mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-12 06:43:17 +08:00
Emergency (fallback / sealed-box) admins lost the workspace sidebar and saw "sign-in failed / add API key" on DSH Desktop because the remote.mux opens anonymously at boot and every early call was rejected terminally. - gateway: anonymous workspace/follow reaches dsh-acl's empty baseline; anonymous streams are parked until the carrier aborts instead of failing; anonymous workspace/initializeDefault answers "nothing created" - request-auth: a dead UDS_SESSION cookie no longer shadows a valid WS ticket or bridge (sync + async variants used by all callers) - dsh-acl: /api/* waits (bounded 15s) for the gateway ACL during Host startup instead of 403, so the Desktop welcome read no longer fails - desktop-bootstrap: key/account projection is best-effort per reference - client: emit connection/reset after login so boot-time caches (settings describe mirror -> Settings > Models) re-read under the real principal - sessions: absolute lifetime fixed at 7 days (was min(ttl, 7d) = 30 min); bridge expiry slides with its session; MemoryStore persisted to sessions.json (bearer hash only, userData AES-256-GCM sealed) - README: session lifetime/persistence and DSH compatibility notes Also includes previously uncommitted uds-auth 0.3.x work in this tree. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
19 lines
1,001 B
YAML
19 lines
1,001 B
YAML
# uds-auth defaults — trusted single-instance (not strong multi-tenant)
|
|
uacBaseUrl: https://uac.zte.com.cn
|
|
userSearchUrl: https://icenterapi.zte.com.cn/zte-km-icenter-addresearch/user/plain/docs/search
|
|
loginSystemCode: '100000455558'
|
|
originSystemCode: ''
|
|
workspaceRoot: ''
|
|
# Explicit first super_admin when roles.json is empty (also: UDS_AUTH_INITIAL_ADMIN)
|
|
initialAdminEmpNo: ''
|
|
# When roles already exist, auto-register unknown UAC users as role=user
|
|
allowOpenRegistration: true
|
|
# Raw /agent-credentials token response (loopback) — off by default; prefer outbound + task capability
|
|
allowRawAgentToken: false
|
|
retainSkillCredentialsOnLogout: true
|
|
skillCredentialTtlSeconds: 604800
|
|
outboundAllowedHosts: icenterapi.zte.com.cn,icentermsg.dt.zte.com.cn
|
|
# Optional exact Host allowlist for /uds-auth writes; empty = Origin must match Host only
|
|
trustedHosts: ''
|
|
# Emergency fallback password is NOT enabled by default. Set via Settings (min 10 chars).
|
|
# Legacy Admin@123 hashes are refused on upgrade.
|