mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-09 00:04:10 +00:00
bf1b2cdcf9cd5251ee0560077db307b6003d472c
6786
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
bf1b2cdcf9 |
fix(duckdb): cast list columns in quicksearch so tables containing them can be previewed (#10614)
* fix(duckdb): cast columns in quicksearch so nested types can be previewed
DuckDB's `CONCAT` implicitly casts scalars but rejects nested types:
D SELECT CONCAT(' ', ['a','b']);
Binder Error: Cannot concatenate types VARCHAR and VARCHAR[] - an explicit
cast is required
Quicksearch concatenates every visible column, so one LIST, STRUCT or MAP column
makes a table impossible to preview — both the grid and its row count fail:
Binder Error: Cannot concatenate types VARCHAR, VARCHAR, BIGINT, ...,
VARCHAR[], ... and TIMESTAMP WITH TIME ZONE - an explicit cast is required
LINE 1: ... FROM "raw"."accounts" WHERE ($1 = '' OR CONCAT(' ', "id", ...
Every scalar in that list concatenates fine on its own — VARCHAR, BIGINT,
DOUBLE, BOOLEAN, DATE and TIMESTAMPTZ were each checked individually — so the
array column is the entire cause.
Cast each column in the predicate. The comparison is textual either way, so no
result changes, and the projection is untouched: casting there would change the
types the caller reads back. This follows the shape already used for MSSQL in
`mssql_needs_cast_for_eq`.
Both DuckDB quicksearch sites are covered, SELECT and COUNT. Fixing one leaves
the grid rendering while the row count still errors.
Tests include the live path: the Database Manager sends a
`-- WM_INTERNAL_DB_SELECT {...}` marker and the backend expands it, so the new
test drives that expansion with the real 27-column definition captured from a
failing job, `sync_id VARCHAR[]` included. It fails without the fix and passes
with it.
* fix(frontend): cast columns in the DuckDB quicksearch
Same defect as the Rust query builders, in the implementation that actually
runs. `make_select_query` / `make_count_query` in windmill-common have no callers
anywhere in the repo; the query the browser sends is built here.
DuckDB's CONCAT implicitly casts scalars but rejects nested types, and
quicksearch concatenates every visible column, so one LIST column makes a table
impossible to preview — both the page and its row count fail with
Binder Error: Cannot concatenate types VARCHAR, ..., VARCHAR[], ... and
TIMESTAMP WITH TIME ZONE - an explicit cast is required
The helper lives in select.ts and is imported by count.ts so the two cannot
drift, and both call sites are fixed: fixing only SELECT leaves the grid
rendering while the row count still errors.
* fix(duckdb): cast only list columns in quicksearch, leaving other SQL byte-identical
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* test(frontend): pin the DuckDB quicksearch column list byte-for-byte
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
8c65511e81 |
fix: raw app new-app modal ignores instance-level AI settings (#10619)
* fix: stop the new raw app modal claiming AI is unconfigured before it knows Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: require a resolved workspace before trusting the loaded AI config Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: drop the unreachable token guard and point superadmins at instance settings Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: show the instance settings link to superadmins who are not workspace admins Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
77adf85ccd |
feat: version history for session artifacts (#10574)
* fix: never replace an in-flight indexeddb open, only a settled one Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: keep a version history for session artifacts Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: let the assistant browse an artifact's earlier versions Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: pick an older artifact version from the preview panel Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(ai_evals): cover the change note the assistant writes on each edit Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: bound every indexeddb open, not only one told it is blocked --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
4a69cd616e | keep the logins state declaration from narrowing to undefined (#10618) | ||
|
|
c725d62fb0 |
fix(frontend): call a dev workspace a dev workspace in the merge UI (#10605)
* fix(frontend): call a dev workspace a dev workspace in the merge UI Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor(frontend): drop the unreachable dev-workspace guard on the fork modals Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
1a709d49f9 |
unblock the frontend check (type error + svelte-check OOM) (#10617)
* fix(frontend): count login options inside a closure so tsc keeps their type * ci: give svelte-check a heap above node's 4GB default |
||
|
|
676256bacc |
feat(flow-editor): measure step panel placement (#10543)
* feat(flow-editor): measure the redesigned step panels Instruments the flow editor's step, loop and branch panels on the existing anonymous `feature_usage` channel, so the redesign can be judged on how the panels are actually used rather than on nothing. Eight event kinds under a new `flow_editor` feature: panel opens and their dwell (bucketed, per placement), placement-preference overrides, which settings get configured or cleared, settings that read as invalid, the prop-picker connect lifecycle, AI input suggestions, and the step header menu that "Save to workspace" now lives behind. Settings changes are diffed off `describeStepSettings`, the same view the graph badges render, so the telemetry vocabulary cannot drift from the one on screen. Only `panel_open` and `setting` carry an entity id — one opaque id per editor mount — since a per-entity row is only worth its cost where the spread per editing session is the question. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(flow-editor): keep the panel telemetry honest Review follow-ups on the instrumentation: - The top dwell bucket was `120s+`, and `+` is outside the charset `is_identifier_shaped` accepts, so `log_feature_usage` skipped those events and still answered 204 — the longest visits vanished with no error on either side. Renamed to `120s_plus` and pinned every emittable key against the backend's charset in a test, since the producer is TypeScript and the validator is Rust. - Dropped the per-session entity id from `setting`: it would pay a row per session per day across twenty-four keys, for a distribution its plain counter already largely answers. - An armed connect that went away with its component never reported, so `open` did not balance against `insert` + `abandon`. - Session preview tabs keep hidden editors mounted, which billed panel time nobody spent. `FlowEditorView` now publishes the visibility it already knows about. - Re-picking the active placement row logged a move, which also made `auto:from_docked` mean two different things. - The last dwell of a session was lost on tab close, since Svelte tears components down on navigation but not on `pagehide`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor(flow-editor): narrow the telemetry to panel placement The eight-kind instrumentation measured more than could be read. With nothing recorded before the redesign there is no baseline to compare panel opens, dwell times, settings usage or connect funnels against, so those counters answered questions nobody could act on while costing a row per key per day in an instance-wide table. What remains are the three numbers the modal panel is actually judged on: how often the 1280px breakpoint puts the panel in a modal, and how often people override that in each direction. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(flow-editor): stop counting placement in session preview tabs Preview tabs keep every flow editor mounted and laid out at panel width whether or not it is the visible one, and that panel is narrower than the breakpoint by construction. Each flow tab opened in a session therefore emitted a `breakpoint_modal` on mount, and one drag of the session panel across 1280px emitted one per mounted tab — with no host dimension in the key to separate that from the crossings the counter exists to measure. Also corrects the comment on the no-op placement guard, which justified itself with a key vocabulary that no longer exists. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(flow-editor): make the three placement counters comparable Sessions were excluded from the breakpoint counter but not from the two override counters, so a pin made in a session landed in the same bucket used to judge the breakpoint, with no crossing in the denominator to read it against. All three are now gated together. An override is also only counted when it moves the panel. Choosing "Detached" on an editor the width had already put in a modal states a preference without changing anything, and the aggregate carries no width to separate that from the wide-screen override that is the actual signal. