Diego Imbert
42271dcf7f
Merge remote-tracking branch 'origin/main' into datatable-perms-3
...
# Conflicts:
# backend/ee-repo-ref.txt
2026-09-04 09:32:27 +02:00
Ruben Fiszel and rubenfiszel
38fc0d3a12
chore(main): release 1.803.0 ( #10952 )
...
* chore(main): release 1.803.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-09-03 13:08:33 +02:00
Ruben Fiszel and rubenfiszel
74c1813f98
chore(main): release 1.801.0 ( #10921 )
...
* chore(main): release 1.801.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-09-02 01:01:01 +02:00
Ruben Fiszel and rubenfiszel
870f67121d
chore(main): release 1.800.1 ( #10910 )
...
* chore(main): release 1.800.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-09-01 11:34:32 +02:00
Diego Imbert
7619a7a51e
fix(datatables): keep role passwords out of audit, and role names out of SQL
...
The audit parameter of a data table config save carried the whole settings
blob, generated role passwords included. Redact it the way every other
export of that blob already is.
Both SDKs pasted the caller's role straight into the `-- role` annotation,
where a newline ends the comment and leaves the rest running as whatever the
first line named. Check the value against the role-name grammar the server
enforces.
2026-09-01 04:09:12 +02:00
Diego Imbert
709cf8aecb
Merge remote-tracking branch 'origin/main' into datatable-perms-3
...
# Conflicts:
# backend/ee-repo-ref.txt
2026-08-31 22:01:47 +02:00
Ruben Fiszel and rubenfiszel
412eb90c0d
chore(main): release 1.800.0 ( #10888 )
...
* chore(main): release 1.800.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-31 20:29:23 +02:00
Ruben Fiszel and rubenfiszel
7a0c81d722
chore(main): release 1.799.0 ( #10874 )
...
* chore(main): release 1.799.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-28 17:26:18 +02:00
Ruben Fiszel and rubenfiszel
90b40fffc3
chore(main): release 1.798.1 ( #10870 )
...
* chore(main): release 1.798.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-27 12:00:45 +02:00
Ruben Fiszel and rubenfiszel
2302e58c24
chore(main): release 1.798.0 ( #10868 )
...
* chore(main): release 1.798.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-27 11:07:15 +02:00
Ruben Fiszel and rubenfiszel
52ca19e9ae
chore(main): release 1.797.0 ( #10848 )
...
* chore(main): release 1.797.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-27 10:15:23 +02:00
Diego Imbert
ae162b6d3e
Merge branch 'main' into datatable-perms-3
2026-08-26 10:24:13 +02:00
Diego Imbert and Claude Opus 5
8a6dc27236
feat: configurable expiry for presigned s3 public url signatures ( #10835 )
...
* feat: configurable expiry for presigned s3 public url signatures
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_015JdZFeMXLGfeFNiQgx9QvA
* fix: describe expiry_secs clamping in the spec and pin the bounds in a test
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_015JdZFeMXLGfeFNiQgx9QvA
* fix: omit null expiry_secs from the python sdk sign request
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_015JdZFeMXLGfeFNiQgx9QvA
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-26 00:47:24 +02:00
Diego Imbert
665cadbca6
feat(datatables): take the sdk role as an options argument
2026-08-25 14:08:37 +02:00
Ruben Fiszel and rubenfiszel
0f3d884c6f
chore(main): release 1.796.0 ( #10810 )
...
* chore(main): release 1.796.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-24 22:42:33 +02:00
Diego Imbert
4e53d1ac45
chore(datatables): regenerate cli/system-prompt docs for the datatable role param
2026-08-24 08:46:17 +02:00
Diego Imbert
5974f5491d
Merge remote-tracking branch 'origin/main' into datatable-perms-3
...
# Conflicts:
# backend/ee-repo-ref.txt
# backend/parsers/windmill-parser/src/asset_parser.rs
# backend/windmill-common/src/workspaces.rs
2026-08-24 08:39:01 +02:00
Ruben Fiszel and rubenfiszel
74af4ed939
chore(main): release 1.795.0 ( #10807 )
...
* chore(main): release 1.795.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-22 12:11:36 +02:00
Ruben Fiszel and rubenfiszel
1a506b8f22
chore(main): release 1.794.1 ( #10801 )
...
