* feat: responsive modal step panel for the flow editor in sessions
On narrow layouts the flow editor's step-details pane opens as a modal
(double-click a graph node) instead of a split pane, with a dock/float
toggle. Scoped to sessions via allowModalPanel; the full-page editor is
unchanged.
- FlowEditor: modal/docked modes gated by mount width + allowModalPanel,
small header (step-id Badge + subtle dock/close), standing
double-click hint, and a per-step hint in the name tooltip
- selectionManager: onSelectIntent hook so flow-level panels (settings,
input, triggers…) open the modal on single click
- PropPickerWrapper: collapse the prop picker until connect and animate
it in via AnimatedPane (runs-page pattern), no blue connect ring in
modal mode
- StepInputGen: drop the TAB/Wand autocompletion button + spinner
(feature still works via focus + Tab)
- InputTransformForm: decouple the Help dropdown from the AI suggestion
- FlowModuleHeader: move 'Save to workspace' into an ellipsis dropdown
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: loop editor rendering and nested splitpanes splitters in the sessions modal
- Loop iterator/parallelism: keep the picker split pane (forceExpanded) so
the editor fills its box and the picker shows; the collapse-until-connect
mode stays for the step inputs
- Remove the intrusive AI TAB/Wand autocompletion button from IteratorGen
(generation still runs headless via focus + Tab)
- Size the iterator connect plug and restyle the loop header/labels/toggles
- Scope the global `.splitter-hidden` splitter-hiding rule to direct children
so it no longer leaks into nested Splitpanes under the sessions preview
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: redesign flow step advanced settings as a single toggle-first column
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: taller step test pane by default and restyle advanced section titles
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: show flow run-settings params disabled when a setting is toggled off
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: single-column for-loop panel reusing the run-settings accordion
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: single-column while-loop panel reusing the run-settings accordion
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: single-column branch panels reusing the run-settings accordion
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: auto-open modal panel when creating an AI agent tool
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: redesign branch panels with card layout and shared predicate editor
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* refactor: remove per-setting status badges from flow map nodes
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* chore: sync package-lock after windmill-utils-internal bump
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* style: polish prop-picker plug button and branch panel layouts
* fix: persist skip-if-stopped toggles in early stop settings
* fix: open the step panel modal on demand and cap its width
* fix: restore graph step setting badges, strip panel header chips instead
* feat: docked panel header with detach action and open-details step menu
* feat: width-based panel mode on every surface with inline detach action
* refactor: single source for flow step settings and their defaults
* docs: pin flow editor vocabulary in CONTEXT.md
* fix: open the trigger panel on double click or a specific trigger
* fix: keep module pickers inside their pane and dismissable
* fix: drop the misleading chevron on the MCP tool entry
* fix: resolve flow approvals against the job's workspace, not the nav one
* refactor: derive the approval workspace from the job, not from callers
* fix: restore S3 snippets and gate params while their setting is off
* fix: restore branch mock controls and address review findings
* chore: drop stray debug log from the flow map item
* feat: pinned output section for loop and branch panels
* fix: open the panel for deliberate navigation from the flow header
* perf: mount branch predicate editors on demand
* fix: skip predicate picker previews the previous step's result
* fix: flow-level graph nodes open their panel on a single click
* fix: open the step panel for AI chat selections, not for undo
* chore: drop dead console.log and duplicated modalPanel doc
* fix: re-sync expression editors and scope error-handler settings
* fix: match the failure module exactly and ignore unselectable nodes
* fix: keep concurrency editable, honour module cache_ttl, tighten panel ids
* fix: open panel from indirect selections, use presence for value-driven toggles
* fix: don't open settings on error-handler delete, flush editors on unmount
* fix: guard editor destroy flush, keep retry kind reachable
* refactor: name the run settings panel after the domain vocabulary
* fix: only write editor flushes to the step they belong to
* fix: bind step panels by id so a delete can't retarget editor writes
* fix: don't let the trigger picker's escape close the drawer beneath it
* docs: condense two comments to the constraint they record
* fix: arbitrate escape through the overlay stack instead of deferring to it
* fix: key nested step blocks by identity so anchored bindings can't go stale
* fix: untrack the overlay-stack push and drop the frozen branch binding
* chore: state the escape rationale once, key branch lists, format
* fix: let the topmost overlay own escape instead of the graph
* fix: keep the dynamic-input help box out of static template fields
* fix: restore the graph connect on the for-loop iterator
* fix: end connect mode with the modal and keep it to docked panels
* fix: never enter graph connect mode from the modal panel
* fix: reveal inserted steps, restore editor pane size, unleak the drawer stack
* fix: keep the enable-AI popover reachable in session panes
* feat: add the connect policy and its single armed slot
