diff --git a/backend/ee-repo-ref.txt b/backend/ee-repo-ref.txt index fcceef3cbc..ba32e45732 100644 --- a/backend/ee-repo-ref.txt +++ b/backend/ee-repo-ref.txt @@ -1 +1 @@ -a20a007527c8d0355523b37c66c7ca242e06fab7 \ No newline at end of file +b6bb7beab73bfd477f6a9c0cc47faeff2b685e5f \ No newline at end of file diff --git a/backend/migrations/20240222074526_add_longer_limits_to_email.down.sql b/backend/migrations/20240222074526_add_longer_limits_to_email.down.sql new file mode 100644 index 0000000000..d2f607c5b8 --- /dev/null +++ b/backend/migrations/20240222074526_add_longer_limits_to_email.down.sql @@ -0,0 +1 @@ +-- Add down migration script here diff --git a/backend/migrations/20240222074526_add_longer_limits_to_email.up.sql b/backend/migrations/20240222074526_add_longer_limits_to_email.up.sql new file mode 100644 index 0000000000..a1fd87a78b --- /dev/null +++ b/backend/migrations/20240222074526_add_longer_limits_to_email.up.sql @@ -0,0 +1,5 @@ +-- Add up migration script here +ALTER TABLE usr ALTER COLUMN email TYPE VARCHAR(255); +ALTER TABLE password ALTER COLUMN email TYPE VARCHAR(255); +ALTER TABLE token ALTER COLUMN email TYPE VARCHAR(255); +ALTER TABLE workspace_invite ALTER COLUMN email TYPE VARCHAR(255); \ No newline at end of file diff --git a/backend/migrations/20240222120410_rename_scim_columns.down.sql b/backend/migrations/20240222120410_rename_scim_columns.down.sql new file mode 100644 index 0000000000..c9b3b8c945 --- /dev/null +++ b/backend/migrations/20240222120410_rename_scim_columns.down.sql @@ -0,0 +1,5 @@ +-- Add down migration script here +ALTER TABLE instance_group +DROP COLUMN external_id; +ALTER TABLE instance_group +RENAME COLUMN id TO external_id; \ No newline at end of file diff --git a/backend/migrations/20240222120410_rename_scim_columns.up.sql b/backend/migrations/20240222120410_rename_scim_columns.up.sql new file mode 100644 index 0000000000..aacfe0ad11 --- /dev/null +++ b/backend/migrations/20240222120410_rename_scim_columns.up.sql @@ -0,0 +1,5 @@ +-- Add up migration script here +ALTER TABLE instance_group +RENAME COLUMN external_id TO id; +ALTER TABLE instance_group +ADD COLUMN external_id VARCHAR(512); \ No newline at end of file diff --git a/backend/src/ee.rs b/backend/src/ee.rs deleted file mode 100644 index ef944b984b..0000000000 --- a/backend/src/ee.rs +++ /dev/null @@ -1,16 +0,0 @@ -use anyhow::anyhow; -#[cfg(feature = "enterprise")] -use windmill_common::error::{Error, Result}; - -pub async fn set_license_key(_license_key: String) -> anyhow::Result<()> { - // Implementation is not open source - Err(anyhow!("License cannot be set in Windmill CE")) -} - -#[cfg(feature = "enterprise")] -pub async fn verify_license_key() -> Result<()> { - // Implementation is not open source - Err(Error::InternalErr( - "License always invalid in Windmill CE".to_string(), - )) -} diff --git a/backend/src/ee.rs b/backend/src/ee.rs new file mode 120000 index 0000000000..ca288038c6 --- /dev/null +++ b/backend/src/ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/src/ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/ee.rs b/backend/windmill-api/src/ee.rs deleted file mode 100644 index a9d170a3ac..0000000000 --- a/backend/windmill-api/src/ee.rs +++ /dev/null @@ -1,6 +0,0 @@ -use anyhow::anyhow; - -pub async fn validate_license_key(_license_key: String) -> anyhow::Result { - // Implementation is not open source - Err(anyhow!