From a7250bfae7007b39e5a42f5000c56e8bdcea372c Mon Sep 17 00:00:00 2001 From: Ruben Fiszel Date: Tue, 18 Jun 2024 20:51:52 +0200 Subject: [PATCH] update datafusion --- backend/src/ee.rs | 24 ++- backend/windmill-api/src/ee.rs | 7 +- backend/windmill-api/src/job_helpers_ee.rs | 6 +- backend/windmill-api/src/oauth2_ee.rs | 189 +++++++++++++++++- backend/windmill-api/src/oidc_ee.rs | 18 +- backend/windmill-api/src/saml_ee.rs | 26 ++- backend/windmill-api/src/scim_ee.rs | 24 ++- backend/windmill-api/src/stripe_ee.rs | 8 +- backend/windmill-audit/src/audit_ee.rs | 76 ++++++- backend/windmill-common/src/ee.rs | 49 ++++- .../windmill-common/src/job_s3_helpers_ee.rs | 19 +- backend/windmill-common/src/stats_ee.rs | 46 ++++- backend/windmill-git-sync/src/git_sync_ee.rs | 18 +- 13 files changed, 497 insertions(+), 13 deletions(-) mode change 120000 => 100644 backend/src/ee.rs mode change 120000 => 100644 backend/windmill-api/src/ee.rs mode change 120000 => 100644 backend/windmill-api/src/job_helpers_ee.rs mode change 120000 => 100644 backend/windmill-api/src/oauth2_ee.rs mode change 120000 => 100644 backend/windmill-api/src/oidc_ee.rs mode change 120000 => 100644 backend/windmill-api/src/saml_ee.rs mode change 120000 => 100644 backend/windmill-api/src/scim_ee.rs mode change 120000 => 100644 backend/windmill-api/src/stripe_ee.rs mode change 120000 => 100644 backend/windmill-audit/src/audit_ee.rs mode change 120000 => 100644 backend/windmill-common/src/ee.rs mode change 120000 => 100644 backend/windmill-common/src/job_s3_helpers_ee.rs mode change 120000 => 100644 backend/windmill-common/src/stats_ee.rs mode change 120000 => 100644 backend/windmill-git-sync/src/git_sync_ee.rs diff --git a/backend/src/ee.rs b/backend/src/ee.rs deleted file mode 120000 index ca288038c6..0000000000 --- a/backend/src/ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/src/ee.rs \ No newline at end of file diff --git a/backend/src/ee.rs b/backend/src/ee.rs new file mode 100644 index 0000000000..955dbaff4f --- /dev/null +++ b/backend/src/ee.rs @@ -0,0 +1,23 @@ +use anyhow::anyhow; +#[cfg(feature = "enterprise")] +use windmill_common::error::{Error, Result}; + +pub async fn set_license_key(_license_key: String) -> anyhow::Result<()> { + // Implementation is not open source + Err(anyhow!("License cannot be set in Windmill CE")) +} + +#[cfg(feature = "enterprise")] +pub async fn verify_license_key() -> Result<()> { + // Implementation is not open source + Err(Error::InternalErr( + "License always invalid in Windmill CE".to_string(), + )) +} + +#[cfg(feature = "enterprise")] +pub async fn jwt_ext_auth(_w_id: Option<&String>, _token: &str) -> Option<(ApiAuthed, usize)> { + // Implementation is not open source + + None +} diff --git a/backend/windmill-api/src/ee.rs b/backend/windmill-api/src/ee.rs deleted file mode 120000 index 0267c6e6fd..0000000000 --- a/backend/windmill-api/src/ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/ee.rs b/backend/windmill-api/src/ee.rs new file mode 100644 index 0000000000..a9d170a3ac --- /dev/null +++ b/backend/windmill-api/src/ee.rs @@ -0,0 +1,6 @@ +use anyhow::anyhow; + +pub async fn validate_license_key(_license_key: String) -> anyhow::Result { + // Implementation is not open source + Err(anyhow!