* chore(main): release 1.794.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-21 13:45:56 +00:00
Ruben Fiszel and rubenfiszel
55b6279058
chore(main): release 1.794.0 ( #10782 )
...
* chore(main): release 1.794.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-21 12:27:44 +02:00
Ruben Fiszel and rubenfiszel
2439a610be
chore(main): release 1.793.0 ( #10764 )
...
* chore(main): release 1.793.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-20 22:18:01 +02:00
Ruben Fiszel and rubenfiszel
a7637aca31
chore(main): release 1.792.2 ( #10753 )
...
* chore(main): release 1.792.2
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-19 14:15:59 +02:00
Ruben Fiszel and rubenfiszel
9f517d5a40
chore(main): release 1.792.1 ( #10750 )
...
* chore(main): release 1.792.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-18 17:10:42 +02:00
Ruben Fiszel and rubenfiszel
8efede55d6
chore(main): release 1.792.0 ( #10745 )
...
* chore(main): release 1.792.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-18 12:32:35 +02:00
Ruben Fiszel and rubenfiszel
ce71756c89
chore(main): release 1.791.0 ( #10718 )
...
* chore(main): release 1.791.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-18 01:55:42 +02:00
Ruben Fiszel and rubenfiszel
010d67e07f
chore(main): release 1.790.1 ( #10712 )
...
* chore(main): release 1.790.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-17 11:08:47 +02:00
Ruben Fiszel and rubenfiszel
944ad1083a
chore(main): release 1.790.0 ( #10699 )
...
* chore(main): release 1.790.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-15 14:54:31 +02:00
Ruben Fiszel and rubenfiszel
80a18ec284
chore(main): release 1.789.0 ( #10670 )
...
* chore(main): release 1.789.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-13 13:29:52 +02:00
Ruben Fiszel and rubenfiszel
b39860235c
chore(main): release 1.788.0 ( #10664 )
...
* chore(main): release 1.788.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-12 21:17:47 +02:00
Ruben Fiszel and rubenfiszel
2ac3e64fe2
chore(main): release 1.787.0 ( #10657 )
...
* chore(main): release 1.787.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-12 13:27:21 +02:00
Ruben Fiszel and rubenfiszel
20953a0c67
chore(main): release 1.786.1 ( #10652 )
...
* chore(main): release 1.786.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-12 09:40:03 +02:00
Ruben Fiszel and rubenfiszel
45a6e4932a
chore(main): release 1.786.0 ( #10649 )
...
* chore(main): release 1.786.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-12 02:22:18 +02:00
Ruben Fiszel and rubenfiszel
a65a184a80
chore(main): release 1.785.0 ( #10626 )
...
* chore(main): release 1.785.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-11 18:26:31 +00:00
Ruben Fiszel and Claude Opus 5
ede4e7781d
unbreak the JSR publish of the typescript client ( #10627 )
...
* fix(sdk): unbreak the JSR publish of the typescript client
`Sql` is `export type Sql = string`, but build.jsr.sh re-exported it as a
value, so `deno publish` fails type-checking with TS1205 under
isolatedModules. Every `v*` tag since has published nothing to JSR.
The npm build never noticed because it lists the same symbol as `type Sql`;
the two scripts keep separate copies of the export list.
Record both JSR-only constraints next to the list, since neither shows up
until a release tag runs publish.jsr.sh.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
* fix(sdk): scope the slow-types note to what deno actually rejects
Deno's fast check only rejects a return type it cannot trivially infer;
setClient, appendToResultStream and streamResult are all exported without
one and publish fine. The previous wording read as if the current list were
already non-compliant.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-11 09:24:47 +02:00
d9b9137e17
feat(sdk): add cancelJob to the TypeScript client ( #10624 )
...
* feat(sdk): add cancelJob to the TypeScript client
The Python client has had cancel_job since forever; the TypeScript one had no
way to cancel a job at all. Wire the same jobs_u/queue/cancel endpoint, with a
default reason when none is given, and export it from both the named and
default exports of the npm package as well as the JSR one.
* chore: regenerate system prompts for cancelJob
check-system-prompts triggers on typescript-client/**, so the agent-facing SDK
reference has to carry the new function.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Tushar <tusharanshu18@gmail.com >
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-11 08:45:48 +02:00
Ruben Fiszel and rubenfiszel
cf3ddaa3cc
chore(main): release 1.784.0 ( #10603 )
...