("License can't be validated in Windmill CE")) -} diff --git a/backend/windmill-api/src/ee.rs b/backend/windmill-api/src/ee.rs new file mode 120000 index 0000000000..0267c6e6fd --- /dev/null +++ b/backend/windmill-api/src/ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/job_helpers_ee.rs b/backend/windmill-api/src/job_helpers_ee.rs deleted file mode 100644 index 61a946bb84..0000000000 --- a/backend/windmill-api/src/job_helpers_ee.rs +++ /dev/null @@ -1,5 +0,0 @@ -use axum::Router; - -pub fn workspaced_service() -> Router { - Router::new() -} diff --git a/backend/windmill-api/src/job_helpers_ee.rs b/backend/windmill-api/src/job_helpers_ee.rs new file mode 120000 index 0000000000..8cc4fbe8bf --- /dev/null +++ b/backend/windmill-api/src/job_helpers_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/job_helpers_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/oauth2_ee.rs b/backend/windmill-api/src/oauth2_ee.rs deleted file mode 100644 index 032e0c9a58..0000000000 --- a/backend/windmill-api/src/oauth2_ee.rs +++ /dev/null @@ -1,212 +0,0 @@ -/* - * Author: Ruben Fiszel - * Copyright: Windmill Labs, Inc 2022 - * This file and its contents are licensed under the AGPLv3 License. - * Please see the included NOTICE for copyright information and - * LICENSE-AGPL for a copy of the license. - */ - -use std::{collections::HashMap, fmt::Debug}; - -use axum::body::StreamBody; -use axum::response::IntoResponse; -use axum::{routing::get, Json, Router}; -use hmac::Mac; -use hyper::{HeaderMap, StatusCode}; - -use oauth2::{Client as OClient, *}; -use serde::{Deserialize, Serialize}; -use sqlx::{Postgres, Transaction}; -use windmill_common::more_serde::maybe_number_opt; - -use crate::{HTTP_CLIENT, OAUTH_CLIENTS}; -use windmill_common::error::{self, to_anyhow}; -use windmill_common::oauth2::*; - -use crate::db::DB; -use std::str; - -pub fn global_service() -> Router { - Router::new() - .route("/list_supabase", get(list_supabase)) - .route("/list_logins", get(list_logins)) - .route("/list_connects", get(list_connects)) -} - -pub fn workspaced_service() -> Router { - Router::new() -} - -#[derive(Serialize)] -#[serde(tag = "type")] -pub enum InstanceEvent { - UserAdded { email: String }, - // UserDeleted { email: String }, - // UserDeletedWorkspace { workspace: String, email: String }, - UserAddedWorkspace { workspace: String, email: String }, - UserInvitedWorkspace { workspace: String, email: String }, - UserJoinedWorkspace { workspace: String, email: String, username: String }, -} - -#[derive(Debug, Clone)] -pub struct ClientWithScopes { - _client: OClient, - scopes: Vec, - extra_params: Option>, - _extra_params_callback: Option>, - _allowed_domains: Option>, - _userinfo_url: Option, -} - -pub type BasicClientsMap = HashMap; - -#[derive(Clone, Debug, Serialize, Deserialize)] -pub struct OAuthConfig { - auth_url: String, - token_url: String, - userinfo_url: Option, - scopes: Option>, - extra_params: Option>, - extra_params_callback: Option>, - req_body_auth: Option, -} - -#[derive(Clone, Debug, Serialize, Deserialize)] -pub struct OAuthClient { - id: String, - secret: String, - allowed_domains: Option>, - connect_config: Option, - login_config: Option, -} - -#[derive(Debug)] -pub struct AllClients { - pub logins: BasicClientsMap, - pub connects: BasicClientsMap, - pub slack: Option, -} - -pub fn build_oauth_clients( - _base_url: &str, - _oauths_from_config: Option>, -) -> anyhow::Result { - // Implementation is not open source - return Ok(AllClients { - logins: HashMap::default(), - connects: HashMap::default(), - slack: None, - }); -} - -#[derive(Clone, Debug, Deserialize, Serialize)] -pub struct TokenResponse { - access_token: AccessToken, - #[serde(deserialize_with = "maybe_number_opt")] - #[serde(default)] - expires_in: Option, - refresh_token: Option, - #[serde(deserialize_with = "helpers::deserialize_space_delimited_vec")] - #[serde(serialize_with = "helpers::serialize_space_delimited_vec")] - #[serde(default)] - scope: Option>, -} - -#[derive(Serialize)] -struct Logins { - oauth: Vec, - saml: Option, -} -async fn list_logins() -> error::JsonResult { - // Implementation