("License can't be validated in Windmill CE")) +} diff --git a/backend/windmill-api/src/job_helpers_ee.rs b/backend/windmill-api/src/job_helpers_ee.rs deleted file mode 120000 index 8cc4fbe8bf..0000000000 --- a/backend/windmill-api/src/job_helpers_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/job_helpers_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/job_helpers_ee.rs b/backend/windmill-api/src/job_helpers_ee.rs new file mode 100644 index 0000000000..61a946bb84 --- /dev/null +++ b/backend/windmill-api/src/job_helpers_ee.rs @@ -0,0 +1,5 @@ +use axum::Router; + +pub fn workspaced_service() -> Router { + Router::new() +} diff --git a/backend/windmill-api/src/oauth2_ee.rs b/backend/windmill-api/src/oauth2_ee.rs deleted file mode 120000 index 1ab1665454..0000000000 --- a/backend/windmill-api/src/oauth2_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/oauth2_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/oauth2_ee.rs b/backend/windmill-api/src/oauth2_ee.rs new file mode 100644 index 0000000000..39960cec92 --- /dev/null +++ b/backend/windmill-api/src/oauth2_ee.rs @@ -0,0 +1,188 @@ +/* + * Author: Ruben Fiszel + * Copyright: Windmill Labs, Inc 2022 + * This file and its contents are licensed under the AGPLv3 License. + * Please see the included NOTICE for copyright information and + * LICENSE-AGPL for a copy of the license. + */ + +use std::{collections::HashMap, fmt::Debug}; + +use axum::{routing::get, Json, Router}; +use hmac::Mac; +use hyper::HeaderMap; + +use itertools::Itertools; +use oauth2::{Client as OClient, *}; +use serde::{Deserialize, Serialize}; +use sqlx::{Postgres, Transaction}; +use windmill_common::more_serde::maybe_number_opt; + +use crate::OAUTH_CLIENTS; +use windmill_common::error; +use windmill_common::oauth2::*; + +use crate::db::DB; +use std::str; + +pub fn global_service() -> Router { + Router::new() + .route("/list_supabase", get(list_supabase)) + .route("/list_logins", get(list_logins)) + .route("/list_connects", get(list_connects)) +} + +pub fn workspaced_service() -> Router { + Router::new() +} + +#[derive(Serialize)] +#[serde(tag = "type")] +pub enum InstanceEvent { + UserAdded { email: String }, + // UserDeleted { email: String }, + // UserDeletedWorkspace { workspace: String, email: String }, + UserAddedWorkspace { workspace: String, email: String }, + UserInvitedWorkspace { workspace: String, email: String }, + UserJoinedWorkspace { workspace: String, email: String, username: String }, +} + +#[derive(Debug, Clone)] +pub struct ClientWithScopes { + _client: OClient, + _scopes: Vec, + _extra_params: Option>, + _extra_params_callback: Option>, + _allowed_domains: Option>, + _userinfo_url: Option, +} + +pub type BasicClientsMap = HashMap; + +#[derive(Clone, Debug, Serialize, Deserialize)] +pub struct OAuthConfig { + auth_url: String, + token_url: String, + userinfo_url: Option, + scopes: Option>, + extra_params: Option>, + extra_params_callback: Option>, + req_body_auth: Option, +} + +#[derive(Clone, Debug, Serialize, Deserialize)] +pub struct OAuthClient { + id: String, + secret: String, + allowed_domains: Option>, + connect_config: Option, + login_config: Option, +} + +#[derive(Debug)] +pub struct AllClients { + pub logins: BasicClientsMap, + pub connects: BasicClientsMap, + pub slack: Option, +} + +pub fn build_oauth_clients( + _base_url: &str, + _oauths_from_config: Option>, +) -> anyhow::Result { + // Implementation is not open source + return Ok(AllClients { + logins: HashMap::default(), + connects: HashMap::default(), + slack: None, + }); +} + +#[derive(Clone, Debug, Deserialize, Serialize)] +pub