* fix: unify billable seat counting and prevent fork subscriptions
* fix: authorize candidate before reading its plan, scope seat breakdown
* chore: pin ee ref for the stripe checkout fork guard
* fix: grant the billable_member view and widen the paid-plan check
* refactor: keep the seat rule in rust instead of a view and function
* docs: correct the attach guard summary after widening the plan check
* revert: keep cloud out of the ci test feature set
* chore: update ee-repo-ref to 9ff97cd818e85940fec282c92161e98c1b8583e2
This commit updates the EE repository reference after PR #742 was merged in windmill-ee-private.
Previous ee-repo-ref: 0ec0b42565a41f271a45bf24a93467d110c36df3
New ee-repo-ref: 9ff97cd818e85940fec282c92161e98c1b8583e2
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
* fix: strip the script/ prefix from trigger error handler paths
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: strip the script/ prefix when collecting trigger handler refs
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: relocate prefixed trigger error handlers on project retarget
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reject a prefixed error_handler_path on triggers instead of resolving it
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: describe error_handler_path as a bare script path in the api schema
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix: key build artifact caches on a runnable's inline modules
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: seal the cache-key base and skip prebundling multi-file bun scripts
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: tighten cache-key invariant comments and name the retained-artifact residual
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: version the build artifact keyspace so pre-fix artifacts are abandoned
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: namespace the artifact cache by keyspace version instead of the hash preimage
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: namespace module-bearing artifacts instead of versioning the whole keyspace
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test: pin the cache-name base seal and name the retained-artifact residual
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore: bump ee ref for agent-worker module resolution fix
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: align agent-worker module resolution with the worker for previews by hash
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: drop calculate_hash imports left unused by artifact_cache_name
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore: update ee-repo-ref to 2d6c66b32f20d9605c6a677727473ab66fcc8a87
This commit updates the EE repository reference after PR #743 was merged in windmill-ee-private.
Previous ee-repo-ref: efce983cae3d53175bbb286a10205a2a360c2a9e
New ee-repo-ref: 2d6c66b32f20d9605c6a677727473ab66fcc8a87
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
* feat: track AI fill, AI fix, evals, reusable agents and debugger usage
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore: pin ee ref to the feature_usage registry commit
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore: update ee-repo-ref to c3b6f62ea579a3583d4b474e9885c77104cfc87e
This commit updates the EE repository reference after PR #745 was merged in windmill-ee-private.
Previous ee-repo-ref: 77992910929188a854eadc06ee45971877b6f954
New ee-repo-ref: c3b6f62ea579a3583d4b474e9885c77104cfc87e
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
* fix(frontend): keep nested template literals intact in template inputs
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: fail a flow step with an unresolvable $args tag instead of hanging
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): surface input expression errors when running a step test
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): treat an escaped \${ as literal text when escaping backticks
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: accept the string "null" as a tag component, reject only JSON null
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: leave a same_worker step's inert tag alone, log an unresolved flow tag
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): escape every backtick when the template walk desynchronizes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: leave a dedicated runnable's inert step tag alone
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute a step only when its own tag is what failed to resolve
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: name the inert-tag guard step_is_pulled_by_tag
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reject a tag only when it interpolates to nothing at all
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): validate the template walk instead of trusting a balanced stack
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: describe what an unresolvable tag actually interpolates to
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor(frontend): decide template escaping with a real parser, not a hand-rolled scan
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: name is_flow_step on push now that it is load-bearing
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal an expression escaped before nested templates were handled
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute a step whose tag reads args that failed to evaluate
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: never hand a job that failed before running to a dedicated runner
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute only a step whose args failed, leave other tags untouched
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: drop the post-preprocessor tag fallback, leaving tag resolution untouched
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: leave interpolate_args exactly as it was
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test: use a generic example in the template literal tests
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): show an expression escaped by the old rule as it was authored
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): surface input expression errors from every step-run entry point
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: state what is_dedicated_worker actually reads
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal only text whose backticks were all escaped by the old rule
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): match the old rule textually so an authored backslash still heals
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal only expressions the old rule broke, never ones that parse
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* docs(api): document large completed job result placeholder
* style(api): use spaces for the large-result description indentation
Co-authored-by: Diego Imbert <70353967+diegoimbert@users.noreply.github.com>
---------
Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Diego Imbert <70353967+diegoimbert@users.noreply.github.com>
* fix: let a job token read the automate_username_creation setting
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test: use an ungated global setting as the confinement control
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix: restrict filesystem workspace storage to debug builds
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Q7p2VbtYqaXHGaAskgwVk5
* chore: update ee-repo-ref to b58ad414b098d3d7787001a352bfbb13e43a335f
This commit updates the EE repository reference after PR #747 was merged in windmill-ee-private.
Previous ee-repo-ref: 1b4dada77a8fe2224579c643550c63b1ac2616de
New ee-repo-ref: b58ad414b098d3d7787001a352bfbb13e43a335f
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix: keep connection string query parameters under token auth
* refactor: fold the database url parsing into one connect-options helper
* docs: state the narrower invariant on base_connect_options
* chore: update ee-repo-ref to 212cc7d61ec38580d4a70d9ac38d7a2cc9daf409
This commit updates the EE repository reference after PR #746 was merged in windmill-ee-private.
Previous ee-repo-ref: a15d08345d7e42526c28382079ad1f575a2d1674
New ee-repo-ref: 212cc7d61ec38580d4a70d9ac38d7a2cc9daf409
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix: force HTTP router rebuild on trigger-change notification
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: coalesce http trigger change events into one forced rebuild
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: retry the coalesced http router rebuild when it fails
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: mark http routers stale when a forced rebuild fails
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: keep the router invalidation across an in-flight rebuild
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix: require admin on workspace tarball settings export
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: name the refused flag in the settings export error
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix: migrate slack resource-connect oauth to v2
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: keep slack scopes one per entry, as every other provider does
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>