is not open source - return Ok(Json(Logins { oauth: vec![], saml: None })); -} - -#[derive(Serialize)] -struct ScopesAndParams { - scopes: Vec, - extra_params: Option>, -} -async fn list_connects() -> error::JsonResult> { - Ok(Json( - (&OAUTH_CLIENTS.read().await.connects) - .into_iter() - .map(|(k, v)| { - ( - k.to_owned(), - ScopesAndParams { - scopes: v.scopes.clone(), - extra_params: v.extra_params.clone(), - }, - ) - }) - .collect::>(), - )) -} - -pub async fn _refresh_token<'c>( - _tx: Transaction<'c, Postgres>, - _path: &str, - _w_id: &str, - _id: i32, -) -> error::Result { - // Implementation is not open source - Err(error::Error::BadRequest( - "Not implemented in Windmill's Open Source repository".to_string(), - )) -} - -async fn list_supabase(headers: HeaderMap) -> impl IntoResponse { - let token = headers - .get("X-Supabase-Token") - .map(|x| x.to_str().unwrap_or("")) - .unwrap_or(""); - let resp = HTTP_CLIENT - .get("https://api.supabase.com/v1/projects") - .bearer_auth(token) - .send() - .await - .map_err(to_anyhow)?; - - let status_code = resp.status(); - let stream = resp.bytes_stream(); - - Ok((status_code, StreamBody::new(stream))) as error::Result<(StatusCode, StreamBody<_>)> -} - -pub async fn check_nb_of_user(db: &DB) -> error::Result<()> { - let nb_users_sso = - sqlx::query_scalar!("SELECT COUNT(*) FROM password WHERE login_type != 'password'",) - .fetch_one(db) - .await?; - if nb_users_sso.unwrap_or(0) >= 10 { - return Err(error::Error::BadRequest( - "You have reached the maximum number of oauth users accounts (10) without an enterprise license" - .to_string(), - )); - } - - let nb_users = sqlx::query_scalar!("SELECT COUNT(*) FROM password",) - .fetch_one(db) - .await?; - if nb_users.unwrap_or(0) >= 50 { - return Err(error::Error::BadRequest( - "You have reached the maximum number of accounts (50) without an enterprise license" - .to_string(), - )); - } - return Ok(()); -} - -#[derive(Clone, Debug)] -pub struct SlackVerifier { - _mac: HmacSha256, -} - -impl SlackVerifier { - pub fn new>(secret: S) -> anyhow::Result { - HmacSha256::new_from_slice(secret.as_ref()) - .map(|mac| SlackVerifier { _mac: mac }) - .map_err(|_| anyhow::anyhow!("invalid secret")) - } -} diff --git a/backend/windmill-api/src/oauth2_ee.rs b/backend/windmill-api/src/oauth2_ee.rs new file mode 120000 index 0000000000..1ab1665454 --- /dev/null +++ b/backend/windmill-api/src/oauth2_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/oauth2_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/oidc_ee.rs b/backend/windmill-api/src/oidc_ee.rs deleted file mode 100644 index 248b990f54..0000000000 --- a/backend/windmill-api/src/oidc_ee.rs +++ /dev/null @@ -1,17 +0,0 @@ -/* - * Author: Ruben Fiszel - * Copyright: Windmill Labs, Inc 2023 - * This file and its contents are licensed under the AGPLv3 License. - * Please see the included NOTICE for copyright information and - * LICENSE-AGPL for a copy of the license. - */ - -use axum::Router; - -pub fn global_service() -> Router { - Router::new() -} - -pub fn workspaced_service() -> Router { - Router::new() -} diff --git a/backend/windmill-api/src/oidc_ee.rs b/backend/windmill-api/src/oidc_ee.rs new file mode 120000 index 0000000000..1e902de563 --- /dev/null +++ b/backend/windmill-api/src/oidc_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/oidc_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/saml_ee.rs b/backend/windmill-api/src/saml_ee.rs deleted file mode 100644 index b3f1d4653c..0000000000 --- a/backend/windmill-api/src/saml_ee.rs +++ /dev/null @@ -1,25 +0,0 @@ -/* - * Author: Ruben Fiszel - * Copyright: Windmill Labs, Inc 2023 - * This file and its contents are licensed under the AGPLv3 License. - * Please see the included NOTICE for copyright