struct TokenResponse { + access_token: AccessToken, + #[serde(deserialize_with = "maybe_number_opt")] + #[serde(default)] + expires_in: Option, + refresh_token: Option, + #[serde(deserialize_with = "helpers::deserialize_space_delimited_vec")] + #[serde(serialize_with = "helpers::serialize_space_delimited_vec")] + #[serde(default)] + scope: Option>, +} + +#[derive(Serialize)] +struct Logins { + oauth: Vec, + saml: Option, +} +async fn list_logins() -> error::JsonResult { + // Implementation is not open source + return Ok(Json(Logins { oauth: vec![], saml: None })); +} + +async fn list_connects() -> error::JsonResult> { + Ok(Json( + (&OAUTH_CLIENTS.read().await.connects) + .keys() + .map(|x| x.to_owned()) + .collect_vec(), + )) +} + +pub async fn _refresh_token<'c>( + _tx: Transaction<'c, Postgres>, + _path: &str, + _w_id: &str, + _id: i32, + _db: &DB, +) -> error::Result { + // Implementation is not open source + Err(error::Error::BadRequest( + "Not implemented in Windmill's Open Source repository".to_string(), + )) +} + +async fn list_supabase(_headers: HeaderMap) -> error::Result { + // Implementation is not open source + Err(error::Error::BadRequest( + "Not implemented in Windmill's Open Source repository".to_string(), + )) +} + +pub async fn check_nb_of_user(db: &DB) -> error::Result<()> { + let nb_users_sso = + sqlx::query_scalar!("SELECT COUNT(*) FROM password WHERE login_type != 'password'",) + .fetch_one(db) + .await?; + if nb_users_sso.unwrap_or(0) >= 10 { + return Err(error::Error::BadRequest( + "You have reached the maximum number of oauth users accounts (10) without an enterprise license" + .to_string(), + )); + } + + let nb_users = sqlx::query_scalar!("SELECT COUNT(*) FROM password",) + .fetch_one(db) + .await?; + if nb_users.unwrap_or(0) >= 50 { + return Err(error::Error::BadRequest( + "You have reached the maximum number of accounts (50) without an enterprise license" + .to_string(), + )); + } + return Ok(()); +} + +#[derive(Clone, Debug)] +pub struct SlackVerifier { + _mac: HmacSha256, +} + +impl SlackVerifier { + pub fn new>(secret: S) -> anyhow::Result { + HmacSha256::new_from_slice(secret.as_ref()) + .map(|mac| SlackVerifier { _mac: mac }) + .map_err(|_| anyhow::anyhow!("invalid secret")) + } +} diff --git a/backend/windmill-api/src/oidc_ee.rs b/backend/windmill-api/src/oidc_ee.rs deleted file mode 120000 index 1e902de563..0000000000 --- a/backend/windmill-api/src/oidc_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/oidc_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/oidc_ee.rs b/backend/windmill-api/src/oidc_ee.rs new file mode 100644 index 0000000000..248b990f54 --- /dev/null +++ b/backend/windmill-api/src/oidc_ee.rs @@ -0,0 +1,17 @@ +/* + * Author: Ruben Fiszel + * Copyright: Windmill Labs, Inc 2023 + * This file and its contents are licensed under the AGPLv3 License. + * Please see the included NOTICE for copyright information and + * LICENSE-AGPL for a copy of the license. + */ + +use axum::Router; + +pub fn global_service() -> Router { + Router::new() +} + +pub fn workspaced_service() -> Router { + Router::new() +} diff --git a/backend/windmill-api/src/saml_ee.rs b/backend/windmill-api/src/saml_ee.rs deleted file mode 120000 index 65286e3f12..0000000000 --- a/backend/windmill-api/src/saml_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/saml_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/saml_ee.rs