* refactor: one picker for every expression input
* refactor: route every connect through one armed slot
* fix: give every connect button the same footprint
* fix: keep the connect ring from showing through the button
* fix: keep flow card actions right-aligned beside the detach button
* fix: give the connect ring an opaque ground to mask against
* feat: dock the panel back without reopening it
* feat: dock the panel from the graph control bar
* style: round the graph control bar and size its glyphs
* style: customize the graph controls through their supported api
* style: build the graph control bar from lucide icons
* fix: use the graph's tooltip component in the zoom controls
* style: pad the graph controls and enlarge their glyphs
* style: pad the graph controls and put dock at the bar's end
* refactor: give settings rows the same popover picker as other expressions
* fix: pass the wrapper's pickable properties to nested inputs
* refactor: stack step settings and render every expression through the step input form
* feat: split loop panels into tabs and rework the approval form
* feat: anchor drawers to their host pane and give them a size floor
* fix: mark the loop iterator expression as required
* refactor: badge ee-only toggles instead of a warning line
* fix: flag an empty loop iterator expression as an error
* refactor: pick the early-stop flow status from one toggle group
* fix: keep parallel loops uncapped unless a limit is opted into
* fix: scope the overlay stack to its host and disarm connect on dismissal
* fix: anchor the trigger picker to its host pane
* feat: move diff into the menu when the top bar is narrow
* fix: gate the result logs toggle to the graph popover
* feat: raise the modal-panel breakpoint to 1280
* fix: anchor flow editor popovers and fullscreen to their host pane
* fix: anchor overlays to their host pane and mute them when hidden
* fix: portal hosted modals and menus into the pane they anchor to
* fix: keep non-listening dialogs off the overlay stack
* fix: drop the topmost gate from confirmation dialogs
* fix: silence overlays in a collapsed preview panel
* feat: rework the branch panels with tabs, reordering and add/delete
* refactor: fold the detached-panel chrome into the card header
* fix: give every flow panel a titled card header
* fix: stop the step panel oscillating on an auto-height editor
* feat: consolidate script panel actions and restore branch predicate AI
* fix: restore the logs toggle on the flow result popover
* fix: collapse the idle property picker in modal step panels
* fix: stop the docked pane scrolling alongside its panel
* fix: space the last settings row off the panel bottom
* revert: always show the property picker pane in step panels
* chore: keep the inline script AI button identical to main
* fix: ask for AI input suggestions on click, not on hover
* fix: keep graph connects armed and remount the parallelism input
* style: reveal the predicate AI button on row hover
* style: give branch cards a handle and delete column
* refactor: arbitrate flow overlay escape through Disposable
* fix: give the popover picker its results and re-narrow the EE badge
* docs: correct loopSubset and guard the modal width measurement
* fix: insert picked properties at the cursor in expression inputs
* fix: give the expanded-subflow panel the shared header chrome
* style: rename the suspend setting to Suspend until approval/resume
* feat: open a step's modal when clicking the step already selected
* feat: add an auto/attached/detached toggle for the step panel
* refactor: pick the step panel's placement from one named menu
* refactor: keep the panel-mode module's exports to what is consumed
* feat: show each configured setting's value on its badge
* fix: carry the suspend rename into the step settings registry
* docs: name both gestures in the step explore hint
* test: pin where the step panel goes for a given width and preference
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat: record and replay raw app sessions step by step
* fix: address review findings on raw app session recorder
* fix: stamp replay target before pruning the snapshot clone
* fix: redact step metadata, lock down replayed frames, fix control pre-state
* feat: add a checkpoint timeline to the app recording player
* fix: parser-based replay CSP, fold label clicks, drop stale frame indices
* fix: scrub redacted attributes, keep scroll, neutralize replay navigation
* fix: bound replay payloads, strip namespaced nav links, keep control pre-frames
* fix: strip SMIL navigation, redact metadata sources, capture pre-edit on beforeinput
* fix: redact template content, drop shadow templates, make replays inert
* test: pin snapshot redaction and replay sanitization with DOM tests
* fix: allow-list no-record attributes and cover a marked document root
* fix: classify input types positively so pickers get pre-change frames
* fix: one step per control interaction and bound step metadata
* fix: keep button inputs recordable and coalesce only continuous controls
* fix: no frames for coalesced repeats and drop inline styles when redacting
* fix: fold only the label's own click and keep marked stylesheets out
* fix: keep label-forwarded and radio-group pre-frames, fold submitter clicks
* fix: bound key pre-frames to their gesture and clear ancestor pointer frames
* fix: age-bound pre-frames and treat a radio group as one target
* fix: consume pre-frames per interaction and coalesce on the browser repeat flag
* fix: spend only the pre-frame a step actually used
* fix: settle a step from its successor's pre-state and drop stale pointer frames
* fix: bound remote frame payloads and snapshot stylesheets as rendered
* fix: let a control change spend its own frame and dedupe Enter activations
* fix: record Escape on controls and drop disabled stylesheets
* feat: collapse the replay step list by default behind a toggle
* fix: neutralize disabled sheets in place and fold Enter submissions