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs(flow-editor): describe the two override keys by what emits them They documented themselves as overriding `auto`, which is no longer the rule: pinning Attached on a wide editor overrides `auto` and emits nothing, while going from an Attached pin to Detached below the breakpoint emits `force_detach` even though `auto` would have produced a modal there too. This file is what someone reads when interpreting the numbers, and "override of auto" is the misreading the emission rule exists to prevent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(flow-editor): count the panel moving, not the breakpoint being armed The tracker held "the breakpoint is responsible for this modal" rather than "the panel is modal", so on a narrow editor pinning Detached and releasing it back to Auto emitted a second breakpoint_modal for a panel that never moved. It also died with the editor, which FlowBuilder rebuilds through a `{#key}` on every reload — each rebuild re-armed it and counted the same narrow editor again. Both inflate the denominator that the two override counters are read against, and both bias it the same way: toward concluding that nobody overrides the breakpoint. The tracker now follows the panel's placement across preference changes, and FlowBuilder owns it from above the `{#key}`, which also puts the session exclusion in one place instead of at each call site. The moves-only rule moves into `forcedPlacementEvent` so both halves of it sit in the module the tests can reach. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(flow-editor): ignore placements measured before the editor is laid out A reload rebuilds the editor through `{#key renderCount}`, and the panel controller is rebuilt with it: its width restarts at zero, which resolves to `docked` because that is what is safe to render rather than because the editor is wide. The breakpoint tracker read that transient as the panel having docked and counted the real width landing as a fresh crossing, inflating the denominator both override ratios are read against. `useFlowPanelMode` now exposes `measured`, and the tracker skips anything unmeasured instead of recording it as a placement. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs(flow-editor): state the placement invariants once each The width-zero rule had accumulated at four sites, two of which forward it without being able to break it. Keep it beside the guards that enforce it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
d638fab5f6 |
stack login options in one column below four (#10598)
* fix(frontend): stack login options in one column below four * style(frontend): drop redundant w-full on login buttons |
||
|
|
0459dda1bf |
correct typo in NATS consumer name description (#10585)
The consumer name field in the NATS trigger config read "Required is using JetStream" instead of "Required if using JetStream", matching the wording already used by the sibling stream name field. Fixes WIN-2335 Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
8c6211c277 |
feat: offer more dev workspace environment labels (#10570)
* feat: allow custom dev workspace environment labels Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: reject dev labels that shadow a tracked branch's namespace Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: guard dev labels against a repo's assumed default branch Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore: state the badge-cap rationale once and drop unenforceable openapi constraints Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: offer a fixed list of environment labels instead of free text Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: match the accepted label set to the openapi enum exactly Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: stop describing the label set as dev/staging only Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
57ed0f77e1 |
fix(frontend): hide the fork workspace banner from operators (#10575)
* fix(frontend): hide the fork workspace banner from operators * fix(frontend): scope the operator gate to the workspace its role was fetched for * fix(frontend): drop superseded whoami responses instead of writing a stale role * fix(frontend): guard the remaining workspace-switch userStore writers |
||
|
|
3c1403ee09 | trim narration comments and drop duplicated badge hover palette (#10579) | ||
|
|
d0089758e6 |
feat: open a session edit in the preview panel from the edits list (#10486)
* feat: open a session edit in the preview panel from the edits list * refactor: move the deploy-kind preview mapping next to its siblings * feat: make preview the primary action in the session edits list Clicking a row in the Edits popover now opens the item in the session preview panel; kinds the panel cannot host fall back to their diff. Each row gains an explicit Diff button for that item, and a pinned footer row opens Review & deploy for the whole set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: fold the open-and-flash rule into SessionPreviewTabs The rule for when a preview open should flash the tab was written out at three call sites, one of them with a looser condition. Move it onto the tab owner as openAndPulse so the three agree. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: preview data-pipeline edits from the edits list A pipeline bundle is stored at `f/<folder>/data_pipeline` while its editor is the folder's pipeline view, so the deploy-kind mapping has to route on the folder. Without it the one remaining previewable kind fell through to the drawer. Also pin the open-and-flash rule with tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: state the pipeline bundle path layout once `f/<folder>/data_pipeline` was parsed independently in the compare page, the home list and the session preview mapping — two of them disagreeing on whether the trailing segment is checked — and built by hand in the editor. Route all four through $lib/pipelinePaths. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: route the pipeline page through the shared bundle path The route built the bundle path by hand and passed the draft kind as a literal, the two halves of the editor disagreeing on where the layout is stated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: name a pipeline edit by its folder in the edits list The bundle path is an implementation detail and the row's click lands on the folder's editor, so showing `f/<folder>/data_pipeline` named something the click doesn't open. Also derive the bundle regex from the draft-kind const it has to agree with. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(cli): drop unrelated package-lock.json change The lockfile diff was an incidental regeneration from an older manifest (it downgraded the locked svelte range below what cli/package.json requires) and had nothing to do with this PR. Reset to main's version. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Ruben Fiszel <ruben@windmill.dev> |
||
|
|
c61404a0f4 |
feat: preview merge result in git-sync PR diff check (#10542)
* feat: preview PR merge result in git-sync diff check * chore: update ee-repo-ref * fix: match pr diff sentinels as structured field, tighten comments * chore: update ee-repo-ref * fix: neutral verdict for unfetchable pr head, testable sentinel parse * chore: bump git-sync pull script pin to hub/28889 * chore: bump git-sync pull script pin to hub/28890 * fix: cover failed history deepening in unavailable-head check text * chore: update ee-repo-ref to 181fa0c206d7f84a289b4396a7f7764bc815d284 This commit updates the EE repository reference after PR #712 was merged in windmill-ee-private. Previous ee-repo-ref: 36f5c0e9d147f9eed63ebc316f2aef9f86b500af New ee-repo-ref: 181fa0c206d7f84a289b4396a7f7764bc815d284 Automated by sync-ee-ref workflow. --------- Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com> Co-authored-by: Ruben Fiszel <ruben@windmill.dev> |
||
|
|
4de1bf5beb |
refactor(recordings): build recordings from the completed run (#10571)
* refactor(recordings): build recordings from the completed run instead of live event capture Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): budget and isolate replay synthesis against hostile recordings Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): capture full logs and the run-time flow, upgrade v1 files Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(recordings): pick an existing run for the hub recording Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): cap recorded logs under the replay loader's text budget Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): pin picked runs to their executed version, keep v1 streamed logs Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): bound pipeline finalize fan-out, pin flow schema to run version Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(recordings): warn on mixed-version fallback, bound code fetches Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