b/backend/windmill-api/src/saml_ee.rs new file mode 100644 index 0000000000..b3f1d4653c --- /dev/null +++ b/backend/windmill-api/src/saml_ee.rs @@ -0,0 +1,25 @@ +/* + * Author: Ruben Fiszel + * Copyright: Windmill Labs, Inc 2023 + * This file and its contents are licensed under the AGPLv3 License. + * Please see the included NOTICE for copyright information and + * LICENSE-AGPL for a copy of the license. + */ +#![allow(non_snake_case)] + +use axum::{routing::post, Router}; + +pub struct ServiceProviderExt(); + +pub async fn build_sp_extension() -> anyhow::Result { + return Ok(ServiceProviderExt()); +} + +pub fn global_service() -> Router { + Router::new().route("/acs", post(acs)) +} + +pub async fn acs() -> String { + // Implementation is not open source as it is a Windmill Enterprise Edition feature + "SAML available only in enterprise version".to_string() +} diff --git a/backend/windmill-api/src/scim_ee.rs b/backend/windmill-api/src/scim_ee.rs deleted file mode 120000 index cd27dc4526..0000000000 --- a/backend/windmill-api/src/scim_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/scim_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/scim_ee.rs b/backend/windmill-api/src/scim_ee.rs new file mode 100644 index 0000000000..f11097f874 --- /dev/null +++ b/backend/windmill-api/src/scim_ee.rs @@ -0,0 +1,23 @@ +/* + * Author: Ruben Fiszel + * Copyright: Windmill Labs, Inc 2023 + * This file and its contents are licensed under the AGPLv3 License. + * Please see the included NOTICE for copyright information and + * LICENSE-AGPL for a copy of the license. + */ + +use axum::{middleware::Next, response::Response, routing::get, Router}; +use hyper::Request; + +pub fn global_service() -> Router { + Router::new().route("/ee", get(ee)) +} + +pub async fn ee() -> String { + return "Enterprise Edition".to_string(); +} + +pub async fn has_scim_token(_request: Request, _next: Next) -> Response { + //Not implemented in open-source version + todo!() +} diff --git a/backend/windmill-api/src/stripe_ee.rs b/backend/windmill-api/src/stripe_ee.rs deleted file mode 120000 index a6c7d1230e..0000000000 --- a/backend/windmill-api/src/stripe_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-api/src/stripe_ee.rs \ No newline at end of file diff --git a/backend/windmill-api/src/stripe_ee.rs b/backend/windmill-api/src/stripe_ee.rs new file mode 100644 index 0000000000..1aea2ecd2d --- /dev/null +++ b/backend/windmill-api/src/stripe_ee.rs @@ -0,0 +1,7 @@ +#[cfg(feature = "stripe")] +use axum::Router; + +#[cfg(feature = "stripe")] +pub fn add_stripe_routes(router: Router) -> Router { + return router; +} diff --git a/backend/windmill-audit/src/audit_ee.rs b/backend/windmill-audit/src/audit_ee.rs deleted file mode 120000 index f8d4a81d03..0000000000 --- a/backend/windmill-audit/src/audit_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-audit/src/audit_ee.rs \ No newline at end of file diff --git a/backend/windmill-audit/src/audit_ee.rs b/backend/windmill-audit/src/audit_ee.rs new file mode 100644 index 0000000000..97a8e6bbcf --- /dev/null +++ b/backend/windmill-audit/src/audit_ee.rs @@ -0,0 +1,75 @@ +/* + * Author: Ruben Fiszel + * Copyright: Windmill Labs, Inc 2022 + * This file and its contents are licensed under the AGPLv3 License. + * Please see the included NOTICE for copyright information and + * LICENSE-AGPL for a copy of the license. + */ +use std::collections::HashMap; + +use