* chore(main): release 1.784.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-10 22:56:55 +02:00
Ruben Fiszel and rubenfiszel
099efa358a
chore(main): release 1.783.0 ( #10578 )
...
* chore(main): release 1.783.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-07 12:41:05 +02:00
Ruben Fiszel and rubenfiszel
d592fb75eb
chore(main): release 1.782.0 ( #10566 )
...
* chore(main): release 1.782.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-06 12:55:48 +02:00
Ruben Fiszel and rubenfiszel
c03bd34be9
chore(main): release 1.781.3 ( #10563 )
...
* chore(main): release 1.781.3
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-06 10:02:27 +02:00
Ruben Fiszel and rubenfiszel
74737d16dd
chore(main): release 1.781.2 ( #10561 )
...
* chore(main): release 1.781.2
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-06 09:53:18 +02:00
Ruben Fiszel and rubenfiszel
c7ea530e1f
chore(main): release 1.781.1 ( #10556 )
...
* chore(main): release 1.781.1
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-06 02:17:57 +00:00
Ruben Fiszel and rubenfiszel
9cf307f3ad
chore(main): release 1.781.0 ( #10528 )
...
* chore(main): release 1.781.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-06 00:04:25 +02:00
Ruben Fiszel and rubenfiszel
055a9c2690
chore(main): release 1.780.0 ( #10527 )
...
* chore(main): release 1.780.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-05 00:37:06 +02:00
Ruben Fiszel and rubenfiszel
59072a1273
chore(main): release 1.779.0 ( #10496 )
...
* chore(main): release 1.779.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-04 20:45:57 +02:00
Diego Imbert
23cd7737b6
feat(datatables): opt-in role-based permissions
2026-08-04 18:59:03 +02:00
Ruben Fiszel and rubenfiszel
4c4d6c98bf
chore(main): release 1.778.0 ( #10469 )
...
* chore(main): release 1.778.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-04 01:49:00 +02:00
7e1c1fa3a4
feat(apps): use the windmill-client SDK from raw app frontend code ( #10377 )
...
* feat(apps): use the windmill-client SDK from raw app frontend code
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): bound the raw app SDK token to deployed runnables
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): deny dependency jobs and survive a failed SDK mint
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): confine the SDK token's users scope to the viewer's identity
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* docs: describe the full raw-app SDK sentinel narrowing
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): deny workflow-as-code replay for raw app SDK tokens
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): deny preview-flow restart replay for raw app SDK tokens
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): re-prompt when an app widens its SDK scopes mid-consent
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* feat(apps): support the frontend SDK in sandboxed raw apps
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): hand the sandboxed SDK token over only once per loaded document
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): bind the sandboxed SDK handoff to the document we loaded
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): use an unguessable nonce for the sandboxed SDK handoff
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): reply to the sandboxed SDK handshake over its own port
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): answer the raw app handshake only over a transferred port
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): set frontend_sdk_scopes in the S3-gated policy literals
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* docs: describe the sandboxed wrapper's credential as it now works
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* ui nit
* feat(apps): make the frontend SDK work in the raw app editor preview
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): guard the preview token mint and drop superseded responses
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): refuse job tokens on every raw app SDK mint path
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* docs: correct the mint caller list and the preview retry rationale
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): apply the consent response's render mode before rendering
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): restart the viewer when a redeploy changes the render mode
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): restart on every render-mode change, not just the first
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): clear the preview's SDK credential when scopes go away
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): remove window.process in the preview instead of blanking it
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* docs: cut the raw app SDK comments down to the invariant
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* refactor(apps): use randomUUID for the raw app handshake nonce
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): re-read the render mode before rendering without a token
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* fix(apps): make the raw app handshake nonce unguessable again
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* chore: pin the EE ref to a commit that builds against this OSS tree
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_018Gmsk9kAG7p9t2Qy6ADRJz
* refactor(apps): authenticate the raw app preview by session instead of a token
The editor preview is same-origin and unsandboxed, so app code there already
holds the editing user's session cookie. Minting a scoped bearer for it added
an endpoint and a portable 12h credential without containing anything.
