mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-09 00:02:30 +00:00
make superadmin_email permission be inherited by ephemeral tokens
This commit is contained in:
@@ -6,6 +6,8 @@
|
||||
* LICENSE-AGPL for a copy of the license.
|
||||
*/
|
||||
|
||||
pub const SUPERADMIN_SECRET_EMAIL: &str = "superadmin_secret@windmill.dev";
|
||||
|
||||
pub fn username_to_permissioned_as(user: &str) -> String {
|
||||
if user.contains('@') {
|
||||
user.to_string()
|
||||
|
||||
@@ -25,7 +25,7 @@ use windmill_common::{
|
||||
flows::{FlowModuleValue, FlowValue},
|
||||
scripts::{ScriptHash, ScriptLang},
|
||||
utils::rd_string,
|
||||
variables, BASE_URL,
|
||||
variables, BASE_URL, users::SUPERADMIN_SECRET_EMAIL,
|
||||
};
|
||||
use windmill_queue::{canceled_job_to_result, get_queued_job, pull, JobKind, QueuedJob, CLOUD_HOSTED};
|
||||
|
||||
@@ -241,7 +241,7 @@ pub async fn create_token_for_owner<'c>(
|
||||
let is_super_admin = sqlx::query_scalar!("SELECT super_admin FROM password WHERE email = $1", email)
|
||||
.fetch_optional(&mut tx)
|
||||
.await?
|
||||
.unwrap_or(false);
|
||||
.unwrap_or(false) || email == SUPERADMIN_SECRET_EMAIL;
|
||||
|
||||
sqlx::query_scalar!(
|
||||
"INSERT INTO token
|
||||
|
||||
Reference in New Issue
Block a user