windmill_common::{ + error::{Error, Result}, + utils::Pagination, +}; + +use crate::{ActionKind, AuditLog, ListAuditLogQuery}; +use sqlx::{Postgres, Transaction}; + +#[derive(Clone)] +pub struct AuditAuthor { + pub username: String, + pub email: String, + pub username_override: Option, +} + +impl AuditAuthorable for AuditAuthor { + fn email(&self) -> &str { + &self.email + } + + fn username(&self) -> &str { + &self.username + } + + fn username_override(&self) -> Option<&str> { + self.username_override.as_deref() + } +} + +pub trait AuditAuthorable { + fn username(&self) -> &str; + fn email(&self) -> &str; + fn username_override(&self) -> Option<&str>; +} + +#[tracing::instrument(level = "trace", skip_all)] +pub async fn audit_log<'c, E: sqlx::Executor<'c, Database = Postgres>>( + _db: E, + _author: &impl AuditAuthorable, + mut _operation: &str, + _action_kind: ActionKind, + _w_id: &str, + mut _resource: Option<&str>, + _parameters: Option>, +) -> Result<()> { + // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature + Ok(()) +} + +pub async fn list_audit( + _tx: Transaction<'_, Postgres>, + _w_id: String, + _pagination: Pagination, + _lq: ListAuditLogQuery, +) -> Result> { + // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature + return Ok(vec![]); +} + +pub async fn get_audit(tx: Transaction<'_, Postgres>, _id: i32, _w_id: &str) -> Result { + // Implementation is not open source as Audit logs is a Windmill Enterprise Edition feature + tx.commit().await?; + Err(Error::NotFound( + "Audit log not not available in Windmill Community edition".to_string(), + )) +} diff --git a/backend/windmill-common/src/ee.rs b/backend/windmill-common/src/ee.rs deleted file mode 120000 index 3220066a5d..0000000000 --- a/backend/windmill-common/src/ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-common/src/ee.rs \ No newline at end of file diff --git a/backend/windmill-common/src/ee.rs b/backend/windmill-common/src/ee.rs new file mode 100644 index 0000000000..a87b4675f0 --- /dev/null +++ b/backend/windmill-common/src/ee.rs @@ -0,0 +1,48 @@ +use crate::ee::LicensePlan::Community; +#[cfg(feature = "enterprise")] +use crate::error; +use serde::Deserialize; +use std::sync::Arc; +use tokio::sync::RwLock; + +lazy_static::lazy_static! { + pub static ref LICENSE_KEY_VALID: Arc> = Arc::new(RwLock::new(true)); + pub static ref LICENSE_KEY_ID: Arc> = Arc::new(RwLock::new("".to_string())); + pub static ref LICENSE_KEY: Arc> = Arc::new(RwLock::new("".to_string())); +} + +pub enum LicensePlan { + Community, + Pro, + Enterprise, +} + +pub async fn get_license_plan() -> LicensePlan { + // Implementation is not open source + return Community; +} + +#[derive(Deserialize)] +#[serde(untagged)] +pub enum CriticalErrorChannel {} + +pub async fn trigger_critical_error_channels(_error_message: String) {} + +#[cfg(feature = "enterprise")] +pub async fn schedule_key_renewal(_http_client: &reqwest::Client, _db: &crate::db::DB) -> () { + // Implementation is not open source +} + +#[cfg(feature = "enterprise")] +pub async fn renew_license_key(_http_client: &reqwest::Client, _db: &crate::db::DB) -> String { + // Implementation is not open source + "".to_string() +} + +#[cfg(feature = "enterprise")] +pub async fn create_customer_portal_session( + _http_client: &reqwest::Client, +) -> error::Result { + // Implementation is not open source + Ok("".to_string()) +} diff --git