5ce29b3436 |
feat: add public sharing option for job pages (#10573)
* feat: add public sharing option for job pages Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: gate public run sharing and address review findings Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: address review nits on public run sharing Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: key public run view on workspace, job and token Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
fdd76a6f13 | fix(frontend): collapse the dev-workspace edit notice into a badge (#10576) | ||
|
|
c6c46eca62 | shimmer highlight uses text-emphasis instead of white (#10569) | ||
|
|
8bab579665 |
stop destroying AI sessions in workspaces reached without a usr row (#10567)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
94a1e01699 |
keep the input transform header full width (#10568)
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
c2a6936e7d |
fix: keep the mermaid fullscreen dialog in its pane and its emoji vector (#10541)
* fix: keep the mermaid fullscreen dialog inside its pane and its emoji vector Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: load only the fonts a diagram needs and size chrome per breakpoint Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: cover every emoji class in the font preload without restyling diagrams Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep the dialog chrome allowance in rem so it scales with the root font Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: decode mermaid entity codes when sampling text for the font preload Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: match mermaid's decimal-only entity codes and decode the Inter sample too Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: drop emoji format characters from the font sample Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: state the emoji subset spread and modifier exclusions precisely Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: re-render once fonts settle instead of hand-picking emoji subsets Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: give Modal a fill-height mode instead of measuring its chrome Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: guard the post-fonts re-render against a newer render The re-render after document.fonts.ready assigned svg without re-checking renderSeq after its own await. renderedCode is set before that await, so a stale re-render landing last leaves svg holding the previous diagram while renderedCode names the current source — showSvg stays true and paints the wrong diagram. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
fc1e11cb3d |
fix: compact ai chat context for models with unknown context windows (#10564)
* fix: compact ai chat context for models with unknown context windows Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: correct stale comment on unknown-model context window handling Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: surface assumed context window in usage indicator for unlisted models Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
1846bd5ce5 |
fix(frontend): take the editor's post-edit content, not setCode's argument (#10562)
#10560 changed the script editor's change handler to read `e.detail` instead of `editorCode`, on the reasoning that the two only diverge while the editor is being torn down. They also diverge in a live editor: `setCode` dispatches the string it was handed, but `alignCodeWithEditor` applies that string to Monaco first, and the resulting `onDidChangeModelContent` runs `updateCode` re-entrantly — so if the model normalized the text (EOL is the reachable case; `ScriptBuilder` builds template content with a `\r\n` join), `editorCode` already holds the buffer's version and the payload is the pre-normalization one. Taking the payload leaves `code` disagreeing with what the editor shows, which the external-write effect then tries to reconcile on every change. The language-switch fix in that PR is `alignCodeWithEditor` clearing the timer its own write armed; that part stands and is unaffected. This restores the handler to the buffer-true read. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
56ea133366 |
fix(frontend): reset the editor content when the script language changes (#10560)
Picking a new language seeds the new template into `script.content`, which
`ScriptEditor` writes straight into Monaco. That write goes through
`onDidChangeModelContent`, which arms the keystroke debounce as if the user had
typed — so when the `{#key effectiveLang}` block then tears the editor down, the
unmount flush sees a pending timer, reads a stale `code`, and dispatches a change
that puts the previous language's template back. The editor kept showing the old
content under the new language.
`alignCodeWithEditor` now clears the timer its own write armed, restoring the
premise the unmount flush is guarded on: a pending timer means Monaco holds
something newer than `code`.
`ScriptEditor` also takes the change payload instead of re-reading `editorCode`.
A destroyed component's `bind:` writes no longer reach the parent, so the
re-read returned the value from before the change — which is what actually
wrote the old template back, and would equally have made the unmount flush
save stale text after real typing.
Fixes WIN-2330
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
4c4387d52a |
feat(flow-editor): show an agent's tool-call status without moving the graph (#10557)
* feat(flow-editor): surface an agent's tool-call status without moving the graph Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: count only an agent's tool calls and key them in one place Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: report an agent's replies alongside its tool calls Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: break the agent summary down by action kind Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: key agent tool nodes by kind and keep the summary clear of the tool row Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: read agent action status from the run's success array Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test: pin the tool joins a local run cannot reach Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: place the agent summary beside the step and match MCP paths bare Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: feed a single-step agent test's calls into the graph status Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
386c66bef0 | fix: open the expression property column on demand, not from focus (#10558) | ||
|
|
e4e7782517 |
fix: restore the flow expression editor's property side panel (#10555)
* fix: give flow expression editors their property side panel back * fix: keep the picker column tied to an input that can receive the pick |
||
|
|
b2d38e0391 |
perf: keep run status out of flow graph node and edge data (#10554)
* perf: keep run status out of flow graph node and edge data Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: key the ai tool node memo on the agent's actions Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: state the edge-data and memo-key constraints as invariants Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: restore selection clearing and pin the zoom bar's border colour Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: show an agent's tool calls as they arrive instead of at step end Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * perf: stop editor runs from rebuilding on agent tool calls Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
c59b60c729 |
fix: keep the same_worker pin when a suspend ends without approval (#10552)
* fix: keep the same_worker pin when a suspend ends without approval A disapproved or timed-out approval gate hands the flow back through the UpdateFlow channel with unrecoverable = true. That flag means "the previous step's worker died", and it is read by six sites. Five of them happen to want what it does here, but continue_on_same_worker and continue_with_runners do not: the worker that ran the approval step is alive, so unpinning the error handler and routing it by tag breaks the ./shared contract of a same_worker flow and can land it on a worker group that cannot run it — the same defect #10551 fixed for the three producers that hand back a live flow. Replace the boolean with StepFailureKind so the suspend producer can say "worker alive, but this failure is not the module's to handle" instead of overstating a worker death. The failed module's error policy is deliberately still bypassed: the failure is recorded against the step the gate was holding back, which never ran, so its retry would re-open the gate and its continue_on_error would skip it outright (verified: the gated step is marked Failure with a nil job id and the flow jumps past it). suspend. continue_on_disapprove_timeout remains the way to continue past a gate. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(flow-editor): flag that continue on error does not cover the approval gate A resolved approval is recorded against the step the gate holds back, not the step carrying the suspend, so continue_on_error never sees it: the flow still stops on a disapproval or timeout. Point users at suspend.continue_on_disapprove_timeout, which is what actually continues past a gate, whenever both settings are on and that one is not. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