information and - * LICENSE-AGPL for a copy of the license. - */ -#![allow(non_snake_case)] - -use axum::{routing::post, Router}; - -pub struct ServiceProviderExt(); - -pub async fn build_sp_extension() -> anyhow::Result { - return Ok(ServiceProviderExt()); -} - -pub fn global_service() -> Router { - Router::new().route("/acs", post(acs)) -} - -pub async fn acs() -> String { - // Implementation is not open source as it is a Windmill Enterprise Edition feature - "SAML available only in enterprise version".to_string() -} diff --git a/backend/windmill-api/src/saml_ee.rs b/backend/windmill-api/src/saml_ee.rs new file mode 120000 index 0000000000..65286e3f12 --- /dev/null +++ b/backend/windmill-api/src/saml_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/saml_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/scim_ee.rs b/backend/windmill-api/src/scim_ee.rs deleted file mode 100644 index 8552405296..0000000000 --- a/backend/windmill-api/src/scim_ee.rs +++ /dev/null @@ -1,22 +0,0 @@ -/* - * Author: Ruben Fiszel - * Copyright: Windmill Labs, Inc 2023 - * This file and its contents are licensed under the AGPLv3 License. - * Please see the included NOTICE for copyright information and - * LICENSE-AGPL for a copy of the license. - */ - -use axum::{middleware::Next, response::Response, routing::get, Router}; -use hyper::Request; - -pub fn global_service() -> Router { - Router::new().route("/ee", get(ee)) -} - -pub async fn ee() -> String { - return "Enterprise Edition".to_string(); -} - -pub async fn has_scim_token(request: Request, next: Next) -> Response { - return next.run(request).await; -} diff --git a/backend/windmill-api/src/scim_ee.rs b/backend/windmill-api/src/scim_ee.rs new file mode 120000 index 0000000000..cd27dc4526 --- /dev/null +++ b/backend/windmill-api/src/scim_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/scim_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/stripe_ee.rs b/backend/windmill-api/src/stripe_ee.rs deleted file mode 100644 index 1aea2ecd2d..0000000000 --- a/backend/windmill-api/src/stripe_ee.rs +++ /dev/null @@ -1,7 +0,0 @@ -#[cfg(feature = "stripe")] -use axum::Router; - -#[cfg(feature = "stripe")] -pub fn add_stripe_routes(router: Router) -> Router { - return router; -} diff --git a/backend/windmill-api/src/stripe_ee.rs b/backend/windmill-api/src/stripe_ee.rs new file mode 120000 index 0000000000..a6c7d1230e --- /dev/null +++ b/backend/windmill-api/src/stripe_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-api/src/stripe_ee.rs \ No newline at end of file diff --git a/backend/windmill-audit/src/audit_ee.rs b/backend/windmill-audit/src/audit_ee.rs deleted file mode 100644 index 5bb52e7b3f..0000000000 --- a/backend/windmill-audit/src/audit_ee.rs +++ /dev/null @@ -1,48 +0,0 @@ -/* - * Author: Ruben Fiszel - * Copyright: Windmill Labs, Inc 2022 - * This file and its contents are licensed under the AGPLv3 License. - * Please see the included NOTICE for copyright information and - * LICENSE-AGPL for a copy of the license. - */ -use std::collections::HashMap; - -use windmill_common::{ - error::{Error, Result}, - utils::Pagination, -}; - -use crate::{ActionKind, AuditLog, ListAuditLogQuery}; -use sqlx::{Postgres, Transaction}; - -#[tracing::instrument(level = "trace", skip_all)] -pub async fn audit_log<'c, E: sqlx::Executor<'c, Database = Postgres>>( - _db: E, - _username: &str, - mut _operation: &str, - _action_kind: ActionKind, - _w_id: &str, - mut _resource: Option<&str>, - _parameters: Option>, -) -> Result<()> { - // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature - Ok(()) -} - -pub async fn list_audit( - _tx: Transaction<'_, Postgres>, - _w_id: String, - _pagination: Pagination, - _lq: ListAuditLogQuery, -) -> Result> { - // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature - return Ok(vec![]); -} - -pub async fn get_audit(tx: Transaction<'_, Postgres>, _id: i32, _w_id: &str) -> Result { - // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature - tx.commit().await?; - Err(Error::NotFound( - "Audit log not not available in Windmill Community edition".to_string(), - )) -} diff --git a/backend/windmill-audit/src/audit_ee.rs b/backend/windmill-audit/src/audit_ee.rs new file mode 120000 index 0000000000..f8d4a81d03 --- /dev/null +++ b/backend/windmill-audit/src/audit_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-audit/src/audit_ee.rs \ No newline at end of file diff --git a/backend/windmill-common/src/ee.rs b/backend/windmill-common/src/ee.rs deleted file mode 100644 index c942447bbc..0000000000 --- a/backend/windmill-common/src/ee.rs +++ /dev/null @@ -1,20 +0,0 @@ -use crate::ee::LicensePlan::Community; -use std::sync::Arc; -use tokio::sync::RwLock; - -lazy_static::lazy_static! { - pub static ref LICENSE_KEY_VALID: Arc> = Arc::new(RwLock::new(true)); - pub static ref LICENSE_KEY_ID: Arc> = Arc::new(RwLock::new("".to_string())); - pub static ref LICENSE_KEY: Arc> = Arc::new(RwLock::new("".to_string())); -} - -pub enum LicensePlan { - Community, - Pro, - Enterprise, -} - -pub async fn get_license_plan() -> LicensePlan { - // Implementation is not open source - return Community; -} diff --git a/backend/windmill-common/src/ee.rs b/backend/windmill-common/src/ee.rs new file mode 120000 index 0000000000..3220066a5d --- /dev/null +++ b/backend/windmill-common/src/ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-common/src/ee.rs \ No newline at end of file diff --git a/backend/windmill-git-sync/src/git_sync_ee.rs b/backend/windmill-git-sync/src/git_sync_ee.rs deleted file mode 100644 index 4be2858c27..0000000000 --- a/backend/windmill-git-sync/src/git_sync_ee.rs +++ /dev/null @@ -1,17 +0,0 @@ -use windmill_common::error::Result; - -use crate::{DeployedObject, DB}; - -pub async fn handle_deployment_metadata<'c, R: rsmq_async::RsmqConnection + Send + Clone + 'c>( - _email: &str, - _created_by: &str, - _db: &DB, - _w_id: &str, - _obj: DeployedObject, - _deployment_message: Option, - _rsmq: Option, - _skip_db_insert: bool, -) -> Result<()> { - // Git sync is an enterprise feature and not part of the open-source version - return Ok(()); -} diff --git a/backend/windmill-git-sync/src/git_sync_ee.rs b/backend/windmill-git-sync/src/git_sync_ee.rs new file mode 120000 index 0000000000..0824f2c28c --- /dev/null +++ b/backend/windmill-git-sync/src/git_sync_ee.rs @@ -0,0 +1 @@ +/git/windmill/../windmill-ee-private/windmill-git-sync/src/git_sync_ee.rs \ No newline at end of file diff --git a/frontend/src/lib/components/SuperadminSettings.svelte b/frontend/src/lib/components/SuperadminSettings.svelte index 5a50089ae6..d4ea374364 100644 --- a/frontend/src/lib/components/SuperadminSettings.svelte +++ b/frontend/src/lib/components/SuperadminSettings.svelte @@ -148,6 +148,7 @@ class="text-red-500 whitespace-nowrap" on:click={() => { deleteConfirmedCallback = async () => { + console.log(email) await UserService.globalUserDelete({ email }) sendUserToast(`User ${email} removed`) listUsers() diff --git a/frontend/src/lib/components/flows/idUtils.ts b/frontend/src/lib/components/flows/idUtils.ts index 94a6c00929..15d3dbba37 100644 --- a/frontend/src/lib/components/flows/idUtils.ts +++ b/frontend/src/lib/components/flows/idUtils.ts @@ -1,6 +1,17 @@ const aCharCode = 'a'.charCodeAt(0) -export const forbiddenIds: string[] = ['do', 'bg', 'ctx', 'state', 'if', 'else', 'for'] +export const forbiddenIds: string[] = [ + 'do', + 'bg', + 'ctx', + 'state', + 'if', + 'else', + 'for', + 'delete', + 'while', + 'new' +] export function numberToChars(n: number) { if (n < 0) {