a/backend/windmill-common/src/job_s3_helpers_ee.rs b/backend/windmill-common/src/job_s3_helpers_ee.rs deleted file mode 120000 index 6c8430be70..0000000000 --- a/backend/windmill-common/src/job_s3_helpers_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-common/src/job_s3_helpers_ee.rs \ No newline at end of file diff --git a/backend/windmill-common/src/job_s3_helpers_ee.rs b/backend/windmill-common/src/job_s3_helpers_ee.rs new file mode 100644 index 0000000000..b00c00a583 --- /dev/null +++ b/backend/windmill-common/src/job_s3_helpers_ee.rs @@ -0,0 +1,18 @@ +use std::future::Future; + +use crate::{ + error::Error, + s3_helpers::{ObjectStoreResource, StorageResourceType}, +}; + +pub async fn get_s3_resource_internal<'c, F, Fut>( + _resource_type: StorageResourceType, + _s3_resource_value_raw: serde_json::Value, + _gen_token: F, +) -> crate::error::Result +where + F: FnOnce(String) -> Fut, + Fut: Future> + Send + 'static, +{ + todo!() +} diff --git a/backend/windmill-common/src/stats_ee.rs b/backend/windmill-common/src/stats_ee.rs deleted file mode 120000 index d0ddc5bd1d..0000000000 --- a/backend/windmill-common/src/stats_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-common/src/stats_ee.rs \ No newline at end of file diff --git a/backend/windmill-common/src/stats_ee.rs b/backend/windmill-common/src/stats_ee.rs new file mode 100644 index 0000000000..48845d5f51 --- /dev/null +++ b/backend/windmill-common/src/stats_ee.rs @@ -0,0 +1,45 @@ +use sqlx::Postgres; + +use crate::{error::Result, scripts::ScriptLang, DB}; + +pub async fn get_disable_stats_setting(_db: &DB) -> bool { + // stats details are closed source + + false +} + +pub async fn schedule_stats( + _instance_name: String, + _db: &DB, + _http_client: &reqwest::Client, +) -> () { + // stats details are closed source +} + +#[derive(Debug, sqlx::FromRow, serde::Serialize)] +struct JobsUsage { + language: Option, + total_duration: i64, + count: i64, +} + +pub async fn send_stats( + _instance_name: &String, + _http_client: &reqwest::Client, + _db: &DB, +) -> Result<()> { + // stats details are closed source + Ok(()) +} + +pub struct ActiveUserUsage { + pub author_count: Option, + pub operator_count: Option, +} + +pub async fn get_user_usage<'c, E: sqlx::Executor<'c, Database = Postgres>>( + _db: E, +) -> Result { + let usage = ActiveUserUsage { author_count: None, operator_count: None }; + Ok(usage) +} diff --git a/backend/windmill-git-sync/src/git_sync_ee.rs b/backend/windmill-git-sync/src/git_sync_ee.rs deleted file mode 120000 index 0824f2c28c..0000000000 --- a/backend/windmill-git-sync/src/git_sync_ee.rs +++ /dev/null @@ -1 +0,0 @@ -/git/windmill/../windmill-ee-private/windmill-git-sync/src/git_sync_ee.rs \ No newline at end of file diff --git a/backend/windmill-git-sync/src/git_sync_ee.rs b/backend/windmill-git-sync/src/git_sync_ee.rs new file mode 100644 index 0000000000..4be2858c27 --- /dev/null +++ b/backend/windmill-git-sync/src/git_sync_ee.rs @@ -0,0 +1,17 @@ +use windmill_common::error::Result; + +use crate::{DeployedObject, DB}; + +pub async fn handle_deployment_metadata<'c, R: rsmq_async::RsmqConnection + Send + Clone + 'c>( + _email: &str, + _created_by: &str, + _db: &DB, + _w_id: &str, + _obj: DeployedObject, + _deployment_message: Option, + _rsmq: Option, + _skip_db_insert: bool, +) -> Result<()> { + // Git sync is an enterprise feature and not part of the open-source version + return Ok(()); +}