NetSuite is a per-instance OAuth provider (account-specific authorize/token
URLs), registered via connect_config_template. Its authorize endpoint
requires scope=rest_webservices, so the template mechanism gains an
optional scopes field copied into the built connect_config.
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* oauth: map Coupa instance to instance_url resource arg
Coupa's managed client-credentials connect collects an instance name to
host-pin the token URL but had no resource_mapping, so the created resource's
instance_url (the API base URL the hub scripts build on) stayed empty. Add the
mapping, mirroring ServiceNow, so the entered instance fills it automatically.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* oauth: default Coupa client-credentials scopes (cc_scopes)
Prefill the connect dialog's scope field with the core.* scopes the Coupa hub
scripts exercise — read+write for suppliers/purchase_orders/requisitions/invoices,
read-only for contracts/expenses (the shipped scripts only read those). Scope
names verified against the Coupa scope docs and corroborated in production code.
The user can trim them to what their OIDC client is granted.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat: zero-setup oauth client credentials for registry-declared providers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: support client-credentials-only custom oauth providers
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: add coupa client credentials provider to oauth registry
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: clarify oauth resource connect auth-method selection
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: support shared instance-level oauth client credentials
Admins can designate an instance OAuth entry's credentials as client
credentials; the connect dialog then runs the exchange server-side with
them instead of asking each user for their own. Replaces the per-provider
"Support Client Credentials Flow" toggle with a grant-type selector.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* chore: update ee-repo-ref to be9f23b2c06b8b6ee0cd3e4d9f16bcd9e90129fb
This commit updates the EE repository reference after PR #613 was merged in windmill-ee-private.
Previous ee-repo-ref: 05643cbbc8c1bebf3509c691c5811b4057d96485
New ee-repo-ref: be9f23b2c06b8b6ee0cd3e4d9f16bcd9e90129fb
Automated by sync-ee-ref workflow.
* feat: allow both grant types on an instance oauth entry
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: bring-your-own oauth credentials from the others section
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: segmented oauth grant-type selector, always show grant
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: enable client credentials for 5 more oauth providers
Verified against official docs: bitbucket, linkedin, spotify, xero and
zoho support the standard client_credentials grant with a plain
client_id + client_secret, compatible with Windmill's token exchange.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: hide create-manually link on the managed oauth connect path
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: enable client credentials for salesforce and servicenow
Salesforce CC requires the org's My Domain token endpoint (login.salesforce.com
is unsupported for that grant), so add an optional cc_token_url registry field
that the connect form prefills for the client-credentials path instead of the
shared token_url. ServiceNow uses the same instance host for both grants, so it
only needs its token URL and req_body_auth surfaced at the top level.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* feat: add instance-level client-credentials token url override
Some providers use a per-org/instance-specific token endpoint for the
client-credentials grant that differs from the authorization-code URL.
Add an optional cc_token_url on the instance OAuth entry, surfaced in
instance settings (prefilled from the registry template) when client
credentials is selected, and used for the CC exchange and refresh while
auth-code keeps its own token URL.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* style: remove redundant grant-type tags from oauth auth cards
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* refactor: extract reusable RadioCard component for the oauth auth chooser
A token-based selectable card (label, description, selected, onSelect,
optional icon) replacing the inline cards in the connect dialog.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix: hide sign-in option on the bring-your-own oauth path
Picking a provider from "Others" means bring your own credentials, so
the auth-code "Sign in" card (which uses the instance client) no longer
shows there — it goes straight to the client-credentials form. The
two-flow chooser stays on the instance-configured path.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix: restrict client-credentials token url to caller-supplied creds
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: resolve client-credentials id and secret all-or-nothing
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: host-pin client-credentials token url via instance-name input
For registry providers whose CC token URL is instance-templated (Coupa,
Salesforce My Domain, ServiceNow), the connect dialog and instance settings
collect an instance name and the backend substitutes it into the fixed-host
template, validating it as a hostname label. A free-form token URL is no longer
accepted for these providers, so the exchange host cannot be redirected.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: client-credentials token url always comes from the registry
Bring-your-own CC is registry-only: the token URL is resolved server-side from
the built-in registry (host-pinned via an instance name for templated providers,
the fixed registry URL otherwise) and rejected for custom resource types. The
caller-supplied token URL field is removed from the connect dialog and the API.
