make superadmin_email permission be inherited by ephemeral tokens

This commit is contained in:
Ruben Fiszel
2023-03-24 13:22:56 +01:00
parent cd0ca8d662
commit 5aa0be8112
2 changed files with 4 additions and 2 deletions
+2
View File
@@ -6,6 +6,8 @@
* LICENSE-AGPL for a copy of the license.
*/
pub const SUPERADMIN_SECRET_EMAIL: &str = "superadmin_secret@windmill.dev";
pub fn username_to_permissioned_as(user: &str) -> String {
if user.contains('@') {
user.to_string()
+2 -2
View File
@@ -25,7 +25,7 @@ use windmill_common::{
flows::{FlowModuleValue, FlowValue},
scripts::{ScriptHash, ScriptLang},
utils::rd_string,
variables, BASE_URL,
variables, BASE_URL, users::SUPERADMIN_SECRET_EMAIL,
};
use windmill_queue::{canceled_job_to_result, get_queued_job, pull, JobKind, QueuedJob, CLOUD_HOSTED};
@@ -241,7 +241,7 @@ pub async fn create_token_for_owner<'c>(
let is_super_admin = sqlx::query_scalar!("SELECT super_admin FROM password WHERE email = $1", email)
.fetch_optional(&mut tx)
.await?
.unwrap_or(false);
.unwrap_or(false) || email == SUPERADMIN_SECRET_EMAIL;
sqlx::query_scalar!(
"INSERT INTO token