* fix: withhold redacted control state, fold key repeats, validate remote metadata
* fix: drop noscript markup and fold implicit form submissions
* fix: mask a select whose chosen option is redacted
* fix: mask redacted select choices before the clone diverges
* fix: run clone-paired passes before removals and fold only Enter submissions
* feat: record a raw app demo from the publish flow instead of the viewer
* fix: wait for in-flight runnable jobs before settling a step
* feat: record from the editor menu and replay publicly at /replay
* feat: export the app recording player and its loader for the hub
* feat: publish from folders only, drop iframe sharing
* fix: observe runnable responses where they land and mount the hub recording route
* fix: respect the app's sandbox opt-in when recording a session
* fix: let stop wait for the runnable the last step is still running
* fix: filter redacted class/id to styled tokens and gate publish on admin
* fix: drop marked sheets from the token vocabulary and bound the replay error
* test: pin the remote app-recording validator
* fix: carry in-flight runnables across a reload and fold held keys into one step
* fix: bind runnable responses off the request and honor base in the replay handoff
* fix: close the settling step when a new fill starts and always re-read stylesheets
* fix: empty the no-record marker so it carries nothing of its own
* fix: decode css escapes so utility classes survive redaction
* fix: read keyDriven from the frame the change starts from
* docs: condense recorder comments to the invariant each protects
* fix: rewrite only real url() tokens and accept leading css escapes
* feat: play flow, script and pipeline recordings on the public /replay page (#10327)
* feat: play flow, script and pipeline recordings on the public /replay page
* fix: render a recorded approval result inert while replaying
* fix: bound an asset sample's cell product and validate recording headers
* fix: make a replayed approval step inert and bound nested recording structures
* fix: stop recorded markup from fetching and bound flow/script render trees
* fix: gate recorded markdown at its renderer and close remaining render-budget gaps
* fix: replace per-key render caps with one structural budget per recorded value
* fix: bound component fan-out and text alongside the structural budget
* fix: make component fan-out cumulative and cap the parsed data-test checklist
* fix: bound the whole recording, graph contents, metadata strings and timer bursts
* fix: keep the published loader path, charge object keys, refuse huge serialized fan-out
* fix: cap flat maps a renderer turns into rows (args, schema properties)
* fix: refuse structure hidden past the depth ceiling and bound errored samples
* fix: count array-shaped argument collections against the row cap
* feat: paint canvas pixels into the snapshot
* fix: budget canvas encoding per snapshot and bound the unknown-kind error
* fix: cap flow graph overlay fan-out and condense budget comments
* docs: teach the raw-app prompt about data-wm-no-record
* feat(ai-chat): background jobs tray with detach, approval and preview
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): route exec_datatable_sql through the jobs tray
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): jobs tray — orange queued badge, 5-recent pagination, drop remove button
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(sessions): silence dev-only false-positive binding warnings
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(sessions): silence dev-only false-positive binding warning in FlowEditorView
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): auto-expand jobs tray on approval, close modal on resume
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): let the AI set a per-call inline wait before jobs detach
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): auto-resume the chat when a background job finishes while idle
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* feat(ai-chat): merge jobs tray and edits bar into a segmented session bar
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): address review — canceled-job handling, cross-chat poll guard, tests
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): gray chip dot for canceled-only jobs instead of green
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): keep jobs segment right-aligned when there are no edits
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): address /review — drain snapshot, live region, a11y, leading-ellipsis, remove dev harness
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): announce all same-tick job completions; drop redundant aria-live
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): guard poller re-entrancy; datatable error fallback (auto-review P2/nit)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): honor tool formatter on detached job completion; coalesce poller
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(ai-chat): persist tool result formatter so rehydrated detached jobs keep contract
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix: prevent browser freeze when approval form number field has no default value
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: disable approval buttons and keep polling after approve/deny action
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: restore approval page link and prevent double resume in flow viewer
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* fix: guard against NaN fallback in Range and reset actionTaken on new approval step
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix approval page url
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* feat: add selfApproval option to WAC waitForApproval + inline approval buttons
Add self-approval configuration to WAC workflows and inline
approve/reject buttons in WorkflowTimeline.