f11e8835fd |
fix: point re-opened previews at the tab already showing them (#10538)
* fix: point re-opened previews at the tab already showing them * fix: judge composed preview mutations as one change * fix: treat a fullscreen preview as displayed when deciding to flash |
||
|
|
2c189fea14 |
fix(frontend): draw the tab strip's scroll bar instead of the native one (#10547)
* fix(frontend): draw the tab strip's scroll bar instead of the native one The strip sizes its scroll row to the tabs, but a native horizontal scrollbar claims layout height on top of that: Firefox spends 11px on `scrollbar-width: thin` — `--wm-scrollbar-size` is WebKit-only, so the 4px it asks for is ignored there — which clipped the tabs at the top of the 32px sessions strip and left a wide gutter under them. Hide the native bar and draw a 4px thumb from `scrollLeft`/`scrollWidth` instead: it costs no layout height, is the same size in every engine, and sits on the strip's bottom edge, flush under the tabs. Tabs drop to `h-6` so they clear it, and the strip's default height matches the sessions caller's `h-8` so every strip has the same geometry. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(frontend): clamp the tab strip thumb at both ends of its track WebKit's elastic overscroll drives `scrollLeft` negative, which slid the thumb out of the track's left edge and into the strip's padding. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
e203ab087a |
feat: allow a dev workspace to have its own dev workspace (#10534)
* feat: allow a dev workspace to have its own dev workspace Fixes WIN-2324 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep every dev workspace in a chain on a distinct deploy branch Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: count a dev workspace the caller has no seat in as holding its label Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor: keep the attach form standing when a candidate takes the last label Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep the label toggle visible when a candidate's dev workspace clashes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: describe the cycle guard by what holds, not by what changed Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: refuse to archive a fork-backed dev workspace that owns a nested dev Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: put the deploy target and item filters under the pairing they configure Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: refuse to archive any dev workspace that owns a nested dev Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: fix the fixture family count Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: put the deploy target with the pairing line it restates, above protections Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: name the same family head in the workspace menu and the scope picker Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: stop offering to delete a dev workspace from the sidebar settings menu Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: state the visibility boundary the lineage root actually resolves to Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: serialize dev-pairing creation against teardown of the same workspace Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: lock both sides of an attach so adjacent pairings cannot share a label Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: serialize dev pairings on one key, the invariant being chain-wide Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: scope the pairing lock to the chains an operation reads Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: hold the pairing lock across renames and re-check the cycle under it Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: hide the fork-delete action until the workspace entry has loaded Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: lock archive before it reads the pairing state it acts on Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: describe the archive lock test by what it pins, and drop an unused fixture row Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
a3b79d7732 |
feat: add a load all to the tree view's per-folder pager (#10548)
* feat: add a load all next to load more in the tree view folder pager * fix: bound tree node rendering and make a long load resumable * fix: resume a failed first load from its saved cursor * fix: size the show-more step by what a node holds, not what it renders * fix: keep the pager visible mid-run and spin only the clicked button |
||
|
|
d9b10e7b0a |
fix(ai): collapse thinking to a status row with a thought-for duration (#10515)
* refactor(ai): render thinking blocks with the shared tool-call card Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(ai): collapse thinking to a status row with a thought-for duration Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * refactor(ai): separate reasoning-timing reset from duration read Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ai): render expanded thinking in the body font, not mono Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(ai): mark in-progress chat rows with a shimmer sweep Thinking and tool calls both announced themselves with a spinner, which carried no more information than the row already did and read as visual noise once several tools ran in sequence. A white copy of the label now sits over the coloured one and is revealed through a travelling band, so a running row is marked by motion across its own text rather than by a separate glyph. Both spinners and the brain icon are gone, leaving the card with no icon slot at all, and every header label settles on text-secondary. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ai): keep a running row marked under reduced motion The shimmer is the only thing distinguishing a running tool row from a settled one, and the reduced-motion rule removed it outright, so the two became identical for those users. The band now degrades to a flat wash instead of disappearing. Also covers the reasoning-duration state machine: that thinking stops at the first answer token rather than at the end of the turn, and that each reasoning pass of a tool-using turn is timed from scratch. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(ai): restore the clock spy after the reasoning-duration tests The file-level hook only clears call records, so the Date.now spy stayed installed and would freeze time for anything appended after this block. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
616d4fe167 |
fix: edit-in-dev-workspace dead-ends, wraps, and misses the tree view (#10354)
* fix: stop the homepage edit-in-fork button from wrapping * fix: show the full edit-in-fork label anywhere on the button * fix: thread showEditButton through the homepage tree view * fix: match the edit-in-fork button styling to the normal edit button * fix: edit in dev workspace dead-ends on items the dev workspace lacks Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: pull the item's folder before copying it into the dev workspace * fix: speak the compare page's update vocabulary in the dev-workspace prompt * fix: raw app with no stylesheet was undeployable across workspaces * fix: drop the raw-app stylesheet workaround now that the backend serves one The frontend wrapped `getRawAppData` to report a missing `.css` as empty, because a raw app with no stylesheet stores no css blob and the shared deploy treats the resulting 404 as fatal. #10364 fixed that at the source: the backend now serves an empty body for a missing stylesheet, so the wrapper guards a 404 that no longer happens. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: drop the fork icon from the edit-in-dev-workspace affordances The row button carried both a pen and a fork, and the menu entries and detail page buttons carried a fork alone — where the menus already used that same icon for Duplicate/Fork, so the two entries were indistinguishable. The action is an edit, so it takes the pen everywhere, matching the ordinary Edit button. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: send edit in dev workspace to the item's editor The affordance landed on the item's page in the dev workspace and left the user to open the editor from there. It says "Edit", so it goes to the editor: `/scripts/edit/...?workspace=<dev>` and the equivalent for flows and both app kinds. `?workspace=` still does the workspace switch, which the logged layout applies on any route. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat: choose the on-behalf-of user when updating the dev workspace The prompt deployed the item with no say over the identity it would run under, so an item that ran on behalf of someone in prod silently became the deploying user's in the dev workspace. It now offers the same choice the compare page does, under the same rules: shown only when the source item carries an on_behalf_of, picking anyone but yourself gated on admin/wm_deployers in the target, and confirming blocked until a choice is made — including while the lookup that decides whether one is needed is still in flight. The prompt also stops offering the compare page inline; the confirm button still leads there when the user can't deploy into the dev workspace. Two fixes the reused selector needed to work inside a dialog: - ConfirmationModal takes `confirmDisabled`, which also blocks the Enter binding. - The popover's z-index is now overridable, and the user picker is portalled. A ConfirmationModal renders above the popover layer, and its card is transformed for the open transition, which makes it the containing block for the picker's `fixed` positioning — so both opened behind, and the picker was laid out inside the card instead of the viewport. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: check deploy rights per item before prompting to update the dev workspace * fix: read the compare page link before closing the dev-workspace prompt The link is derived from the request the prompt is answering, so closing first left an empty string to navigate to: refusing users saw the dialog dismiss and stay put, with no way through to the compare page. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep the new-tab promise and speak up when a popup is blocked Three defects found by successive cold reviews of the click-time resolution added earlier in this branch, each one only reachable once the previous fix existed: - Safari refuses `window.open` from any promise continuation however fast it resolves, so the tab the editor dropdown opens after its existence probe never appeared there. `claimTab` takes the tab inside the click's own transient activation and points it at the answer once it lands, releasing it when there is nothing to show. - That left the two halves of the same action disagreeing: the entry promises never to navigate the editor away, but when the item turned out to be missing the prompt took over and navigated in place. The request now carries `openInNewTab`, and every destination the prompt can reach honours it. - With popups blocked the fallback called `window.open` without checking, so a successful deploy closed the prompt and did nothing, silently. It now names what it could not open. `openEditInFork` also takes the workspace explicitly. The four editor dropdowns computed their label from `opWorkspace` but resolved the action from the navigation store, and `prodWorkspaceId` feeds `deployItem({ workspaceFrom })` — so a session pane would have deployed from the wrong workspace. `checkPathWritePermission` is exported with an injectable folder probe and covered by table-driven cases, chiefly to pin its two fail-open branches, which otherwise read as dead code inviting deletion. The two unrelated whitespace hunks in ScriptBuilder.svelte are the repo's format-on-save hook fixing pre-existing violations in a file this touched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: create the dev workspace's missing folder without overwriting it `ensureFolder` delegated to the shared `deployItem`, which re-probes and switches to `updateFolder` when the folder turns out to exist. Nobody asked for that folder to be deployed — it is created only so the item has somewhere to land — so a folder created between the two probes had its owners, ACL, summary and labels silently replaced with the source workspace's. Creating is now create-only, and losing that race counts as success: the folder exists, which is all the caller needed. The same delegation dropped `default_permissioned_as` and `labels`, which the shared folder deploy does not send. A folder copied without its create-time identity rules applies none, so an item landing inside it with no on_behalf_of of its own resolves to whoever deployed it rather than to the principal the source folder would have chosen — the exact substitution the rest of this branch exists to prevent. Both are now carried across. Also check `window.open` in the no-dev-workspace branch of `openEditInFork`. The branch beneath it already reported a blocked popup; this one returned as if it had opened something. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: translate copied folder identity rules into the target workspace A `u/<username>` names a workspace-local account, so copying a folder's `default_permissioned_as` verbatim was wrong in two directions: the same username in the dev workspace can be a different person, who would then be granted the item; and a username with no account there at all passes the folder-create check, which is structural, only to fail every subsequent item deploy on the existence check, including the retry — the folder now exists, so `ensureFolder` short-circuits and the deploy fails identically, with no way out of the prompt. Rules are now resolved source username -> email -> target username, since email is the only identifier stable across workspaces, and a rule whose principal has no account in the target is dropped rather than carried. Dropping one makes the copied folder less restrictive than its source, which is not something to discover later from an item running as the wrong user, so it is reported. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: refuse to overwrite a concurrent item, and translate every folder principal Four findings from CI review, all on the implicit half of this flow — the writes the user did not explicitly ask for. The item write is now create-only. The shared `deployItem` re-probes and silently switches to an update, so the caller that acts on an item being *absent* could still overwrite whoever landed it between the two probes. Rather than reimplementing the per-kind deploys, the frontend's own provider refuses exactly the three writes that branch reaches for — `updateFlow`, `updateApp`/ `updateAppRaw`, and a `createScript` carrying a `parent_hash`, which is what makes an otherwise identical create an update. A refusal reports `conflict`, and the prompt opens their version instead of replacing it. Folder principals are translated rather than copied. `u/<username>` is workspace-local, so a verbatim copy either names nobody or names a different account that happens to share the username. Users now resolve source username -> email -> target username, and the two kinds of unresolvable principal are separated because they fail differently: an owner or ACL entry is dropped, which can only narrow the folder and leaves the creator owning it; an identity rule refuses the copy outright, because dropping it runs the item as the deployer and keeping it creates a folder the server then rejects every deploy into. Groups resolve against `listGroups` rather than `listGroupNames`, which unions in instance groups that folder rules do not resolve against — a same-named instance group would otherwise let an unusable rule through. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: read every page of workspace groups before judging a folder principal `listGroups` paginates, and the `perPage: 100` it was called with is narrower than the server's own default of 1000 — so a group past the first page read as having no account in the target. Since an unresolvable identity rule now refuses the whole folder copy, that turned into a refusal naming a group that does exist, and an owner or ACL entry on a later page was dropped silently. Read until a page comes back short, with a size check as the backstop for a server that ignores `page`. `list_users` is unpaginated, so the user half of the same lookup was never affected. Also move `makeProvider`'s doc block back onto `makeProvider`; adding `DeployConflict` had left it documenting the type instead. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: reattach principalTranslator's doc block to principalTranslator Adding `workspaceGroupNames` above it left the block documenting the helper, the same way adding `DeployConflict` had displaced `makeProvider`'s. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
9f3f4fb6d0 |
stop swallowing Ctrl/Cmd+Shift+S in the editors (#10530)
