mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-12 06:50:48 +08:00
Emergency (fallback / sealed-box) admins lost the workspace sidebar and saw "sign-in failed / add API key" on DSH Desktop because the remote.mux opens anonymously at boot and every early call was rejected terminally. - gateway: anonymous workspace/follow reaches dsh-acl's empty baseline; anonymous streams are parked until the carrier aborts instead of failing; anonymous workspace/initializeDefault answers "nothing created" - request-auth: a dead UDS_SESSION cookie no longer shadows a valid WS ticket or bridge (sync + async variants used by all callers) - dsh-acl: /api/* waits (bounded 15s) for the gateway ACL during Host startup instead of 403, so the Desktop welcome read no longer fails - desktop-bootstrap: key/account projection is best-effort per reference - client: emit connection/reset after login so boot-time caches (settings describe mirror -> Settings > Models) re-read under the real principal - sessions: absolute lifetime fixed at 7 days (was min(ttl, 7d) = 30 min); bridge expiry slides with its session; MemoryStore persisted to sessions.json (bearer hash only, userData AES-256-GCM sealed) - README: session lifetime/persistence and DSH compatibility notes Also includes previously uncommitted uds-auth 0.3.x work in this tree. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
71 lines
2.9 KiB
JavaScript
71 lines
2.9 KiB
JavaScript
import assert from 'node:assert/strict'
|
|
import test from 'node:test'
|
|
import { getUserContext, runAsHost, withUserContext } from '../lib/context.js'
|
|
import { installDshAcl } from '../lib/dsh-acl.js'
|
|
import { MemoryStore } from '../lib/session/memory-store.js'
|
|
|
|
test('Host callback context is isolated across concurrent browser identities and exceptions', async () => {
|
|
const identities = [null, { empNo: 'u1' }, { empNo: 'u2' }]
|
|
await Promise.all(identities.map(identity => withUserContext(identity, async () => {
|
|
assert.equal(await runAsHost(async () => {
|
|
await Promise.resolve()
|
|
assert.equal(getUserContext(), undefined)
|
|
return 'host-result'
|
|
}), 'host-result')
|
|
assert.equal(getUserContext(), identity)
|
|
assert.throws(() => runAsHost(() => { throw new Error('failed') }), /failed/)
|
|
assert.equal(getUserContext(), identity)
|
|
})))
|
|
assert.equal(runAsHost(() => 42), 42)
|
|
assert.throws(() => runAsHost(null), TypeError)
|
|
})
|
|
|
|
test('trusted Host creation works from browser ALS while unauthenticated browser creation stays denied', async () => {
|
|
let creations = 0
|
|
const owners = []
|
|
const sessionStore = new MemoryStore()
|
|
const minted = await sessionStore.create({ empNo: 'u1' }, 600)
|
|
const controller = {
|
|
async list() { return { items: [] } },
|
|
async search() { return { items: [] } },
|
|
async create(request) {
|
|
creations += 1
|
|
return { sessionId: `session-${creations}`, request }
|
|
},
|
|
}
|
|
installDshAcl({
|
|
on() { return () => {} },
|
|
get() { return undefined },
|
|
inject(names, callback) {
|
|
if (names[0] === 'sessionController') callback({ sessionController: controller })
|
|
},
|
|
}, {
|
|
sessionAcl: { getOwner() { return null }, setOwner: (...args) => owners.push(args) },
|
|
userWorkspaces: { isUserPath: (empNo, path) => path === `/ws/${empNo}`, get() { return null } },
|
|
getWorkspaceRoot: () => '/ws',
|
|
getWorkspaceRegistry: () => undefined,
|
|
getSessionStore: () => sessionStore,
|
|
})
|
|
await withUserContext(null, async () => {
|
|
await assert.rejects(controller.create({ cwd: '/bot' }), error => (
|
|
error.details.udsError === 'login_required_create_session'
|
|
))
|
|
const result = await runAsHost(() => controller.create({ cwd: '/bot', agentPreset: 'netxops' }))
|
|
assert.deepEqual(result.request, { cwd: '/bot', agentPreset: 'netxops' })
|
|
assert.equal(getUserContext(), null)
|
|
await assert.rejects(controller.create({ cwd: '/bot' }))
|
|
})
|
|
assert.equal(creations, 1)
|
|
assert.deepEqual(owners, [], 'background sessions must not inherit a browser owner')
|
|
await withUserContext({
|
|
empNo: 'u1',
|
|
sessionId: minted.sessionId,
|
|
permissions: {},
|
|
}, async () => {
|
|
await assert.rejects(controller.create({ cwd: '/other' }), error => (
|
|
error.details.udsError === 'session_workspace_only'
|
|
))
|
|
await controller.create({ cwd: '/ws/u1' })
|
|
})
|
|
assert.deepEqual(owners, [['session-2', 'u1']])
|
|
})
|