- TS SDK: add selfApproval option to waitForApproval()
- Python SDK: add self_approval param to wait_for_approval()
- Backend: store approval_conditions in flow_status for WAC,
enforce self-approval checks on resume endpoints
- Frontend: show Approve/Reject buttons in timeline with form
support (EE), gated by user permissions
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: revert sqlx query change + regenerate system prompts
- Revert get_suspended_flow_info to use original sqlx::query_as!
with COALESCE to avoid sqlx offline cache mismatch in CI
- Detect WAC by checking if FlowStatus parsing fails + suspend > 0
- Re-fetch flow_status column separately for WAC approval conditions
- Regenerate auto-generated system prompt files for SDK changes
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: use resume URLs for WAC inline approval buttons
- Backend generates HMAC-signed resume/cancel URLs when creating
WAC approval, stores them in timeline entry and approval meta
- Frontend uses anonymous resume endpoint (like classic flows)
with fallback to resumeSuspendedFlowAsOwner for admins
- Buttons show for everyone when URLs are present; server-side
self_approval_disabled check enforces restrictions
- Show warning for admins/owners when self-approval is disabled
- selfApproval: false requires EE (errors at dispatch on CE)
- self_approval_disabled check moved outside user_auth_required
gate so it works independently
- WAC detection no longer requires task import
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: add resume_suspended and approval_info endpoints
- New approval_token DB table for token-based approval access
- New POST /jobs_u/flow/resume_suspended/{job_id} endpoint:
- OptAuthed: works with login or approval_token
- Checks approval_conditions (self_approval, groups, auth)
- Admins/owners bypass rules
- New GET /jobs_u/flow/approval_info/{job_id} endpoint:
- Returns form, rules, can_approve status
- HMAC anonymous endpoint now bypasses all approval_conditions
(secret = full capability)
- getResumeUrls approvalPage URL now uses token format
- WAC approval dispatch generates and stores approval tokens
- Mark resumeSuspendedFlowAsOwner as legacy
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: simplify frontend to use resume_suspended endpoint
- OpenAPI spec updated with resume_suspended and approval_info endpoints
- WorkflowTimeline: removed URL parsing, now calls single
resumeSuspended endpoint for both approve and reject
- Buttons show for any logged-in user viewing the job (backend
enforces authorization rules)
- Kept self-approval warning for admins
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: stateless approval tokens, new approval page, FlowStatusWaitingForEvents update
- Replace DB-stored approval tokens with stateless HMAC derivation:
token = HMAC(workspace_key, job_id + "approval_token")
Verifiable without DB lookup, not reversible to resume secret
- Drop approval_token migration (no DB table needed)
- FlowStatusWaitingForEvents: use resumeSuspended endpoint instead
of URL parsing + resumeSuspendedFlowAsOwner
- New approval page route /approve/{ws}/{job}?token= that uses
approval_info and resume_suspended endpoints
- Old approval page route kept for back-compat
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: match old approval page content in new approval page
- Add FlowMetadata, JobArgs, FlowGraphV2, DisplayResult
- Add approvers with tooltips, flow arguments section
- Add admin self-approval bypass warning
- Add "Open run details" link
- Fetch full job alongside approval_info for all UI data
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: filter _MODULES from args, show 'workflow' for WAC approvals
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* chore: remove deno template from approval/prompt SuspendDrawer
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: approval page form display + hide deno from approval script picker
- Fix form schema rendering on new approval page by wrapping flat
WAC form schemas in { properties, order } for SchemaForm
- Hide deno from the approval step language picker in flow editor
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: remove deno from canHaveApproval in script_helpers.ts
The insert menu uses canHaveApproval() from script_helpers.ts via
FlowInputsQuick, not the displayLang function in FlowInputs.svelte.
Revert the unnecessary FlowInputs.svelte change.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: return form schema and description in approval_info for classic flows
The approval_info endpoint was returning None for form_schema on
classic flows. Now fetches raw_flow to get suspend.resume_form
schema, hide_cancel, and the step's completed result for description.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: inline Login component on approval page instead of redirect
Show the Login component directly on the approval page when
authentication is required. On successful login, reloads user
and approval info without navigating away.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: show resume buttons for all users, not just owners
The resume_suspended endpoint handles authorization server-side,
so the frontend should always show the buttons. Remove isOwner
gate and the "cannot resume" message.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: prevent layout shift on resume by removing spinner from cancel button
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: prevent resume button expansion by using disabled instead of loading
The loading prop adds a Loader2 spinner that expands the button width.