* fix(frontend): stop swallowing Ctrl/Cmd+Shift+S in the editors Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(frontend): make Ctrl/Cmd+S from a focused Monaco flush the draft Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(frontend): broadcast the Monaco save shortcut after the effect flush Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
29e179f787 |
fix(debugger): report python debugger dependency install failures instead of timing out (#10531)
* fix: report python debugger dependency install failures instead of timing out Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: surface swallowed installer errors and stream debugger prepare progress Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: reap the python debugger on a failed launch and bound prepare-deps Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: match uv failure output by stripping progress instead of matching errors Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: treat uv build, download and warning lines as install progress Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
09c8f3b1f3 |
feat: redesign flow step, loop and branch settings panels (#10026)
* feat: responsive modal step panel for the flow editor in sessions On narrow layouts the flow editor's step-details pane opens as a modal (double-click a graph node) instead of a split pane, with a dock/float toggle. Scoped to sessions via allowModalPanel; the full-page editor is unchanged. - FlowEditor: modal/docked modes gated by mount width + allowModalPanel, small header (step-id Badge + subtle dock/close), standing double-click hint, and a per-step hint in the name tooltip - selectionManager: onSelectIntent hook so flow-level panels (settings, input, triggers…) open the modal on single click - PropPickerWrapper: collapse the prop picker until connect and animate it in via AnimatedPane (runs-page pattern), no blue connect ring in modal mode - StepInputGen: drop the TAB/Wand autocompletion button + spinner (feature still works via focus + Tab) - InputTransformForm: decouple the Help dropdown from the AI suggestion - FlowModuleHeader: move 'Save to workspace' into an ellipsis dropdown Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix: loop editor rendering and nested splitpanes splitters in the sessions modal - Loop iterator/parallelism: keep the picker split pane (forceExpanded) so the editor fills its box and the picker shows; the collapse-until-connect mode stays for the step inputs - Remove the intrusive AI TAB/Wand autocompletion button from IteratorGen (generation still runs headless via focus + Tab) - Size the iterator connect plug and restyle the loop header/labels/toggles - Scope the global `.splitter-hidden` splitter-hiding rule to direct children so it no longer leaks into nested Splitpanes under the sessions preview Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: redesign flow step advanced settings as a single toggle-first column Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: taller step test pane by default and restyle advanced section titles Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: show flow run-settings params disabled when a setting is toggled off Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: single-column for-loop panel reusing the run-settings accordion Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: single-column while-loop panel reusing the run-settings accordion Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: single-column branch panels reusing the run-settings accordion Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix: auto-open modal panel when creating an AI agent tool Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat: redesign branch panels with card layout and shared predicate editor Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor: remove per-setting status badges from flow map nodes Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore: sync package-lock after windmill-utils-internal bump Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * style: polish prop-picker plug button and branch panel layouts * fix: persist skip-if-stopped toggles in early stop settings * fix: open the step panel modal on demand and cap its width * fix: restore graph step setting badges, strip panel header chips instead * feat: docked panel header with detach action and open-details step menu * feat: width-based panel mode on every surface with inline detach action * refactor: single source for flow step settings and their defaults * docs: pin flow editor vocabulary in CONTEXT.md * fix: open the trigger panel on double click or a specific trigger * fix: keep module pickers inside their pane and dismissable * fix: drop the misleading chevron on the MCP tool entry * fix: resolve flow approvals against the job's workspace, not the nav one * refactor: derive the approval workspace from the job, not from callers * fix: restore S3 snippets and gate params while their setting is off * fix: restore branch mock controls and address review findings * chore: drop stray debug log from the flow map item * feat: pinned output section for loop and branch panels * fix: open the panel for deliberate navigation from the flow header * perf: mount branch predicate editors on demand * fix: skip predicate picker previews the previous step's result * fix: flow-level graph nodes open their panel on a single click * fix: open the step panel for AI chat selections, not for undo * chore: drop dead console.log and duplicated modalPanel doc * fix: re-sync expression editors and scope error-handler settings * fix: match the failure module exactly and ignore unselectable nodes * fix: keep concurrency editable, honour module cache_ttl, tighten panel ids * fix: open panel from indirect selections, use presence for value-driven toggles * fix: don't open settings on error-handler delete, flush editors on unmount * fix: guard editor destroy flush, keep retry kind reachable * refactor: name the run settings panel after the domain vocabulary * fix: only write editor flushes to the step they belong to * fix: bind step panels by id so a delete can't retarget editor writes * fix: don't let the trigger picker's escape close the drawer beneath it * docs: condense two comments to the constraint they record * fix: arbitrate escape through the overlay stack instead of deferring to it * fix: key nested step blocks by identity so anchored bindings can't go stale * fix: untrack the overlay-stack push and drop the frozen branch binding * chore: state the escape rationale once, key branch lists, format * fix: let the topmost overlay own escape instead of the graph * fix: keep the dynamic-input help box out of static template fields * fix: restore the graph connect on the for-loop iterator * fix: end connect mode with the modal and keep it to docked panels * fix: never enter graph connect mode from the modal panel * fix: reveal inserted steps, restore editor pane size, unleak the drawer stack * fix: keep the enable-AI popover reachable in session panes * feat: add the connect policy and its single armed slot * refactor: one picker for every expression input * refactor: route every connect through one armed slot * fix: give every connect button the same footprint * fix: keep the connect ring from showing through the button * fix: keep flow card actions right-aligned beside the detach button * fix: give the connect ring an opaque ground to mask against * feat: dock the panel back without reopening it * feat: dock the panel from the graph control bar * style: round the graph control bar and size its glyphs * style: customize the graph controls through their supported api * style: build the graph control bar from lucide icons * fix: use the graph's tooltip component in the zoom controls * style: pad the graph controls and enlarge their glyphs * style: pad the graph controls and put dock at the bar's end * refactor: give settings rows the same popover picker as other expressions * fix: pass the wrapper's pickable properties to nested inputs * refactor: stack step settings and render every expression through the step input form * feat: split loop panels into tabs and rework the approval form * feat: anchor drawers to their host pane and give them a size floor * fix: mark the loop iterator expression as required * refactor: badge ee-only toggles instead of a warning line * fix: flag an empty loop iterator expression as an error * refactor: pick the early-stop flow status from one toggle group * fix: keep parallel loops uncapped unless a limit is opted into * fix: scope the overlay stack to its host and disarm connect on dismissal * fix: anchor the trigger picker to its host pane * feat: move diff into the menu when the top bar is narrow * fix: gate the result logs toggle to the graph popover * feat: raise the modal-panel breakpoint to 1280 * fix: anchor flow editor popovers and fullscreen to their host pane * fix: anchor overlays