPOST /uds-auth/qr-proxy— 代理 UAC 扫码校验GET /uds-auth/api/me— 当前用户POST /uds-auth/api/logout— 登出(UI 会话;skill 凭证是否保留见配置)GET|POST /uds-auth/agent-credentials— loopback:按DSH_SESSION_ID取 skill 用 empNo+tokenPOST /uds-auth/outbound— loopback:白名单出站并注入鉴权头- 用户管理 / 兜底管理员:见
/uds-auth/api/users*、/uds-auth/api/fallback/* - 默认兜底账号(扫码不可用时):用户名
administrator,密码Admin@123(首次启动自动启用;可在设置中改密或关闭) - ACL:租户边界以工作区为准(可见工作区下的会话可访问);
session-owners.json仅记录工号供导出/分析,不是主鉴权键
Skill 认证(给他人改造 skill 时)
发整个 uds-auth 插件 即可,内含:
- 标准:docs/skill-auth-standard.zh.md
- 公共 skill 说明:docs/uds-skill-auth.zh.md
- 公共 skill 本体:skills/uds-skill-auth/(随插件提交)
现场:装插件 → 把 skills/uds-skill-auth 配进 skills 路径 → 扫码 → 再装业务 skill。
可配置:retainSkillCredentialsOnLogout(默认 true)、skillCredentialTtlSeconds、outboundAllowedHosts。
License
MIT