Use disabled={loading} instead to prevent layout shift.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: approval page login redirects back with full page reload
Set rd to the full URL (starts with http) so Login.redirectUser()
uses window.location.href instead of goto(), triggering a full page
reload after login. This ensures the approval page re-fetches data
as an authenticated user.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: fetch flow definition from flow_version when raw_flow is null
Deployed flows don't store raw_flow on the job. Fall back to
flow_version table using runnable_id to get suspend settings
(form schema, hide_cancel) for the approval_info endpoint.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: show specific reasons when user cannot approve
Display whether denial is due to self-approval being disabled,
required group membership, or both.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: support both nested and flat form schema in waitForApproval
Users can now pass either:
waitForApproval({ form: { schema: { name: { type: "string" } } } })
or:
waitForApproval({ form: { name: { type: "string" } } })
Both WorkflowTimeline and approval page handle both formats.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: convert sqlx query macros to non-macro for CI offline cache
Replace sqlx::query! and sqlx::query_scalar! with sqlx::query and
sqlx::query_as to avoid SQLX_OFFLINE cache misses in CI.
Also remove unused LogIn import from approval page.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: suppress dead code warning + unused isOwner variable
- Add #[allow(dead_code)] to without_flow method (CI -D warnings)
- Rename isOwner to _isOwner in FlowStatusWaitingForEvents (unused)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: security and robustness fixes from PR review
- Add workspace_id verification in resume_suspended to prevent
cross-workspace approval (#3)
- Fix token leakage: use relative path for login redirect instead
of full URL with token (#4)
- Handle getJob failure independently from approval_info so the
page works for unauthenticated users (#7)
- Clear error state on successful data load (#13)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: address review feedback — shared token gen, rand resume_id, UX
- Move generate_approval_token to windmill-common::variables (shared
between windmill-api and windmill-worker, eliminates duplicate HMAC)
- Use rand::random::<u32>() for resume_id instead of DefaultHasher
- Stop polling after approve/reject on approval page
- Add cancelLoading state to WorkflowTimeline Reject button
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* migrate FlowPreviewContent to svelte 5
* run background preview from input panel
* share local run test
* Show approval in graph is testing in graph
* use component and props instead of portal for approval in graph
* Add a toggle to show module status in graph
* open module result after each run
* Fix module reactivity issue
* Add test flow button
* Extract preview run logic from flowPreviewContent
* Revert "Extract preview run logic from flowPreviewContent"
This reverts commit a39c70a920.
* nit
* lazy load preview content
* create component for flow preview button
* open preview v0
* open preview v1
* connect open preview button
* improve graph run display
* enable cancel preview
* Run test flow from input panel
* nit
* wip
* Use global context instead of module context for moduleTestState
* nit
* fix flow preview rendering
* Add testJob to modulesTest context
* update module status based on individual test data
* fix: clear job status on run preview
* detatch run buttons from input node
* move preview job in FlowEditorContext
* move outputPickerOpenFns to FlowEditorContext
* add result panel
* Add result output picker
* add status to loops and branch
* add open detail button to result panel
* fix test up to
* clean unnecessary binding
* clean
* Make iteration annotation smaller in editmode
* detatch test button to and aproval from node
* prevent flow edition during execution
* Prevent step test run during flow run
* Show approval in graph edges
* prevent opening output popover if node is outside the graph
* fix pointerdownOutside action
* fix test up to dropdown not closing
* fix test up to
* nit
* change job status badge display
* fix running status
* Enable test flow in Dev
* fix darkmode
* fix node panel display in Dev
* fix test flow button positionning
* fix suspend in subflows
* improve lazy load of preview
* prevent preview data unmount on close drawer
* clean code
* move flowjob into flow context
* Revert "move flowjob into flow context"
This reverts commit 939e9dbaaf.
* clean context
* nit
* fix dark mode status view
* fix test button alignment
* clean job status on deleted step
* fix retry bad status display
* Detect flow change
* Update frontend/src/lib/components/flows/header/FlowPreviewButtons.svelte
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>
---------
Co-authored-by: ellipsis-dev[bot] <65095814+ellipsis-dev[bot]@users.noreply.github.com>