to their host pane and mute them when hidden * fix: portal hosted modals and menus into the pane they anchor to * fix: keep non-listening dialogs off the overlay stack * fix: drop the topmost gate from confirmation dialogs * fix: silence overlays in a collapsed preview panel * feat: rework the branch panels with tabs, reordering and add/delete * refactor: fold the detached-panel chrome into the card header * fix: give every flow panel a titled card header * fix: stop the step panel oscillating on an auto-height editor * feat: consolidate script panel actions and restore branch predicate AI * fix: restore the logs toggle on the flow result popover * fix: collapse the idle property picker in modal step panels * fix: stop the docked pane scrolling alongside its panel * fix: space the last settings row off the panel bottom * revert: always show the property picker pane in step panels * chore: keep the inline script AI button identical to main * fix: ask for AI input suggestions on click, not on hover * fix: keep graph connects armed and remount the parallelism input * style: reveal the predicate AI button on row hover * style: give branch cards a handle and delete column * refactor: arbitrate flow overlay escape through Disposable * fix: give the popover picker its results and re-narrow the EE badge * docs: correct loopSubset and guard the modal width measurement * fix: insert picked properties at the cursor in expression inputs * fix: give the expanded-subflow panel the shared header chrome * style: rename the suspend setting to Suspend until approval/resume * feat: open a step's modal when clicking the step already selected * feat: add an auto/attached/detached toggle for the step panel * refactor: pick the step panel's placement from one named menu * refactor: keep the panel-mode module's exports to what is consumed * feat: show each configured setting's value on its badge * fix: carry the suspend rename into the step settings registry * docs: name both gestures in the step explore hint * test: pin where the step panel goes for a given width and preference --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
1dcb6bb900 |
fix(frontend): filter the AI Sandbox entry by the flow insert search (#10529)
Also drops the now-stale (new) badge on the Claude Code picker entry. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
aa91619bb6 |
fix: flow step picker layout and single hover/keyboard highlight (#10488)
* fix: keep flow step picker rows on one line and highlight only one Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: restore hover on standalone picker rows and drop phantom ai slots Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: drop inert picker resize and align hub rows with workspace rows The step picker popover carried `!resize` but computes `overflow: visible`, so CSS `resize` never applied and the handle did nothing. Dropping it also pins the inner height at 464px, keeping `displayPath` off everywhere except the content-sized trigger picker. Hub rows there rendered summary and path inside a fixed 28px button; give them the same `h-auto min-h-7 py-1` the workspace rows got. Guard `hover:bg-transparent` on `onHover` in both pickers so all three agree, and drop the unconditional `title` on TopLevelNode, which put a native tooltip on every kind button. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep GenAiQuick's CSS hover when it is not wired into the shared index Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
340d3cd565 |
feat(dbt): reach any dbt adapter through a dbt_profile resource, and constrain the warehouse picker (#10525)
* feat(dbt): reach any dbt adapter through a dbt_profile resource, and constrain the warehouse picker
The workspace dbt warehouse picker listed every resource in the workspace, so a
slack or github resource was an offerable answer to a field that can only be a
warehouse. Constraining it exposed that the set of resource types that actually
work is both smaller than the docs claim and too small to be useful:
- `render_profile` translates only six adapters from a Windmill resource; the
rest (clickhouse, duckdb, salesforce, mssql, oracle) refused one outright.
- `redshift` and `duckdb` name no resource type anywhere, so two of the
adapters the quickstart advertises were unreachable.
- the `databricks` resource carries `workspace_url`, while the renderer demanded
`host`, so that warehouse could never render at all.
So the picker gets a constraint and dbt gets an escape hatch wide enough to make
it honest. `dbt_profile` is a resource whose value IS a `profiles.yml` target —
`{ type, target }` — passed to dbt unchanged, so any adapter and any key it
documents works.
`DbtAdapter` is now open: it carries dbt's own `type:` spelling plus an optional
`KnownAdapter` (the eleven Windmill has facts about — a field mapping, a pip
package, the license gate). Anything else is carried by name and installed as
`dbt-<name>`, the convention every adapter on PyPI follows, so "whatever dbt
supports" no longer means "whatever this enum lists". The license gate is
unaffected: `sqlserver`/`oracle` still resolve to their `KnownAdapter` and are
still gated. The name is confined to `[a-z0-9_-]` starting alphanumeric because
it reaches a pip requirement and a venv path on the host.
Two adjacent fixes fall out: the project's own `profiles.yml` and the
descriptor's `profile.type` now accept any adapter instead of the closed list,
and a databricks resource renders its `host` from `workspace_url`.
The picker is constrained to `dbt_profile` plus the translated types, so nothing
it offers can fail for want of a mapping.
Fixes WIN-2320
* fix: drop the unused DbtAdapter::from_resource_type wrapper
Nothing calls it: a Windmill resource type maps through
KnownAdapter::from_resource_type, and the executor resolves an adapter from
the resource's own dbt spelling or by inference. CI builds with -D warnings,
so the dead wrapper failed every backend check.
* fix(dbt): make dbt_profile the block itself, and address the review findings
**A `dbt_profile`'s value IS a `profiles.yml` output block**, `type` included.
It was `{ type, output }`, which asked the user to restructure their block
before pasting it — a translation step, in the one type that exists to avoid
translation. The schema now declares no properties, so the resource form renders
a single JSON editor over the value.
That means the value's shape can no longer say what it is: a `dbt_profile` and
Windmill's bigquery resource are both objects with a `type` (the latter says
`type: service_account`). So the warehouse carries its resource's type
(`DbtWarehouseConnection.resource_type`), and detection is exact. It also makes
decision 9's "the resource type name is the authority" true at runtime for the
translated path, which until now resolved its adapter by sniffing fields.
Review findings, all three reviewers:
- **[P0] an author-chosen adapter became an unsandboxed PyPI install.** `dbt-` is
not a reserved prefix, and `provision_core_1x` installs through `run_tool`,
outside the nsjail ordinary dependency installation uses — so `dbt-<name>` from
a script author's `type` could run a PEP 517 build backend as the worker. Now
gated on a list of published adapters plus `DBT_EXTRA_ADAPTERS`, so trust stays
the admin's call. The open set survives: the engines that ship their adapters
install nothing and take any type.
- **[P1] `type: fabric` rendered as `sqlserver`.** dbt's `type:` was resolved
through the resource-type table, where `fabric` is a Windmill alias for SQL
Server — so a Fabric profile installed dbt-sqlserver, was enterprise-gated, and
failed on an ODBC driver without ever naming Fabric. dbt types now have their
own table.
- **[P1] two spellings of one adapter compared unequal.** `PartialEq` covers the
carried name, so `postgres` != `postgresql` even resolving to one adapter, and
the descriptor/resource check rejected valid configs with a message naming the
same adapter twice. The name is normalised to the adapter's dbt spelling.
- **[P2] identity keys.** `database_key` is what a Windmill resource spells it,
and only translated adapters have one; the rest read dbt's `database`.
- **[P2] duplicate `sslrootcert`** when a block carried both a PEM and a path.
Verified with three real dbt builds: a flat `dbt_profile` postgres block, the
same with `type: postgresql` under a `profile.type: postgres` descriptor (the
alias case, which failed before), and trino for the unknown-adapter path.
* docs(dbt): say that installing an adapter is gated, not just using one
The open-adapter text promised every future adapter is installed as dbt-<name>,
which ensure_adapter_installable refuses outside PUBLISHED_ADAPTERS and
DBT_EXTRA_ADAPTERS. Separates the two: rendering, licensing and identity are open
to any adapter, and only the dbt-core 1.x PyPI install is gated, because that is
the step that runs outside the sandbox.