Inject only BASE_URL and WM_WORKSPACE: `windmill-client` falls back to
credentialed same-origin requests when it finds no token, so the SDK runs as
the editing user. Drops POST /apps/preview_sdk_token and the mint/race
handling in the editor.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* fix(sdk): send credentials only outside the browser
The API answers `Access-Control-Allow-Origin: *` and never sets
`allow_credentials`, so a credentialed cross-origin request fails before the
bearer is read — which is what a sandboxed raw app issues. Keying this on the
browser rather than on `WM_TOKEN` leaves non-browser callers byte-identical,
and browsers keep sending cookies same-origin through fetch's own default.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* remove windmill-client from templates
* fix(sdk): drop credentials only for raw app bundles
A sandboxed raw app calls the API from an opaque origin, and the API answers
`Access-Control-Allow-Origin: *`, which a credentialed request can never pair
with. Gate on WM_RAW_APP, set by the two places that build a raw app's
`window.process.env`, so every other windmill-client consumer is untouched.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* feat(apps): make frontend SDK access sandbox-only
An unsandboxed bundle runs same-origin with the viewer's full session, so a
consent prompt there implies a boundary that does not exist and the token adds
nothing it could not already do. Advertise scopes and mint only when isolation
is on; turning the toggle off clears the declared scopes with it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* Revert "refactor(apps): authenticate the raw app preview by session instead of a token"
This reverts commit 81905e455b , restoring POST /apps/preview_sdk_token.
Session auth gave the preview the editing user's full permissions and worked
regardless of policy, so an app that would 403 for a viewer — or that declares
no scopes at all — ran fine in the preview and broke only once deployed. The
preview now takes the same credential as a deployed app, gated the same way:
sandbox off or no scopes means no env at all.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* docs(apps): state the sandbox-only SDK contract in the public schema
The Policy and EmbedTokenResponse descriptions still promised a token to any
raw app with non-empty scopes, and said raw apps skip tokens entirely. Point
authors at adding windmill-client themselves too, since the starter templates
no longer carry it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* fix(apps): drop the preview token before minting its replacement
A mint is asynchronous, so clearing the env only on the empty-scope path left
the running preview — and any build fed meanwhile — holding scopes the policy
had just removed, or a token for the workspace just left, for as long as the
request took.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* fix(apps): restart the preview realm when its credential changes
Re-feeding the build resets the preview's DOM but keeps its JavaScript realm,
so the previous bundle's timers, listeners and pending callbacks went on using
the client they imported — and the token it captured at module load — after the
policy dropped it. Reload both shells instead; each replays the build on its
way back, so only the new realm survives.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* fix(apps): start the preview once per credential change
Restarting the realm made its shell replay the build immediately, so a delayed
mint ran the app once tokenless and again tokenful — mount-time side effects
twice per scope or workspace change. Hold the build back until the mint
settles: the shell comes back blank and whichever finishes last starts the app.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* fix(apps): wait for the detached preview shell before replaying
Its reload was only initiated, never awaited — unlike the inline iframe it had
no readiness flag — so a mint settling first posted the build to the retiring
document, which then ran alongside the replacement shell's own replay. Track
readiness from both paths that announce it: `load` for a freshly opened window,
`appPreviewReady` for a reload.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01KPCW1WB5QeYrgJmgwcywNA
* chore: update ee-repo-ref to 99e143fa1e2e6c33b3525366a5afe48f7a4f020e
This commit updates the EE repository reference after PR #688 was merged in windmill-ee-private.
Previous ee-repo-ref: 609e197fbc08f1ce83dd86f816748cc19d213f77
New ee-repo-ref: 99e143fa1e2e6c33b3525366a5afe48f7a4f020e
Automated by sync-ee-ref workflow.
* nit better description
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
2026-08-03 19:31:57 +00:00
6b9691df3a
chore(main): release 1.777.1 ( #10464 )
...
* chore(main): release 1.777.1
* Apply automatic changes
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
Co-authored-by: windmill-internal-app[bot] <217088191+windmill-internal-app[bot]@users.noreply.github.com>
2026-08-03 13:18:26 +02:00
Ruben Fiszel and rubenfiszel
45b5c7a0c0
chore(main): release 1.777.0 ( #10454 )
...
* chore(main): release 1.777.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-03 12:32:57 +02:00
Ruben Fiszel and rubenfiszel
b0a2c8ca44
chore(main): release 1.776.0 ( #10406 )
...
* chore(main): release 1.776.0
* Apply automatic changes
---------
Co-authored-by: rubenfiszel <275584+rubenfiszel@users.noreply.github.com >
2026-08-01 20:47:00 +02:00