Adds unit tests for the resolver.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: address CC review - sandbox CC config and instance-templated providers
Resolve `_sandbox` provider keys to the parent registry entry in the instance
settings and connect-dialog helpers, so salesforce_sandbox (and future sandbox
entries) can enable client credentials. Use the effective CC token URL template
(cc_token_url or token_url) so the instance-name field works for Coupa/ServiceNow,
and hide that field when a connect_config_template already owns the instance input
(ServiceNow). Document the authorization contract on resolve_instance_cc_credentials.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor: unify instance-templated oauth onto connect_config_template
Remove the separate cc_token_url and cc_instance config fields. An instance-
templated provider now declares one connect_config_template (auth_url optional
for client-credentials-only providers like Coupa); the CC flow reads its token
URL, label and strip_suffix to host-pin the exchange. Coupa and ServiceNow move
to connect_config_template; Coupa stays drawer-only (no auth_url -> excluded from
instance settings). Salesforce CC is removed for now (its auth-code/CC host split
needs the endpoint-profiles model).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: cc_scopes defaults and instance config for client credentials
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: store empty auth_url for cc-only templated oauth providers
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: address review nits - sandbox key lookup, template doc, deref specs
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: default shared client-credentials connect to cc_scopes
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: support bring-your-own client credentials for instance-configured providers
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor: move oauth grant-type help into per-option tooltips
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: keep instance-configured oauth providers selectable from Others
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: preserve admin-configured scopes for custom client-credentials providers
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: use cc scopes on cc refresh and enforce cc grant for bring-your-own
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: require {instance} in leftmost host label for cc token url templates
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: drop token_url from unauthenticated get_connect response
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: fill byo templated resource args from the entered instance
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore: update ee-repo-ref to 136f4634aca61e74ccb045372358a1e3f6b23e75
This commit updates the EE repository reference after PR #616 was merged in windmill-ee-private.
Previous ee-repo-ref: b5083e266492e908456e39401778a9cdcea46e94
New ee-repo-ref: 136f4634aca61e74ccb045372358a1e3f6b23e75
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* oauth: add ServiceNow provider; make per-instance OAuth registry-driven
ServiceNow's OAuth endpoints are per-instance
(https://<instance>.service-now.com/oauth_auth.do + /oauth_token.do), like
Snowflake's. Rather than add another bespoke special-case, generalize:
a registry entry may carry a `connect_config_template` (label/placeholder/
help_url + {instance}-templated auth_url/token_url + req_body_auth +
optional extra_params_key/strip_suffix). The instance-settings UI renders
one generic instance-name input for any such provider and substitutes
{instance} to build the per-client connect_config — a new per-instance
provider needs only a JSON entry, no frontend code.
- oauth_connect.json: servicenow + snowflake_oauth now carry a
connect_config_template (snowflake keeps its account_identifier
extra_params key for backward compatibility).
- windmill-oauth: add the ConnectConfigTemplate struct (frontend-only
metadata; the backend's existing connect_config override resolves the
concrete URLs generically — no other backend change).
- AuthSettings/InstanceSettings: replace the Snowflake + ServiceNow
special-cases with one registry-driven path (instanceInputs map,
setupTemplatedOauthUrls, loadInstanceInputs); per-instance providers are
derived from the registry for the builtins list + dropdown.
Pairs with windmill-integrations#139 (ServiceNow hub integration).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* ci: point ee-repo-ref at servicenow-oauth EE branch (revert at merge)
Temporary CI pointer so check_ee_full / cargo_test build against the EE
slack-literal fix (windmill-ee-private#602). Revert to a pinned SHA once
that EE PR is merged.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* oauth: add salesforce provider
Register Salesforce OAuth (Authorization Code) for Windmill resource connect.
Production uses login.salesforce.com; the sandbox block points at
test.salesforce.com (URL overrides only; scopes inherited) per #9358, so a single
canonical `salesforce` resource type covers both with separate `salesforce_sandbox`
instance credentials.
Paired with the hub integration: windmill-labs/windmill-integrations#131.
The Salesforce icon already exists in the frontend (SalesforceIcon.svelte).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Fix JSON syntax error in oauth_connect.json
* fix: add salesforce production tile to OAuth settings dropdown
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(oauth): support per-provider sandbox URLs in registry + instance settings
* fix(oauth): polish sandbox review nits (cc lookup, header label, ee ref)
* refactor(oauth): drop dead build_oauth_clients duplicate in windmill-oauth
* refactor(oauth): derive sandbox-capable provider list from registry
* chore(docker): copy oauth_connect.json into frontend build stage
* test(oauth): cover sandbox helpers (as_sandbox, canonical_name, resolve)
* chore: update ee-repo-ref to 9297d8f790346e6a6ad540c7bca1a67f91ec11a2
This commit updates the EE repository reference after PR #595 was merged in windmill-ee-private.
Previous ee-repo-ref: 3ab3eca9ac15ebab6db991e7964bc5e48ce21f42
New ee-repo-ref: 9297d8f790346e6a6ad540c7bca1a67f91ec11a2
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
Adds the Docusign Authorization Code OAuth entry. Used by the
Docusign integration in the windmill-integrations hub (PR #128).
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
* feat(oauth): add snowflake oauth support
* fixes
* fix keypair auth
* avoid loop when changing settings
* including account id doc link in the settings ui
---------
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>