* fix(dbt): keep a dbt_profile's own sslrootcert when Windmill writes none
The previous round skipped the block's sslrootcert unconditionally to avoid
emitting the key twice, which drops a path-only CA reference — a certificate
baked into the image or mounted on the worker, which is the block's own trust
source. Skipped now only when a root_certificate_pem is present, which is when
Windmill writes a replacement.
* fix(frontend): let a resource type declare no properties
A schema without `properties` is a JSON-edited resource type, not a broken one -
`dbt_profile` is a profiles.yml block whose keys belong to its adapter, so there
is nothing for Windmill to declare. Both editors assumed properties exist:
- ResourceEditor threw on Object.keys(undefined) while deriving the field order,
which left the drawer on its loading skeleton forever, so the resource could
not be viewed or edited at all.
- ApiConnectForm caught the same throw and reported the type as missing from the
workspace, offering to sync a type it already had.
Both now fall back to the raw JSON editor, which is what usesRawEditor already
intended for a schema with no properties.
* chore: cut the new comments to AGENTS.md's four-line cap
Each still states its constraint once; the long-form rationale belongs in
docs/dbt-runtime.md and the PR, not beside the code.
* fix(dbt): keep a dbt_profile's empty and nested collections intact
A block with no children reads back as null, so `extensions: []` reached the
adapter as a missing value rather than the empty list dbt was handed, and a
nested array went through the scalar path and arrived as a quoted JSON string.
Both are keys dbt passes to the adapter as it finds them, so the type has to
survive: empty collections are emitted inline, and the value half of an entry
recurses instead of bottoming out at a scalar.
The test parses the rendered YAML back rather than string-matching it, since
what matters is what a YAML reader sees.
Also cuts DbtWarehouseConnection.resource_type's comment to the four-line cap.
|
||
|
|
552ad9c859 |
fix: reflect custom tag add/remove in the manage-tags drawer immediately (#10526)
* fix: reflect custom tag add/remove in the manage-tags drawer immediately Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: do not fail the custom_tags write when the cache refresh errors Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
4254686758 |
feat: show far more in the home tree view and say what is not loaded (#10519)
* feat: show far more in the home tree view and say what is not loaded * feat: let every folder in the home tree page within its own prefix * fix: count leaves in nested badges and stop transient subtree mounts * fix: merge nested pages instead of replacing rows an ancestor loaded * docs: tighten the tree prefix-loading invariants |
||
|
|
0d1cb818ee |
feat: preview and edit steps inside expanded subflows (#10520)
* feat: preview and edit expanded subflow steps in the flow editor * fix: hide subflow edit button when no flow editor drawer is available * fix: address review findings on expanded subflow step panel * fix: base-prefix subflow links and bound the expanded subflow module cache * fix: do not let a pre-deploy response repopulate the invalidated subflow cache * fix: guard expanded subflow reloads against collapse and encode workspace in link * fix: commit an expanded subflow reload only onto the expansion it fetched for |
||
|
|
62b2f4b067 |
fix: bundle a vector emoji font so emoji scale with flow graph zoom (#10498)
* fix: bundle a vector emoji font so emoji scale with flow graph zoom Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: include the upstream copyright notice in the bundled OFL license Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: match the bundled license notice to the shipped font binaries Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: correct the unicode-range gating comment Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
6d21d30242 |
fix: bound ScopeSelector badge heights and correct three scope-chip defects (#10523)
* fix: cap ScopeSelector badge container heights The "Selected Scopes" summary and each domain header rendered their badges in unconstrained flex-wrap containers. With path-restricted scopes the badge strings run long, so a handful of them wrapped over many rows and pushed the scope domain list and the token form's action buttons below the fold. Cap the summary at 8rem and the per-domain header at 4rem, both scrolling vertically past that. Fixes WIN-2318 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: correct scope chip disabled state, summary readability and domain widening Follow-ups to #10517, all in ScopeSelector: - The shared scopeChip snippet bound the component-level `disabled` for its remove button, but a scope card computes `isDisabled = disabled || isScopeDisabled(...)`. A scope superseded by its `:write` sibling greyed out its checkbox and its path button while the `x` on its path chips stayed live, so those paths could still be destroyed. The effective state is now passed in. - Truncating a chip hides the paths being granted, which is the point of the Selected Scopes summary. Chips there now wrap instead; the tight per-domain header and the per-scope path lists keep truncating. - Ticking a domain checkbox re-added its write and run scopes bare, dropping any resource paths configured on them: a token restricted to one path silently became a token for the whole domain, and unticking did not bring the paths back. The checkbox already reads as checked when those scopes are path-restricted, so it now carries the paths over. Both branches of the requires_resource_path conditional it replaces pushed the same bare value, so nothing was reading that flag. - The path popover tooltip explained that no paths means full access but never that each path added widens the scope's reach, which is what reads backwards next to the "Add path" button. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: correct the path tooltip and drop the domain-header height cap Review nits from #10523. The tooltip claimed every path added widens the scope's reach, which is only true from the second path on: the first replaces a bare, full-access scope with a path-restricted one, narrowing it. Stating what each state means avoids the direction question entirely. The domain header no longer caps its height. Truncation holds every chip to one row and a domain has a handful of scopes, so the row cannot run away, while the cap put a 64px scroller inside the scrollable domain list that swallowed wheel events crossing it — and clipped mid-row, since 64px is not a multiple of the row height. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
221566d282 |
feat: let the database manager run its jobs on a custom worker tag (#10516)
* feat: let the database manager run its jobs on a custom worker tag Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: ignore a superseded database load, share the tag button between drawers Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: share the database worker tag override across mounted drawers Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
ae2f584de8 |
fix: keep the token scope builder inside its panel when scopes get long (#10517)
* fix: keep the token scope builder inside its panel when scopes get long Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: label the scope path popover 'Add path' once paths exist Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
71e68e87dc |
fix: show which MCP endpoint tools a token scope will actually expose (#10514)
* fix: show which MCP endpoint tools a token scope will actually expose Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: keep a wildcard endpoint scope when pruning the MCP endpoint selection Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * docs: drop orphaned matcher comment and name the wildcard remedy in the MCP scope warning Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
d63315ed35 |
feat(frontend): pick workspace members from a searchable instance user list (#10474)
* feat(frontend): pick workspace members from a searchable instance user list Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m * fix: exclude non-addable users in the query and keep the picker input editable Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m * fix: cancel a superseded user search so its result cannot overwrite a newer one Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m * fix: treat the typed address as the email so Add works without the dropdown Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m * fix: only submit the typed picker text when it is a whole email address Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m * fix: keep the typed address visible in the picker once its dropdown closes Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FoPnHJJTRrkZ2UnzWuFM2m --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |